1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved ave.exe returns and redirects. At a loss.

Discussion in 'Malware and Virus Removal Archive' started by irolder67, 2010/04/19.

  1. 2010/04/19
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    [Resolved] ave.exe returns and redirects. At a loss.

    I am running windows Vista with Verizon security suite. Verizon antivirus quarantined ave.exe but it got thru with a lot of other malware all from same site. Site was reported. Verizon worked on my computer 8 hours said all was well and then all returned there suggestion at that point was reformat. I took matters into my own hands and here is what has been done so far.
    The following scans run: Malware bytes, Superantispyware, Hitmanpro, Verizon antivirus, eset on line scanner. Other Programs run: Hijack this, combo fix. Using process Viewer to watch programs. Several Programs Verizon ran. I have done a few reg edit. Uninstalled IE8 to 7 no help on redirect. Firefox redirected, Google Chrome opens but cannot load page. Have been able to remove ave.exe but with the redirect problem ave.exe returns. ave.exe disables windows updates. Below is the scan you have requested. Thanks for any Help.


    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Owner at 23:27:17.79 on Mon 04/19/2010
    Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_10
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.957.250 [GMT -4:00]

    AV: Verizon Internet Security Suite Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: Antispyware *disabled* (Updated) {527D3A1B-E68A-4CA3-8771-74CC42308FE9}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Verizon Internet Security Suite Anti-Spyware *enabled* (Updated) {307352C6-1CBD-11DB-8AF6-B622A1EF5492}
    FW: Verizon Internet Security Suite Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k apphost
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
    c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files\Verizon\Online Backup\Scheduler\OnlineBackup.SchedulerService.exe
    C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k iissvcs
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\svchost.exe -k WindowsMobile
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
    C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe
    C:\Program Files\Verizon\Online Backup\vewatch.exe
    C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
    C:\WINDOWS\WindowsMobile\wmdcBase.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\Kav\Bin\ScanningProcess.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Users\Owner\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\Microsoft\Web Platform Installer\WebPlatformInstaller.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Owner\Desktop\bbs virus\dds.pif
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: PopKill Class: {3c060ea2-e6a9-4e49-a530-d4657b8c449a} - c:\program files\verizon\verizon internet security suite\pkR.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
    TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRunOnce: [IndexCleaner] "c:\program files\verizon\verizon internet security suite\IdxClnR.exe "
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Online Backup Auto Update] "c:\program files\verizon\online backup\auto update\OnlineBackup.UpdateSystemTray.exe "
    mRun: [Vault Explorer Cache Watcher] c:\program files\verizon\online backup\vewatch.exe
    mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
    mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
    mRun: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
    mRunOnce: [IndexCleaner] "c:\program files\verizon\verizon internet security suite\IdxClnR.exe "
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
    IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
    IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
    IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
    IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemywifi.verizon.net/sdcCommon/download/WIFI/Verizon%20WiFi%20Installer.cab
    DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
    DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
    DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
    DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
    DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} - hxxps://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx
    DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
    DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\ian14093.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.google.mozilla.com/firefox?client=firefox-a&rls=com.google:en-US:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBook.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpClipBookDB.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpNeoLogger.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSaturn.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartSelect.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSmartWebPrinting.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpSWPOperation.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPLogging.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTC.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXPMTL.dll
    FF - component: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\components\hpXREStub.dll
    FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\ian14093.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\hp\digital imaging\smart web printing\mozillaaddon3\plugins\nphpclipbook.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
    FF - plugin: c:\program files\verizon\vsp\nprpspa.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\ian14093.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-20 64160]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 66632]
    R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\verizon\verizon internet security suite\safeconnect\driver\platform_vista\SafeConnectDriver.sys [2008-11-14 161304]
    R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\verizon\verizon internet security suite\safeconnect\driver\platform_vista\SafeConnectFilter.sys [2008-11-14 29720]
    R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\verizon\verizon internet security suite\safeconnect\driver\platform_vista\SafeConnectShim.sys [2008-11-14 29248]
    R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\system32\drivers\RTL85n86.sys [2008-7-4 366080]
    S3 Activ;Activ;c:\windows\system32\drivers\Activ.sys [2010-4-18 15680]
    S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-8-24 54632]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
    S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]
    S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
    S3 NUVision;Pinnacle DVC 80 Video;c:\windows\system32\drivers\nuvvid2.sys [2008-11-12 155264]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 12872]
    S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]

    =============== Created Last 30 ================

    2010-04-19 13:15:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-19 13:15:29 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-19 13:15:28 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-19 00:06:35 0 d-----w- c:\users\owner\appdata\roaming\CyberScrub
    2010-04-19 00:06:20 84 ----a-w- c:\windows\csact.ini
    2010-04-18 22:10:39 0 d-----w- c:\program files\Rapidware
    2010-04-18 22:08:52 15680 ----a-w- c:\windows\system32\drivers\Activ.sys
    2010-04-18 01:45:01 0 d-----w- c:\program files\Free Process Viewer
    2010-04-17 19:21:18 0 d-----w- c:\program files\ESET
    2010-04-17 18:49:05 0 d-----w- c:\users\owner\appdata\roaming\ieSpell
    2010-04-17 18:47:57 0 d-----w- c:\program files\ieSpell
    2010-04-15 19:39:47 65536 --sha-w- c:\users\owner\ntuser.dat{8ab5f247-0447-11de-8746-00032545351d}.TxR.blf
    2010-04-15 18:58:42 218 ----a-w- c:\windows\system32\.crusader
    2010-04-15 18:58:41 12872 ----a-w- c:\windows\system32\bootdelete.exe
    2010-04-15 18:34:39 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2010-04-15 18:34:02 0 d-----w- c:\programdata\Hitman Pro
    2010-04-15 18:33:53 0 d-----w- c:\program files\Hitman Pro 3.5
    2010-04-15 13:56:10 0 d-s---w- C:\ComboFix
    2010-04-15 13:03:20 0 d-----w- c:\windows\LMIB7CA.tmp
    2010-04-15 13:02:39 0 d-----w- c:\windows\LMI15FC.tmp
    2010-04-13 16:38:02 16384 ----a-w- c:\windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
    2010-04-13 16:38:01 3276800 ----a-w- c:\windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
    2010-04-13 16:38:00 0 d-----w- c:\program files\Microsoft ATS
    2010-04-13 00:25:31 0 d-sh--w- C:\$RECYCLE.BIN
    2010-04-12 23:46:52 0 d-----w- c:\windows\LMI2B10.tmp
    2010-04-12 22:50:32 98816 ----a-w- c:\windows\sed.exe
    2010-04-12 22:50:32 77312 ----a-w- c:\windows\MBR.exe
    2010-04-12 22:50:32 261632 ----a-w- c:\windows\PEV.exe
    2010-04-12 22:50:32 161792 ----a-w- c:\windows\SWREG.exe
    2010-04-12 16:35:19 0 d-----w- c:\windows\LMI6CAD.tmp
    2010-04-12 13:33:20 0 d-----w- c:\programdata\avG
    2010-04-12 00:12:19 0 d-----w- c:\programdata\SecTaskMan
    2010-04-11 19:27:25 0 d-----w- c:\program files\Bing Bar Installer
    2010-04-11 19:13:22 176192921 ----a-w- c:\windows\MEMORY.DMP
    2010-04-11 19:10:10 0 d-----w- c:\users\owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}
    2010-04-11 01:24:59 0 d-----w- C:\spyware
    2010-04-09 22:21:51 0 d-----w- c:\program files\Uniblue
    2010-04-09 22:19:27 0 d-----w- c:\users\owner\appdata\roaming\Uniblue
    2010-03-22 01:39:53 0 d-----w- c:\program files\Citrix
    2010-03-22 01:39:16 72080 ----a-w- c:\users\owner\g2mdlhlpx.exe
    2010-03-22 00:13:37 0 d-----r- C:\Sandbox
    2010-03-21 23:20:59 0 d-----w- c:\program files\Sandboxie

    ==================== Find3M ====================

    2010-04-20 02:47:16 389349664 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2010-04-16 15:34:12 5213024 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2010-04-16 14:28:47 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-04-16 14:28:47 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-04-16 14:28:47 143360 ----a-w- c:\windows\inf\infstor.dat
    2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-24 09:33:16 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
    2010-02-20 23:06:41 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2010-02-20 23:05:14 30720 ----a-w- c:\windows\system32\httpapi.dll
    2010-02-20 20:53:34 411648 ----a-w- c:\windows\system32\drivers\http.sys
    2010-02-11 22:34:56 1228304 ----a-w- c:\users\owner\ADBEFLPRCS4Win_LS1.exe
    2010-02-01 20:09:53 23112 ----a-w- c:\windows\hpqins15.dat
    2010-01-30 12:43:50 77376 ----a-w- c:\windows\hpqins05.dat
    2010-01-28 15:58:43 4956 ----a-w- c:\users\owner\appdata\roaming\wklnhst.dat
    2010-01-25 12:00:35 471552 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-01-25 12:00:35 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-25 12:00:35 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-01-25 12:00:22 471552 ----a-w- c:\windows\system32\secproc.dll
    2010-01-25 11:58:52 332288 ----a-w- c:\windows\system32\msdrm.dll
    2010-01-25 08:21:20 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-01-25 08:21:20 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-25 08:21:18 518144 ----a-w- c:\windows\system32\RMActivate.exe
    2010-01-25 08:21:18 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-01-23 09:26:13 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-01-23 01:08:39 186815 ----a-w- c:\windows\hpwins23.dat
    2009-11-18 18:17:37 665600 ----a-w- c:\windows\inf\drvindex.dat
    2008-09-21 15:33:50 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-05-29 16:57:40 2048 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat
    2009-05-29 16:57:40 2048 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat

    ============= FINISH: 23:36:12.68 ===============


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft® Windows Vistaâ„¢ Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/30/2008 4:24:23 PM
    System Uptime: 4/19/2010 7:43:52 PM (4 hours ago)

    Motherboard: Gateway | |
    Processor: Genuine Intel(R) CPU T2060 @ 1.60GHz | U23 | 1600/mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 139 GiB total, 61.735 GiB free.
    D: is FIXED (NTFS) - 10 GiB total, 4.459 GiB free.
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0001
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter #2
    PNP Device ID: ROOT\*ISATAP\0001
    Service: tunnel

    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0002
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter #3
    PNP Device ID: ROOT\*ISATAP\0002
    Service: tunnel

    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6500 E709n
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet 6500 E709n
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:

    Class GUID: {4d36e979-e325-11ce-bfc1-08002be10318}
    Description: Officejet 6500 E709n
    Device ID: ROOT\PRINTER\0000
    Manufacturer: HP
    Name: Officejet 6500 E709n
    PNP Device ID: ROOT\PRINTER\0000
    Service:

    ==== System Restore Points ===================


    ==== Installed Programs ======================

    32 Bit HP CIO Components Installer
    6500_E709_eDocs
    6500_E709_Help
    6500_E709n
    Acrobat.com
    Adobe AIR
    Adobe Anchor Service CS3
    Adobe Anchor Service CS4
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge CS4
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe CMaps CS4
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color EU Extra Settings CS4
    Adobe Color JA Extra Settings
    Adobe Color JA Extra Settings CS4
    Adobe Color NA Recommended Settings
    Adobe Color NA Recommended Settings CS4
    Adobe CSI CS4
    Adobe Default Language CS3
    Adobe Default Language CS4
    Adobe Device Central CS3
    Adobe Device Central CS4
    Adobe Dreamweaver CS3
    Adobe Drive CS4
    Adobe Dynamiclink Support
    Adobe ExtendScript Toolkit 2
    Adobe ExtendScript Toolkit CS4
    Adobe Extension Manager CS3
    Adobe Extension Manager CS4
    Adobe Flash CS3
    Adobe Flash CS4
    Adobe Flash CS4 Extension - Flash Lite STI en
    Adobe Flash CS4 Professional
    Adobe Flash CS4 STI-en
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Flash Video Encoder
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe Linguistics CS4
    Adobe Media Encoder CS4
    Adobe Media Player
    Adobe Output Module
    Adobe PDF Library Files
    Adobe PDF Library Files CS4
    Adobe Photoshop CS3
    Adobe Reader 9.1
    Adobe Search for Help
    Adobe Service Manager Extension
    Adobe Setup
    Adobe Shockwave Player 11.5
    Adobe Soundbooth CS3
    Adobe Soundbooth CS3 Codecs
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Type Support CS4
    Adobe Update Manager CS3
    Adobe Update Manager CS4
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP DVA Panels CS3
    Adobe XMP Panels CS3
    Adobe XMP Panels CS4
    AdobeColorCommonSetCMYK
    AdobeColorCommonSetRGB
    ATI Catalyst Install Manager
    ATI Uninstaller
    Avery Wizard 3.1
    Bing Bar
    BlackBerry Desktop Software 5.0.1
    Bonjour
    bpd_scan
    BPDSoftware
    BPDSoftware_Ini
    BufferChm
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center Localization Chinese Standard
    Catalyst Control Center Localization Chinese Traditional
    Catalyst Control Center Localization Czech
    Catalyst Control Center Localization Danish
    Catalyst Control Center Localization Dutch
    Catalyst Control Center Localization Finnish
    Catalyst Control Center Localization French
    Catalyst Control Center Localization German
    Catalyst Control Center Localization Greek
    Catalyst Control Center Localization Hungarian
    Catalyst Control Center Localization Italian
    Catalyst Control Center Localization Japanese
    Catalyst Control Center Localization Korean
    Catalyst Control Center Localization Norwegian
    Catalyst Control Center Localization Polish
    Catalyst Control Center Localization Portuguese
    Catalyst Control Center Localization Russian
    Catalyst Control Center Localization Spanish
    Catalyst Control Center Localization Swedish
    Catalyst Control Center Localization Thai
    Catalyst Control Center Localization Turkish
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CDDRV_Installer
    Chuzzle Deluxe 1.01
    CleanUp!
    Connect
    Destination Component
    DeviceDiscovery
    DIGOpt
    DocMgr
    DocProc
    ESET Online Scanner v3
    Fax
    FileZilla Client 3.1.0.1
    Free Process Viewer 2.0
    Gateway Game Console
    Gateway Recovery Center Installer
    Google Chrome
    Google Desktop
    Google Earth
    Google Toolbar for Firefox
    Google Toolbar for Internet Explorer
    Google Update Helper
    Google Updater
    GPBaseService2
    Hex Color Finder
    HijackThis 2.0.2
    Hitman Pro 3.5
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB945282)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946040)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946308)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB946344)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947540)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB947789)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB948127)
    Hotfix for Microsoft Visual Basic 2008 Express Edition with SP1 - ENU (KB951708)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB945282)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946040)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946308)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946344)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB946581)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB947540)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB947789)
    Hotfix for Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU (KB951708)
    HP Customer Participation Program 12.0
    HP Document Manager 2.0
    HP Imaging Device Functions 12.0
    HP Officejet 6500 E709 Series
    HP Smart Web Printing 4.60
    HP Solution Center 13.0
    HP Update
    HPProductAssistant
    HPSSupply
    ieSpell
    InfraRecorder
    Java(TM) 6 Update 10
    Java(TM) SE Runtime Environment 6
    Junk Mail filter update
    KhalInstallWrapper
    kuler
    Logitech QuickCam
    Logitech SetPoint
    Malwarebytes' Anti-Malware
    MarketResearch
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Digital Image Starter Edition 2006
    Microsoft Digital Image Starter Edition 2006 Editor
    Microsoft Digital Image Starter Edition 2006 Library
    Microsoft Money 2007 Home & Business
    Microsoft Money Shared Libraries
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office FrontPage 2003
    Microsoft Office Live Add-in 1.3
    Microsoft Office Live Meeting 2007
    Microsoft Office OneNote 2003
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office Professional Edition 2003
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
    Microsoft Office Visual Web Developer 2007
    Microsoft Office Visual Web Developer MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft SQL Server 2008
    Microsoft SQL Server 2008 Browser
    Microsoft SQL Server 2008 Common Files
    Microsoft SQL Server 2008 Database Engine Services
    Microsoft SQL Server 2008 Database Engine Shared
    Microsoft SQL Server 2008 Management Objects
    Microsoft SQL Server 2008 Native Client
    Microsoft SQL Server 2008 RsFx Driver
    Microsoft SQL Server 2008 Setup Support Files
    Microsoft SQL Server Compact 3.5 SP1 Design Tools English
    Microsoft SQL Server Compact 3.5 SP1 English
    Microsoft SQL Server VSS Writer
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft VC9 runtime libraries
    Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual Studio Web Authoring Component
    Microsoft Visual Web Developer 2005 Express Edition - ENU
    Microsoft Visual Web Developer 2005 Express Edition - ENU Service Pack 1 (KB926751)
    Microsoft Visual Web Developer 2008 Express Edition with SP1 - ENU
    Microsoft Web Platform Installer 2.0 Beta
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Web - enu
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
    Microsoft Works
    Motherboard Monitor 5
    Motorola Driver Installation 3.7.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.5.7)
    MSN
    MSN Toolbar
    MSVCRT
    MSVCSetup
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    NCH Toolbox
    Network
    OCR Software by I.R.I.S. 12.0
    OGA Notifier 2.0.0048.0
    OutFront Web Template
    PDF Settings
    PDF Settings CS4
    PerfectDisk 2008
    Photoshop Camera Raw
    Pinnacle USB device drivers
    Pixel Bender Toolkit
    Power2Go 5.0
    ProductContext
    Publix Preschool Pals
    QuickTime
    Reader Rabbit Thinking Adventures Ages 4-6
    RPS Burn
    RPS CRT
    RPS Diagnostic Utility
    RPS Firewall
    RPS Ksdk
    RPS ParentalControl
    RPS PerfectDiskStub
    RPS PopupBlocker
    RPS RpsCore
    RPS SafeConnect
    Scan
    Security Update for 2007 Microsoft Office System (KB951550)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Service Pack 1 for SQL Server 2008 (KB968369)
    Shop for HP Supplies
    SigmaTel Audio
    Skins
    SmartWebPrinting
    SolutionCenter
    SortSite 3.0 Evaluation
    SoundTap Streaming Audio Recorder
    Sql Server Customer Experience Improvement Program
    StarMessage Screen Saver
    Status
    Suite Shared Configuration CS4
    SUPERAntiSpyware Free Edition
    Synaptics Pointing Device Driver
    Toolbox
    TrayApp
    UnloadSupport
    Update for 2007 Microsoft Office System (KB967642)
    Update for 2007 Microsoft Office System (KB977724)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Visual Studio Web Authoring Component (KB945140)
    Update for Microsoft Visual Web Developer 2005 Express Edition - ENU (KB932232)
    Verizon Internet Security Suite
    Verizon Online Backup
    Verizon Servicepoint 1.5.24
    Vz In Home Agent
    VZAccess Manager for RIM
    WavePad Sound Editor
    WebReg
    Wi-Fi Connect
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live Mail
    Windows Live Messenger
    Windows Live OneCare safety scanner
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Player Firefox Plugin
    Windows Movie Maker 2.6
    WinRAR archiver
    WinZip Self-Extractor

    ==== End Of File ===========================
     
  2. 2010/04/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I suggest, that eventually, you switch from Verizon Security Suite to some better protection program.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.pif
    * Rkill.exe

    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.
    * If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run then try to immediately run the following.

    Now download and run exeHelper.

    * Please download exeHelper from Raktor to your desktop.
    * Double-click on exeHelper.com to run the fix.
    * A black window should pop up, press any key to close once the fix is completed.
    * A log file named log.txt will be created in the directory where you ran exeHelper.com
    * Attach the log.txt file to your next message.[/LIST]

    Note: If the window shows a message that says "Error deleting file ", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    ===============================================================

    Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    Do NOT use the computer while GMER is running!
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.

    ===============================================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     

  3. to hide this advert.

  4. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Logs

    Logs per your request. *Note: Combo fix requested Verizon scan software be disabled. That was done but error message still continued . Ran combo fix anyway.Please see attached log's.

    exeHelper by Raktor
    Build 20100414
    Run at 01:35:51 on 04/20/10
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Removing HKCR\secfile
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--


    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit quick scan 2010-04-20 01:59:07
    Windows 6.0.6002 Service Pack 2
    Running: ezdoygxs[1].exe; Driver: C:\Users\Owner\AppData\Local\Temp\kglcapow.sys


    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
    AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

    Device -> \Driver\atapi \Device\Harddisk0\DR0 84D2CAC8

    ---- Files - GMER 1.0.15 ----

    File C:\Windows\system32\drivers\atapi.sys suspicious modification

    ---- EOF - GMER 1.0.15 ----


    ComboFix 10-04-19.04 - Owner 04/20/2010 2:26.5.2 - x86 NETWORK
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.957.566 [GMT -4:00]
    Running from: c:\users\Owner\Desktop\bbs virus\ComboFix.exe
    AV: Verizon Internet Security Suite Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
    FW: Verizon Internet Security Suite Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
    SP: Antispyware *disabled* (Updated) {527D3A1B-E68A-4CA3-8771-74CC42308FE9}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Verizon Internet Security Suite Anti-Spyware *enabled* (Updated) {307352C6-1CBD-11DB-8AF6-B622A1EF5492}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\5kl3dfTWL.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\64KP0i.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\65O8mE80.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\758r1np5.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\7hYtwbP6.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\7Ixg6Q604.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\7WntFt0w.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\F1ntK2D8k.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\HlTajcP00.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\sw8UUc8.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\U381jsd1G.jpg
    c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\VLiUarj.jpg

    Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
    Restored copy from - Kitty had a snack :p
    .
    ((((((((((((((((((((((((( Files Created from 2010-03-20 to 2010-04-20 )))))))))))))))))))))))))))))))
    .

    2010-04-20 06:41 . 2010-04-20 06:42 -------- d-----w- c:\users\Owner\AppData\Local\temp
    2010-04-20 06:41 . 2010-04-20 06:41 -------- d-----w- c:\users\Public\AppData\Local\temp
    2010-04-20 06:41 . 2010-04-20 06:41 -------- d-----w- c:\users\Guest\AppData\Local\temp
    2010-04-20 06:41 . 2010-04-20 06:41 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-04-20 06:03 . 2010-04-20 06:15 -------- d-----w- C:\32788R22FWJFW
    2010-04-19 13:15 . 2010-03-30 04:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-19 13:15 . 2010-03-30 04:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-19 13:15 . 2010-04-19 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-19 00:06 . 2010-04-19 16:17 -------- d-----w- c:\users\Owner\AppData\Roaming\CyberScrub
    2010-04-18 22:10 . 2010-04-18 22:10 -------- d-----w- c:\program files\Rapidware
    2010-04-18 22:08 . 2008-06-16 03:18 15680 ----a-w- c:\windows\system32\drivers\Activ.sys
    2010-04-18 01:45 . 2010-04-18 01:45 -------- d-----w- c:\program files\Free Process Viewer
    2010-04-17 22:36 . 2010-04-17 22:47 -------- d-----w- c:\program files\Windows Live Safety Center
    2010-04-17 19:21 . 2010-04-17 19:21 -------- d-----w- c:\program files\ESET
    2010-04-17 18:49 . 2010-04-17 19:01 -------- d-----w- c:\users\Owner\AppData\Roaming\ieSpell
    2010-04-17 18:47 . 2010-04-17 18:47 -------- d-----w- c:\program files\ieSpell
    2010-04-15 18:58 . 2010-04-18 23:55 12872 ----a-w- c:\windows\system32\bootdelete.exe
    2010-04-15 18:34 . 2010-04-19 12:57 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2010-04-15 18:34 . 2010-04-15 18:58 -------- d-----w- c:\programdata\Hitman Pro
    2010-04-15 18:33 . 2010-04-15 18:33 -------- d-----w- c:\program files\Hitman Pro 3.5
    2010-04-15 13:03 . 2010-04-15 13:03 -------- d-----w- c:\windows\LMIB7CA.tmp
    2010-04-15 13:02 . 2010-04-15 19:32 -------- d-----w- c:\windows\LMI15FC.tmp
    2010-04-13 17:31 . 2010-04-13 17:31 -------- d-----w- c:\users\Owner\AppData\Local\ElevatedDiagnostics
    2010-04-13 16:58 . 2010-04-15 00:00 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
    2010-04-13 16:38 . 2010-04-13 17:25 -------- d-----w- c:\program files\Microsoft ATS
    2010-04-12 23:46 . 2010-04-13 22:12 -------- d-----w- c:\windows\LMI2B10.tmp
    2010-04-12 16:35 . 2010-04-12 16:35 -------- d-----w- c:\users\Owner\AppData\Local\ICS
    2010-04-12 16:35 . 2010-04-13 01:48 -------- d-----w- c:\windows\LMI6CAD.tmp
    2010-04-12 13:33 . 2010-04-12 13:33 -------- d-----w- c:\programdata\avG
    2010-04-12 00:12 . 2010-04-16 14:31 -------- d-----w- c:\programdata\SecTaskMan
    2010-04-11 19:27 . 2010-04-11 19:27 -------- d-----w- c:\program files\Bing Bar Installer
    2010-04-11 19:10 . 2010-04-11 19:10 -------- d-----w- c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}
    2010-04-11 01:24 . 2010-04-11 01:25 -------- d-----w- C:\spyware
    2010-04-10 18:37 . 2010-04-10 18:37 -------- d-----w- c:\users\Owner\AppData\Roaming\HPAppData
    2010-04-09 22:21 . 2010-04-09 22:21 -------- d-----w- c:\program files\Uniblue
    2010-04-09 22:19 . 2010-04-09 22:19 -------- d-----w- c:\users\Owner\AppData\Roaming\Uniblue
    2010-03-22 01:39 . 2010-04-16 13:32 -------- d-----w- c:\program files\Citrix
    2010-03-22 01:39 . 2010-03-22 01:39 72080 ----a-w- c:\users\Owner\g2mdlhlpx.exe
    2010-03-22 00:13 . 2010-03-22 00:13 -------- d-----r- C:\Sandbox
    2010-03-21 23:20 . 2010-04-16 13:57 -------- d-----w- c:\program files\Sandboxie

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-20 05:48 . 2009-01-02 01:46 389604128 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2010-04-20 05:05 . 2008-05-30 20:50 -------- d-----w- c:\program files\Google
    2010-04-20 00:05 . 2009-05-10 21:25 256 ----a-w- c:\windows\system32\pool.bin
    2010-04-19 23:48 . 2008-06-07 21:58 -------- d-----w- c:\programdata\Google Updater
    2010-04-19 13:02 . 2009-07-14 00:25 1356 ----a-w- c:\users\Owner\AppData\Local\d3d9caps.dat
    2010-04-16 15:34 . 2009-01-02 01:46 5213024 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2010-04-16 14:58 . 2008-05-30 18:15 111032 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-04-16 14:29 . 2008-06-25 00:01 -------- d-----w- c:\program files\Yahoo!
    2010-04-16 14:16 . 2008-05-30 20:35 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-04-16 13:43 . 2008-05-30 20:45 -------- d-----w- c:\programdata\Microsoft Help
    2010-04-16 13:40 . 2008-05-30 20:48 -------- d-----w- c:\program files\Microsoft Works
    2010-04-16 13:19 . 2008-05-30 20:58 -------- d-----w- c:\program files\BigFix
    2010-04-16 13:18 . 2010-02-11 22:19 -------- d-----w- c:\program files\Common Files\Akamai
    2010-04-14 18:39 . 2010-04-14 18:39 52224 ----a-w- c:\users\Owner\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-04-14 18:39 . 2010-04-14 18:39 117760 ----a-w- c:\users\Owner\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-04-14 18:38 . 2009-02-27 05:03 -------- d-----w- c:\program files\SUPERAntiSpyware
    2010-04-12 15:44 . 2009-02-27 04:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-04-12 00:12 . 2010-04-12 00:12 53 ----a-w- c:\programdata\SecTaskMan\icn_99DB51844A69EF948A58CD0FE6E9E487.dll
    2010-04-09 07:22 . 2009-05-11 13:07 -------- d-----w- c:\program files\Any Video Converter
    2010-04-09 07:22 . 2009-05-11 13:07 -------- d-----w- c:\users\Owner\AppData\Roaming\Any Video Converter
    2010-03-12 01:14 . 2009-01-06 02:21 -------- d-----w- c:\program files\Common Files\Roxio Shared
    2010-03-12 01:13 . 2009-01-06 02:21 -------- d-----w- c:\programdata\Roxio
    2010-03-12 01:10 . 2008-06-08 14:09 -------- d-----w- c:\program files\Common Files\PX Storage Engine
    2010-03-11 23:57 . 2010-03-11 23:57 -------- d-----w- c:\programdata\Research In Motion
    2010-03-11 23:45 . 2008-07-06 20:21 -------- d-----w- c:\users\Owner\AppData\Roaming\InstallShield
    2010-03-11 13:47 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-03-11 05:35 . 2008-11-12 16:41 -------- d-----w- c:\program files\Movie Maker 2.6
    2010-02-24 14:16 . 2009-10-02 19:19 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-24 09:33 . 2010-02-11 01:34 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
    2010-02-20 23:06 . 2010-03-11 05:30 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2010-02-20 23:05 . 2010-03-11 05:30 30720 ----a-w- c:\windows\system32\httpapi.dll
    2010-02-20 20:53 . 2010-03-11 05:30 411648 ----a-w- c:\windows\system32\drivers\http.sys
    2010-02-11 22:34 . 2010-02-11 22:25 1228304 ----a-w- c:\users\Owner\ADBEFLPRCS4Win_LS1.exe
    2010-02-05 17:10 . 2009-11-18 03:33 33558 ----a-w- c:\programdata\Google\Toolbar for Firefox\Firefox_Toolbar_Uninstaller.exe
    2010-02-02 01:07 . 2010-02-02 01:07 4276600 ----a-w- c:\users\Public\sp38062.exe
    2010-02-02 00:58 . 2010-02-02 00:58 10717624 ----a-w- c:\users\Public\sp36542.exe
    2010-02-01 20:09 . 2010-02-01 20:07 23112 ----a-w- c:\windows\hpqins15.dat
    2010-01-30 12:43 . 2010-01-30 03:23 77376 ----a-w- c:\windows\hpqins05.dat
    2010-01-28 15:58 . 2008-06-04 11:42 4956 ----a-w- c:\users\Owner\AppData\Roaming\wklnhst.dat
    2010-01-25 12:00 . 2010-02-23 20:43 471552 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-01-25 12:00 . 2010-02-23 20:43 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-25 12:00 . 2010-02-23 20:43 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-01-25 12:00 . 2010-02-23 20:43 471552 ----a-w- c:\windows\system32\secproc.dll
    2010-01-25 11:58 . 2010-02-23 20:43 332288 ----a-w- c:\windows\system32\msdrm.dll
    2010-01-25 08:21 . 2010-02-23 20:43 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-01-25 08:21 . 2010-02-23 20:43 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-25 08:21 . 2010-02-23 20:43 518144 ----a-w- c:\windows\system32\RMActivate.exe
    2010-01-25 08:21 . 2010-02-23 20:43 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-01-23 09:26 . 2010-02-23 20:44 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-01-23 01:08 . 2010-01-22 23:12 186815 ----a-w- c:\windows\hpwins23.dat
    2009-07-23 18:30 . 2009-07-23 18:30 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2009-05-29 16:57 . 2009-05-28 00:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    2009-05-29 16:57 . 2009-05-28 00:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC "= "c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "ehTray.exe "= "c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "Google Update "= "c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "WMPNSCFG "= "c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "ISUSPM "= "c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "Online Backup Auto Update "= "c:\program files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe" [2009-09-19 131072]
    "Vault Explorer Cache Watcher "= "c:\program files\Verizon\Online Backup\vewatch.exe" [2009-07-30 28672]
    "AdobeCS4ServiceManager "= "c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "BlackBerryAutoUpdate "= "c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
    "Windows Mobile-based device management "= "c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "GrpConv "= "grpconv -o" [X]
    "IndexCleaner "= "c:\program files\Verizon\Verizon Internet Security Suite\IdxClnR.exe" [2009-04-22 65264]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2009-11-19 1807704]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA "= 0 (0x0)
    "EnableUIADesktopToggle "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2010-04-14 18:38 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux2 "=wdmaud.drv

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "
    path=
    backup=

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Calendar Sync.lnk]
    backup=c:\windows\pss\Google Calendar Sync.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Online Backup Tray.lnk]
    backup=c:\windows\pss\Online Backup Tray.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
    2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2009-07-23 18:30 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2008-09-02 19:26 133104 ----atw- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
    2007-10-25 21:33 563984 ----a-w- c:\program files\Common Files\Logishrd\LComMgr\Communications_Helper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2007-10-25 21:37 2178832 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
    2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-01-05 20:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
    2009-01-16 23:25 460216 ----a-w- c:\windows\System32\Adobe\Shockwave 11\SwHelper_1103472.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 19:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2008-09-14 14:44 144792 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-06-07 21:58 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    2006-11-17 21:58 815104 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
    2009-03-12 16:31 2303216 ----a-w- c:\program files\Verizon\VSP\VerizonServicepoint.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
    2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2 "=hex(b):8b,ce,f0,1f,a8,da,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1647119644-2749980030-1312532287-1000]
    "EnableNotificationsRef "=dword:00000003

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1647119644-2749980030-1312532287-500]
    "EnableNotificationsRef "=dword:00000002

    R2 AtiPolicyAgent;Ati External Event Utility AtiPolicyAgent;c:\windows\system32\9B13A86Dq.exe [x]
    R2 dev5_ap1;dev5_ap1;c:\phpdev5\apache\Apache.exe [2008-08-05 20480]
    R2 FilesystemWatcher;Filesystem Watcher;c:\program files\Verizon\Online Backup\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe [2008-09-02 24576]
    R3 Activ;Activ;c:\windows\system32\DRIVERS\Activ.sys [2008-06-16 15680]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    getPlusHelper REG_MULTI_SZ getPlusHelper
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPService REG_MULTI_SZ HPSLPSVC
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-19 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-01 00:48]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 18:27]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 18:27]

    2010-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1647119644-2749980030-1312532287-1000Core.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 19:26]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1647119644-2749980030-1312532287-1000UA.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 19:26]

    2010-04-15 c:\windows\Tasks\OnlineBackupManager.job
    - c:\program files\Verizon\Online Backup\SyncNShare\OnlineBackup.SyncNShare.exe [2009-09-19 04:11]

    2010-04-20 c:\windows\Tasks\User_Feed_Synchronization-{6423E243-42D3-4145-8B37-F0BFB307FC59}.job
    - c:\windows\system32\msfeedssync.exe [2008-09-20 07:33]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
    IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
    IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
    DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ian14093.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.google.mozilla.com/firefox?client=firefox-a&rls=com.google:en-US:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ian14093.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Microsoft\Web Platform Installer\NPWPIDetector.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
    FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ian14093.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true.
    - - - - ORPHANS REMOVED - - - -

    HKLM-RunOnce-<NO NAME> - (no file)
    MSConfigStartUp-BigFix - c:\program files\Bigfix\bigfix.exe
    MSConfigStartUp-SandboxieControl - c:\program files\Sandboxie\SbieCtrl.exe
    MSConfigStartUp-Weather - c:\program files\AWS\WeatherBug\Weather.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-04-20 02:42
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HitmanPro35CrusaderBoot]
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    [1].exe\" /crusader:boot "
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    [1].exe\" /crusader:boot "


    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HitmanPro35CrusaderBoot]
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    "MSCurrentCountry "=dword:000000b5

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    Completion time: 2010-04-20 02:50:36
    ComboFix-quarantined-files.txt 2010-04-20 06:50

    Pre-Run: 67,169,865,728 bytes free
    Post-Run: 67,343,482,880 bytes free

    - - End Of File - - 09BD57065B6F9A2F676F3F2C3FFCD123
     
  5. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Safe mode still :Browser redirects have stopped tested 5-6 searches and google chrome up and running. I have not restarted the computer since combo fix ran . I have made no changes to the computer. *update 9:00am. restarted computer in normal mode and here are a few things I noticed: All is well no signs of ave popups, Chrome still good, no redirects, MS updater started on its own, . I realize I have just recovered from a bad virus and other maleware but when i open a program now takes along time to open, IE IE7 1min 10 sec. Google chrome 2 min. fire fox aprox 3-4 min other type programs IE Google earth 4-5 min. are we still seeing signs of the virus or is this a topic for a new post.
    Side note: browsers started in under 15 sec in safe mode. and before the virus about half the time they do now in regular mode. Looking for new antivirus, would like real time protection if available. Please advise.
     
    Last edited: 2010/04/20
  6. 2010/04/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Pretty good news, then.
    Don't worry about delays for now. We just started. The main goal was to make your computer more stable.
    As for security program, I suggest, you uninstall Verizon Suite and install ONE of these:
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
    Make sure to turn Windows firewall on.
    However, wait with the above changes until we're done with Combofix.

    My instructions say to run Combofix from desktop, so please, move the file.

    Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.
    Upload following files to http://www.virustotal.com/ for security check:
    c:\windows\system32\drivers\Activ.sys
    IMPORTANT! If the file is listed as already analyzed, click on Reanalyse file now button.
    Post scan results.
    If the result says 0/42, you don't have to post logs.


    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\9B13A86Dq.exe
    
    
    Folder::
    C:\32788R22FWJFW
    
    DirLook::
    c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}
    
    Driver::
    AtiPolicyAgent
    
    Registry::
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
     
  7. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    New error messages.

    step one moved combo fix. made sure check was on show all files.uploaded file to website. ran scan 0/41 (%0%) would post log but having error messages will explain.
    Icopied text to note pad followed instructions to the letter. as i merged text file with combo fix the following happened. Error message told me my file txt was misspelled so i deleted and redid ok, next error after merging was that combo fix had become corrupt and to re download from bleeping computer so i did. re merged the txt with new combo fix all went well until after the reboot i was waiting for the log to come up and some security program had a pop up saying that a file in combo fix was a virus, thats all it said but looked like a Verizon popup. Had to be MS security I hope because Verizon was shut off for scan. it went away before I could find my pen. so that is all I can tell you . log did post in note pad. Just after all this I tried to run hyjack this or open a browser and I receive these error messages.
    (IE) C:\Users\Owner\AppData\Local\Google\Application\chrome.exe
    llegal operation attempted on a registry key that has bee marked for deletion

    So I stopped and have done nothing since Im posting this on my alternate computer infected computer is on with desk top showing have done nothing else awaiting instructions. Broni Thank you for all your help and patients .
     
  8. 2010/04/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You need to restart computer.
     
  9. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Ahhh sorry that would be Acoms Razor
     
  10. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Updated Logs

    Logs per your request. Note: I mentioned updater started on its own earler found 8 or so updates but they have not been installed.


    Antivirus Version Last Update Result
    a-squared 4.5.0.50 2010.04.20 -
    AhnLab-V3 5.0.0.2 2010.04.20 -
    AntiVir 7.10.6.145 2010.04.20 -
    Antiy-AVL 2.0.3.7 2010.04.19 -
    Authentium 5.2.0.5 2010.04.20 -
    Avast 4.8.1351.0 2010.04.20 -
    Avast5 5.0.332.0 2010.04.20 -
    AVG 9.0.0.787 2010.04.20 -
    BitDefender 7.2 2010.04.20 -
    CAT-QuickHeal 10.00 2010.04.20 -
    ClamAV 0.96.0.3-git 2010.04.20 -
    Comodo 4653 2010.04.20 -
    DrWeb 5.0.2.03300 2010.04.20 -
    eSafe 7.0.17.0 2010.04.18 -
    eTrust-Vet 35.2.7436 2010.04.20 -
    F-Prot 4.5.1.85 2010.04.20 -
    F-Secure 9.0.15370.0 2010.04.20 -
    Fortinet 4.0.14.0 2010.04.20 -
    GData 19 2010.04.20 -
    Ikarus T3.1.1.80.0 2010.04.20 -
    Jiangmin 13.0.900 2010.04.20 -
    Kaspersky 7.0.0.125 2010.04.20 -
    McAfee 5.400.0.1158 2010.04.20 -
    McAfee-GW-Edition 6.8.5 2010.04.20 -
    Microsoft 1.5703 2010.04.20 -
    NOD32 5045 2010.04.20 -
    Norman 6.04.11 2010.04.20 -
    nProtect 2010-04-20.01 2010.04.20 -
    Panda 10.0.2.7 2010.04.20 -
    PCTools 7.0.3.5 2010.04.20 -
    Prevx 3.0 2010.04.20 -
    Rising 22.44.01.03 2010.04.20 -
    Sophos 4.52.0 2010.04.20 -
    Sunbelt 6200 2010.04.20 -
    Symantec 20091.2.0.41 2010.04.20 -
    TheHacker 6.5.2.0.265 2010.04.20 -
    TrendMicro 9.120.0.1004 2010.04.20 -
    TrendMicro-HouseCall 9.120.0.1004 2010.04.20 -
    VBA32 3.12.12.4 2010.04.19 -
    ViRobot 2010.4.19.2284 2010.04.20 -
    VirusBuster 5.0.27.0 2010.04.20 -

    Additional information
    File size: 15680 bytes
    MD5...: 437fb166de7d17a8dc77b9ffc0bea13e
    SHA1..: becb5afcd1057c1cfe28562d6f3e790a21d3ea6c
    SHA256: cc94ac06a3096bcd05c960f98cb491a976f1291a44fb0dd6b328a91e1ca1f5f0
    ssdeep: 192:BfEZn60xN0n1n2KswucFhQmN9lg3GnvHCldBw8qEjASrL986FlCoVo08L+8w<BR>X8Fk:BkxNqn2Ksw/g2fIwSHW6T8RUX8Fwr<BR>
    PEiD..: -
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x2d05<BR>timedatestamp.....: 0x485516af (Sun Jun 15 13:18:39 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 6 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x480 0x2140 0x2180 6.47 2bf13e0bd87991b9c51fe45ecb98b86b<BR>.rdata 0x2600 0x494 0x500 3.37 bd5720def3e99dfd04dc6dc68b4ca5a9<BR>.data 0x2b00 0x1c8 0x200 1.75 749ef383ede0c2d470741aec1cfed926<BR>INIT 0x2d00 0x5b4 0x600 5.19 7ea694edd05a7981656a07312070f66b<BR>.rsrc 0x3300 0x380 0x380 3.30 aaf60896a6b5c6c653ee4b9b832a9d24<BR>.reloc 0x3680 0x28a 0x300 5.32 ac63f90471e935b893c57d263ced553c<BR><BR>( 3 imports ) <BR>&gt; ntoskrnl.exe: MmMapLockedPagesSpecifyCache, MmProbeAndLockProcessPages, IoAllocateMdl, ZwClose, ObfDereferenceObject, ObReferenceObjectByHandle, ZwQueryInformationProcess, memcpy, RtlVolumeDeviceToDosName, vDbgPrintEx, RtlQueryRegistryValues, ObQueryNameString, PsGetCurrentProcessId, KeTickCount, KeBugCheckEx, ExAllocatePoolWithTag, memset, RtlAppendUnicodeStringToString, ExFreePoolWithTag, MmUnlockPages, IoFreeMdl, PsGetVersion, KeAddSystemServiceTable, MmIsAddressValid, KeServiceDescriptorTable, DbgPrint, PsSetLoadImageNotifyRoutine, CmRegisterCallback, CmUnRegisterCallback, PsRemoveLoadImageNotifyRoutine, ZwOpenProcess, PsSetCreateProcessNotifyRoutine, RtlUnwind<BR>&gt; HAL.dll: KeGetCurrentIrql<BR>&gt; FLTMGR.SYS: FltParseFileNameInformation, FltReleaseFileNameInformation, FltGetVolumeContext, FltReleaseContext, FltAllocateContext, FltGetDiskDeviceObject, FltGetVolumeProperties, FltSetVolumeContext, FltRegisterFilter, FltStartFiltering, FltDeleteVolumeContext, FltCloseCommunicationPort, FltUnregisterFilter, FltGetFileNameInformation<BR><BR>( 0 exports ) <BR>
    RDS...: NSRL Reference Data Set<BR>-
    pdfid.: -
    trid..: Win32 Executable Generic (58.4%)<BR>Clipper DOS Executable (13.8%)<BR>Generic Win/DOS Executable (13.7%)<BR>DOS Executable Generic (13.7%)<BR>VXD Driver (0.2%)
    sigcheck:<BR>publisher....: Rapidware Pty Ltd<BR>copyright....: (c) 2007-08 Rapidware Pty Ltd<BR>product......: Rapidware OS Activity Monitor<BR>description..: Rapidware OS Activity Monitor Driver<BR>original name: Activ.sys<BR>internal name: Activ.sys<BR>file version.: 1.2.0.0<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
    Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99


    Antivirus Version Last Update Result
    a-squared 4.5.0.50 2010.04.20 -
    AhnLab-V3 5.0.0.2 2010.04.20 -
    AntiVir 7.10.6.145 2010.04.20 -
    Antiy-AVL 2.0.3.7 2010.04.19 -
    Authentium 5.2.0.5 2010.04.20 -
    Avast 4.8.1351.0 2010.04.20 -
    Avast5 5.0.332.0 2010.04.20 -
    AVG 9.0.0.787 2010.04.20 -
    BitDefender 7.2 2010.04.20 -
    CAT-QuickHeal 10.00 2010.04.20 -
    ClamAV 0.96.0.3-git 2010.04.20 -
    Comodo 4653 2010.04.20 -
    DrWeb 5.0.2.03300 2010.04.20 -
    eSafe 7.0.17.0 2010.04.18 -
    eTrust-Vet 35.2.7436 2010.04.20 -
    F-Prot 4.5.1.85 2010.04.20 -
    F-Secure 9.0.15370.0 2010.04.20 -
    Fortinet 4.0.14.0 2010.04.20 -
    GData 19 2010.04.20 -
    Ikarus T3.1.1.80.0 2010.04.20 -
    Jiangmin 13.0.900 2010.04.20 -
    Kaspersky 7.0.0.125 2010.04.20 -
    McAfee 5.400.0.1158 2010.04.20 -
    McAfee-GW-Edition 6.8.5 2010.04.20 -
    Microsoft 1.5703 2010.04.20 -
    NOD32 5045 2010.04.20 -
    Norman 6.04.11 2010.04.20 -
    nProtect 2010-04-20.01 2010.04.20 -
    Panda 10.0.2.7 2010.04.20 -
    PCTools 7.0.3.5 2010.04.20 -
    Prevx 3.0 2010.04.20 -
    Rising 22.44.01.03 2010.04.20 -
    Sophos 4.52.0 2010.04.20 -
    Sunbelt 6200 2010.04.20 -
    Symantec 20091.2.0.41 2010.04.20 -
    TheHacker 6.5.2.0.265 2010.04.20 -
    TrendMicro 9.120.0.1004 2010.04.20 -
    TrendMicro-HouseCall 9.120.0.1004 2010.04.20 -
    VBA32 3.12.12.4 2010.04.19 -
    ViRobot 2010.4.19.2284 2010.04.20 -
    VirusBuster 5.0.27.0 2010.04.20 -

    Additional information
    File size: 15680 bytes
    MD5...: 437fb166de7d17a8dc77b9ffc0bea13e
    SHA1..: becb5afcd1057c1cfe28562d6f3e790a21d3ea6c
    SHA256: cc94ac06a3096bcd05c960f98cb491a976f1291a44fb0dd6b328a91e1ca1f5f0
    ssdeep: 192:BfEZn60xN0n1n2KswucFhQmN9lg3GnvHCldBw8qEjASrL986FlCoVo08L+8w<BR>X8Fk:BkxNqn2Ksw/g2fIwSHW6T8RUX8Fwr<BR>
    PEiD..: -
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x2d05<BR>timedatestamp.....: 0x485516af (Sun Jun 15 13:18:39 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 6 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x480 0x2140 0x2180 6.47 2bf13e0bd87991b9c51fe45ecb98b86b<BR>.rdata 0x2600 0x494 0x500 3.37 bd5720def3e99dfd04dc6dc68b4ca5a9<BR>.data 0x2b00 0x1c8 0x200 1.75 749ef383ede0c2d470741aec1cfed926<BR>INIT 0x2d00 0x5b4 0x600 5.19 7ea694edd05a7981656a07312070f66b<BR>.rsrc 0x3300 0x380 0x380 3.30 aaf60896a6b5c6c653ee4b9b832a9d24<BR>.reloc 0x3680 0x28a 0x300 5.32 ac63f90471e935b893c57d263ced553c<BR><BR>( 3 imports ) <BR>&gt; ntoskrnl.exe: MmMapLockedPagesSpecifyCache, MmProbeAndLockProcessPages, IoAllocateMdl, ZwClose, ObfDereferenceObject, ObReferenceObjectByHandle, ZwQueryInformationProcess, memcpy, RtlVolumeDeviceToDosName, vDbgPrintEx, RtlQueryRegistryValues, ObQueryNameString, PsGetCurrentProcessId, KeTickCount, KeBugCheckEx, ExAllocatePoolWithTag, memset, RtlAppendUnicodeStringToString, ExFreePoolWithTag, MmUnlockPages, IoFreeMdl, PsGetVersion, KeAddSystemServiceTable, MmIsAddressValid, KeServiceDescriptorTable, DbgPrint, PsSetLoadImageNotifyRoutine, CmRegisterCallback, CmUnRegisterCallback, PsRemoveLoadImageNotifyRoutine, ZwOpenProcess, PsSetCreateProcessNotifyRoutine, RtlUnwind<BR>&gt; HAL.dll: KeGetCurrentIrql<BR>&gt; FLTMGR.SYS: FltParseFileNameInformation, FltReleaseFileNameInformation, FltGetVolumeContext, FltReleaseContext, FltAllocateContext, FltGetDiskDeviceObject, FltGetVolumeProperties, FltSetVolumeContext, FltRegisterFilter, FltStartFiltering, FltDeleteVolumeContext, FltCloseCommunicationPort, FltUnregisterFilter, FltGetFileNameInformation<BR><BR>( 0 exports ) <BR>
    RDS...: NSRL Reference Data Set<BR>-
    pdfid.: -
    trid..: Win32 Executable Generic (58.4%)<BR>Clipper DOS Executable (13.8%)<BR>Generic Win/DOS Executable (13.7%)<BR>DOS Executable Generic (13.7%)<BR>VXD Driver (0.2%)
    sigcheck:<BR>publisher....: Rapidware Pty Ltd<BR>copyright....: (c) 2007-08 Rapidware Pty Ltd<BR>product......: Rapidware OS Activity Monitor<BR>description..: Rapidware OS Activity Monitor Driver<BR>original name: Activ.sys<BR>internal name: Activ.sys<BR>file version.: 1.2.0.0<BR>comments.....: n/a<BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
    Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:29:58 PM, on 4/20/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
    C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe
    C:\Program Files\Verizon\Online Backup\vewatch.exe
    C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
    C:\WINDOWS\WindowsMobile\wmdcBase.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\System32\mobsync.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Users\Owner\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\wuauclt.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Online Backup Auto Update] "C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe "
    O4 - HKLM\..\Run: [Vault Explorer Cache Watcher] C:\Program Files\Verizon\Online Backup\vewatch.exe
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
    O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemywifi.verizon.net/sdcCommon/download/WIFI/Verizon WiFi Installer.cab
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: dev5_ap1 - Unknown owner - C:\phpdev5\apache\Apache.exe
    O23 - Service: Filesystem Watcher (FilesystemWatcher) - DigiData Corp. - C:\Program Files\Verizon\Online Backup\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Update Service (gupdate1ca0bc343ab1d86) (gupdate1ca0bc343ab1d86) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Hitman Pro 3.5 Crusader (Boot) (HitmanPro35CrusaderBoot) - Unknown owner - C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35[1].exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Online Backup Scheduler (OnlineBackupSchedulerService) - Unknown owner - C:\Program Files\Verizon\Online Backup\Scheduler\OnlineBackup.SchedulerService.exe
    O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
    O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Radialpoint SafeCare Inc. - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
    O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
    O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

    --
    End of file - 12495 bytes
     
  11. 2010/04/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Delete your Combofix file, download fresh one and retry to run my script from my post #5.
    If it still doesn't work, try Safe Mode.
     
  12. 2010/04/20
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    safemode 2 tries

    ComboFix 10-04-19.08 - Owner 04/20/2010 23:32:07.8.2 - x86 NETWORK
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.957.182 [GMT -4:00]
    Running from: c:\users\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\users\Owner\Desktop\CFScript.txt
    AV: Verizon Internet Security Suite Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
    FW: Verizon Internet Security Suite Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
    SP: Antispyware *disabled* (Updated) {527D3A1B-E68A-4CA3-8771-74CC42308FE9}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Verizon Internet Security Suite Anti-Spyware *enabled* (Updated) {307352C6-1CBD-11DB-8AF6-B622A1EF5492}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    * Created a new restore point

    FILE ::
    "c:\windows\system32\9B13A86Dq.exe "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\32788R22FWJFW
    c:\32788r22fwjfw\EN-US\cmd.cfxxe.mui

    .
    ((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
    .

    2010-04-21 03:46 . 2010-04-21 03:50 -------- d-----w- c:\users\Owner\AppData\Local\temp
    2010-04-21 03:46 . 2010-04-21 03:46 -------- d-----w- c:\users\Public\AppData\Local\temp
    2010-04-21 03:46 . 2010-04-21 03:46 -------- d-----w- c:\users\Guest\AppData\Local\temp
    2010-04-21 03:46 . 2010-04-21 03:46 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-04-20 14:30 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2010-04-20 14:30 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2010-04-20 14:30 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2010-04-20 14:29 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2010-04-20 14:29 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
    2010-04-20 14:29 . 2010-03-04 17:33 430080 ----a-w- c:\windows\system32\vbscript.dll
    2010-04-20 14:27 . 2010-03-09 15:42 834048 ----a-w- c:\windows\system32\wininet.dll
    2010-04-20 14:27 . 2010-03-09 16:25 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-04-20 14:26 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2010-04-20 14:26 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
    2010-04-20 14:26 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
    2010-04-20 14:17 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
    2010-04-20 13:56 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
    2010-04-19 13:15 . 2010-03-30 04:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-19 13:15 . 2010-03-30 04:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-19 13:15 . 2010-04-19 23:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-19 00:06 . 2010-04-19 16:17 -------- d-----w- c:\users\Owner\AppData\Roaming\CyberScrub
    2010-04-18 22:10 . 2010-04-18 22:10 -------- d-----w- c:\program files\Rapidware
    2010-04-18 22:08 . 2008-06-16 03:18 15680 ----a-w- c:\windows\system32\drivers\Activ.sys
    2010-04-18 01:45 . 2010-04-18 01:45 -------- d-----w- c:\program files\Free Process Viewer
    2010-04-17 22:36 . 2010-04-17 22:47 -------- d-----w- c:\program files\Windows Live Safety Center
    2010-04-17 19:21 . 2010-04-17 19:21 -------- d-----w- c:\program files\ESET
    2010-04-17 18:49 . 2010-04-17 19:01 -------- d-----w- c:\users\Owner\AppData\Roaming\ieSpell
    2010-04-17 18:47 . 2010-04-17 18:47 -------- d-----w- c:\program files\ieSpell
    2010-04-15 18:58 . 2010-04-18 23:55 12872 ----a-w- c:\windows\system32\bootdelete.exe
    2010-04-15 18:34 . 2010-04-19 12:57 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
    2010-04-15 18:34 . 2010-04-15 18:58 -------- d-----w- c:\programdata\Hitman Pro
    2010-04-15 18:33 . 2010-04-15 18:33 -------- d-----w- c:\program files\Hitman Pro 3.5
    2010-04-15 13:03 . 2010-04-15 13:03 -------- d-----w- c:\windows\LMIB7CA.tmp
    2010-04-15 13:02 . 2010-04-15 19:32 -------- d-----w- c:\windows\LMI15FC.tmp
    2010-04-13 17:31 . 2010-04-13 17:31 -------- d-----w- c:\users\Owner\AppData\Local\ElevatedDiagnostics
    2010-04-13 16:58 . 2010-04-20 14:32 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
    2010-04-13 16:38 . 2010-04-13 17:25 -------- d-----w- c:\program files\Microsoft ATS
    2010-04-12 23:46 . 2010-04-13 22:12 -------- d-----w- c:\windows\LMI2B10.tmp
    2010-04-12 16:35 . 2010-04-12 16:35 -------- d-----w- c:\users\Owner\AppData\Local\ICS
    2010-04-12 16:35 . 2010-04-13 01:48 -------- d-----w- c:\windows\LMI6CAD.tmp
    2010-04-12 13:33 . 2010-04-12 13:33 -------- d-----w- c:\programdata\avG
    2010-04-12 00:12 . 2010-04-16 14:31 -------- d-----w- c:\programdata\SecTaskMan
    2010-04-11 19:27 . 2010-04-11 19:27 -------- d-----w- c:\program files\Bing Bar Installer
    2010-04-11 19:10 . 2010-04-11 19:10 -------- d-----w- c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}
    2010-04-11 01:24 . 2010-04-11 01:25 -------- d-----w- C:\spyware
    2010-04-10 18:37 . 2010-04-10 18:37 -------- d-----w- c:\users\Owner\AppData\Roaming\HPAppData
    2010-04-09 22:21 . 2010-04-09 22:21 -------- d-----w- c:\program files\Uniblue
    2010-04-09 22:19 . 2010-04-09 22:19 -------- d-----w- c:\users\Owner\AppData\Roaming\Uniblue

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-04-21 00:34 . 2009-01-02 01:46 389819168 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2010-04-20 23:27 . 2009-05-10 21:25 256 ----a-w- c:\windows\system32\pool.bin
    2010-04-20 23:16 . 2009-01-02 01:46 5221928 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2010-04-20 15:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-04-20 05:05 . 2008-05-30 20:50 -------- d-----w- c:\program files\Google
    2010-04-19 23:48 . 2008-06-07 21:58 -------- d-----w- c:\programdata\Google Updater
    2010-04-19 13:02 . 2009-07-14 00:25 1356 ----a-w- c:\users\Owner\AppData\Local\d3d9caps.dat
    2010-04-16 14:58 . 2008-05-30 18:15 111032 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-04-16 14:29 . 2008-06-25 00:01 -------- d-----w- c:\program files\Yahoo!
    2010-04-16 14:16 . 2008-05-30 20:35 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-04-16 13:57 . 2010-03-21 23:20 -------- d-----w- c:\program files\Sandboxie
    2010-04-16 13:43 . 2008-05-30 20:45 -------- d-----w- c:\programdata\Microsoft Help
    2010-04-16 13:40 . 2008-05-30 20:48 -------- d-----w- c:\program files\Microsoft Works
    2010-04-16 13:32 . 2010-03-22 01:39 -------- d-----w- c:\program files\Citrix
    2010-04-16 13:19 . 2008-05-30 20:58 -------- d-----w- c:\program files\BigFix
    2010-04-16 13:18 . 2010-02-11 22:19 -------- d-----w- c:\program files\Common Files\Akamai
    2010-04-14 18:38 . 2009-02-27 05:03 -------- d-----w- c:\program files\SUPERAntiSpyware
    2010-04-12 15:44 . 2009-02-27 04:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-04-09 07:22 . 2009-05-11 13:07 -------- d-----w- c:\program files\Any Video Converter
    2010-04-09 07:22 . 2009-05-11 13:07 -------- d-----w- c:\users\Owner\AppData\Roaming\Any Video Converter
    2010-03-22 01:39 . 2010-03-22 01:39 72080 ----a-w- c:\users\Owner\g2mdlhlpx.exe
    2010-03-12 01:14 . 2009-01-06 02:21 -------- d-----w- c:\program files\Common Files\Roxio Shared
    2010-03-12 01:13 . 2009-01-06 02:21 -------- d-----w- c:\programdata\Roxio
    2010-03-12 01:10 . 2008-06-08 14:09 -------- d-----w- c:\program files\Common Files\PX Storage Engine
    2010-03-11 23:57 . 2010-03-11 23:57 -------- d-----w- c:\programdata\Research In Motion
    2010-03-11 23:45 . 2008-07-06 20:21 -------- d-----w- c:\users\Owner\AppData\Roaming\InstallShield
    2010-03-11 05:35 . 2008-11-12 16:41 -------- d-----w- c:\program files\Movie Maker 2.6
    2010-02-24 14:16 . 2009-10-02 19:19 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-24 09:33 . 2010-02-11 01:34 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
    2010-02-20 23:06 . 2010-03-11 05:30 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2010-02-20 23:05 . 2010-03-11 05:30 30720 ----a-w- c:\windows\system32\httpapi.dll
    2010-02-20 20:53 . 2010-03-11 05:30 411648 ----a-w- c:\windows\system32\drivers\http.sys
    2010-02-11 22:34 . 2010-02-11 22:25 1228304 ----a-w- c:\users\Owner\ADBEFLPRCS4Win_LS1.exe
    2010-02-02 01:07 . 2010-02-02 01:07 4276600 ----a-w- c:\users\Public\sp38062.exe
    2010-02-02 00:58 . 2010-02-02 00:58 10717624 ----a-w- c:\users\Public\sp36542.exe
    2010-02-01 20:09 . 2010-02-01 20:07 23112 ----a-w- c:\windows\hpqins15.dat
    2010-01-30 12:43 . 2010-01-30 03:23 77376 ----a-w- c:\windows\hpqins05.dat
    2010-01-28 15:58 . 2008-06-04 11:42 4956 ----a-w- c:\users\Owner\AppData\Roaming\wklnhst.dat
    2010-01-25 12:00 . 2010-02-23 20:43 471552 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-01-25 12:00 . 2010-02-23 20:43 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-25 12:00 . 2010-02-23 20:43 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-01-25 12:00 . 2010-02-23 20:43 471552 ----a-w- c:\windows\system32\secproc.dll
    2010-01-25 11:58 . 2010-02-23 20:43 332288 ----a-w- c:\windows\system32\msdrm.dll
    2010-01-25 08:21 . 2010-02-23 20:43 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-01-25 08:21 . 2010-02-23 20:43 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-25 08:21 . 2010-02-23 20:43 518144 ----a-w- c:\windows\system32\RMActivate.exe
    2010-01-25 08:21 . 2010-02-23 20:43 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-01-23 09:26 . 2010-02-23 20:44 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-01-23 01:08 . 2010-01-22 23:12 186815 ----a-w- c:\windows\hpwins23.dat
    2009-07-23 18:30 . 2009-07-23 18:30 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2009-05-29 16:57 . 2009-05-28 00:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    2009-05-29 16:57 . 2009-05-28 00:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    .

    (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    ---- Directory of c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add} ----

    2010-03-23 19:59 . 2010-03-23 19:59 8260 ----a-w- c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}\net8185.cat
    2010-03-23 06:17 . 2010-03-23 06:17 8369 ----a-w- c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}\net8185.inf
    2010-03-23 06:17 . 2010-03-23 06:17 1170464 ----a-w- c:\users\Owner\{2206ce3e-a7df-4850-9622-8ddeb4927add}\rtl85n86.sys


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC "= "c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "ehTray.exe "= "c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "Google Update "= "c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "WMPNSCFG "= "c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "ISUSPM "= "c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "IndexCleaner "= "c:\program files\Verizon\Verizon Internet Security Suite\IdxClnR.exe" [2009-04-22 65264]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
    "Online Backup Auto Update "= "c:\program files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe" [2009-09-19 131072]
    "Vault Explorer Cache Watcher "= "c:\program files\Verizon\Online Backup\vewatch.exe" [2009-07-30 28672]
    "AdobeCS4ServiceManager "= "c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "BlackBerryAutoUpdate "= "c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-11-20 623960]
    "Windows Mobile-based device management "= "c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "GrpConv "= "grpconv -o" [X]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2009-11-19 1807704]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA "= 0 (0x0)
    "EnableUIADesktopToggle "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2010-04-14 18:38 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux2 "=wdmaud.drv

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @= "Service "
    path=
    backup=

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Google Calendar Sync.lnk]
    backup=c:\windows\pss\Google Calendar Sync.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Online Backup Tray.lnk]
    backup=c:\windows\pss\Online Backup Tray.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
    2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2009-07-23 18:30 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2008-09-02 19:26 133104 ----atw- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
    2007-10-25 21:33 563984 ----a-w- c:\program files\Common Files\Logishrd\LComMgr\Communications_Helper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2007-10-25 21:37 2178832 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
    2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-01-05 20:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
    2009-01-16 23:25 460216 ----a-w- c:\windows\System32\Adobe\Shockwave 11\SwHelper_1103472.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 19:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2008-09-14 14:44 144792 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-06-07 21:58 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    2006-11-17 21:58 815104 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
    2009-03-12 16:31 2303216 ----a-w- c:\program files\Verizon\VSP\VerizonServicepoint.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
    2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2 "=hex(b):8b,ce,f0,1f,a8,da,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1647119644-2749980030-1312532287-1000]
    "EnableNotificationsRef "=dword:00000003

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1647119644-2749980030-1312532287-500]
    "EnableNotificationsRef "=dword:00000002

    R2 dev5_ap1;dev5_ap1;c:\phpdev5\apache\Apache.exe [2008-08-05 20480]
    R2 FilesystemWatcher;Filesystem Watcher;c:\program files\Verizon\Online Backup\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe [2008-09-02 24576]
    R3 Activ;Activ;c:\windows\system32\DRIVERS\Activ.sys [2008-06-16 15680]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    getPlusHelper REG_MULTI_SZ getPlusHelper
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPService REG_MULTI_SZ HPSLPSVC
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder

    2010-04-20 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-01 00:48]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 18:27]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-23 18:27]

    2010-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1647119644-2749980030-1312532287-1000Core.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 19:26]

    2010-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1647119644-2749980030-1312532287-1000UA.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 19:26]

    2010-04-20 c:\windows\Tasks\OnlineBackupManager.job
    - c:\program files\Verizon\Online Backup\SyncNShare\OnlineBackup.SyncNShare.exe [2009-09-19 04:11]

    2010-04-21 c:\windows\Tasks\User_Feed_Synchronization-{6423E243-42D3-4145-8B37-F0BFB307FC59}.job
    - c:\windows\system32\msfeedssync.exe [2008-09-20 07:33]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
    IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
    IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
    DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ian14093.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.google.mozilla.com/firefox?client=firefox-a&rls=com.google:en-US:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
    FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
    FF - component: c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ian14093.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true.
    - - - - ORPHANS REMOVED - - - -

    HKLM-RunOnce-<NO NAME> - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-04-20 23:52
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HitmanPro35CrusaderBoot]
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    [1].exe\" /crusader:boot "
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    [1].exe\" /crusader:boot "


    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HitmanPro35CrusaderBoot]
    "ImagePath "= "\ "c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    "MSCurrentCountry "=dword:000000b5

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'Explorer.exe'(1912)
    c:\program files\Verizon\Online Backup\LogicNP.EZNamespaceExtensions.dll
    c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\helppane.exe
    c:\windows\system32\wbem\unsecapp.exe
    .
    **************************************************************************
    .
    Completion time: 2010-04-21 00:03:56 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-04-21 04:03
    ComboFix2.txt 2010-04-20 20:04
    ComboFix3.txt 2010-04-20 06:50

    Pre-Run: 69,464,485,888 bytes free
    Post-Run: 69,353,865,216 bytes free

    - - End Of File - - 1531E54DD0E1E9ACDF9B8A98CC635E27
     
  13. 2010/04/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good :)

    Delete GMER file.

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start> "Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall "
    Click OK (Vista users - press Enter).
    Restart computer.

    ==================================================================

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scans.***


    STEP 1. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 2.
    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Installer under Version 2.0.2
    [DO NOT download version 2.0.3 (beta)]
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  14. 2010/04/21
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    new logs

    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    Database version: 4006

    Windows 6.0.6002 Service Pack 2 (Safe Mode)
    Internet Explorer 7.0.6002.18005

    4/21/2010 3:50:55 PM
    mbam-log-2010-04-21 (15-50-55).txt

    Scan type: Full scan (C:\|D:\|)
    Objects scanned: 406694
    Time elapsed: 1 hour(s), 58 minute(s), 19 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:24:04 PM, on 4/21/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
    C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe
    C:\Program Files\Verizon\Online Backup\vewatch.exe
    C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
    C:\WINDOWS\WindowsMobile\wmdcBase.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
    C:\Users\Owner\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
    C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Windows\system32\wuauclt.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Online Backup Auto Update] "C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe "
    O4 - HKLM\..\Run: [Vault Explorer Cache Watcher] C:\Program Files\Verizon\Online Backup\vewatch.exe
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
    O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemywifi.verizon.net/sdcCommon/download/WIFI/Verizon WiFi Installer.cab
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: dev5_ap1 - Unknown owner - C:\phpdev5\apache\Apache.exe
    O23 - Service: Filesystem Watcher (FilesystemWatcher) - DigiData Corp. - C:\Program Files\Verizon\Online Backup\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Update Service (gupdate1ca0bc343ab1d86) (gupdate1ca0bc343ab1d86) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Hitman Pro 3.5 Crusader (Boot) (HitmanPro35CrusaderBoot) - Unknown owner - C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35[1].exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Online Backup Scheduler (OnlineBackupSchedulerService) - Unknown owner - C:\Program Files\Verizon\Online Backup\Scheduler\OnlineBackup.SchedulerService.exe
    O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
    O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Radialpoint SafeCare Inc. - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
    O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
    O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

    --
    End of file - 12509 bytes
     
  15. 2010/04/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very good :)

    Now, this is optional, but I'd suggest, you uninstall Verizon Security Suite and move to something better.
    I propose ONE of these:
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
    If you decide to go this way, make sure to turn Windows firewall on and run full scan with newly installed AV program.
    Report on any findings.

    Regardless of the above....

    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    2. Go to Kaspersky website and perform an online antivirus scan.

    1. Disable your active antivirus program.
    2. Read through the requirements and privacy statement and click on Accept button.
    3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    4. When the downloads have finished, click on Settings.
    5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, Adware, Dialers, and other potentially dangerous programs
      [*] Archives
      [*] Mail databases
    6. Click on My Computer under Scan.
    7. Once the scan is complete, it will display the results. Click on View Scan Report.
    8. You will see a list of infected items there. Click on Save Report As....
    9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

    Post fresh HijackThis log as well.
     
  16. 2010/04/21
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Ive read many pages and still cant find how to run IE7 vista in admin mode. I tried to creat a shortcut and right click go to properties advanced but run as admin is greyd out. My user acount is set to admin. Can run scan till this is resolved. Thanks for the help.
     
  17. 2010/04/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try this....

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Push Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    Post fresh HJT log as well.
     
  18. 2010/04/22
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Broni ...started scan as directed scan finished 3 errors . 2 were taken care of one caused a scan error but yet it showed a complete scan. I went to export log and my browser died. Started a second scan this morning came home was at 46 percent and my monitor died. ran a test on the inverter all well LCD OK just needs a bulb so in the mean time hooked up a free standing monitor switched the desk top over and have restarted scan will post upon completion. sorry for the delay.
     
  19. 2010/04/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Not a problem. There is no rush, when dealing with malware issues :)
     
  20. 2010/04/23
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Broni: Update still scanning 49% 16.5 hours will post when done. Thank You.
     
  21. 2010/04/23
    irolder67

    irolder67 Inactive Thread Starter

    Joined:
    2010/04/19
    Messages:
    23
    Likes Received:
    0
    Logs to post.

    Eset scan came up clean. nothing found. no log to export.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:40:39 PM, on 4/23/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Verizon\Verizon Internet Security Suite\rps.exe
    C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe
    C:\Program Files\Verizon\Online Backup\vewatch.exe
    C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
    C:\WINDOWS\WindowsMobile\wmdcBase.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
    C:\Users\Owner\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaMonitor.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Verizon Internet Security Suite\pkR.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Online Backup Auto Update] "C:\Program Files\Verizon\Online Backup\Auto Update\OnlineBackup.UpdateSystemTray.exe "
    O4 - HKLM\..\Run: [Vault Explorer Cache Watcher] C:\Program Files\Verizon\Online Backup\vewatch.exe
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
    O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe "
    O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemywifi.verizon.net/sdcCommon/download/WIFI/Verizon WiFi Installer.cab
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.8.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
    O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: dev5_ap1 - Unknown owner - C:\phpdev5\apache\Apache.exe
    O23 - Service: Filesystem Watcher (FilesystemWatcher) - DigiData Corp. - C:\Program Files\Verizon\Online Backup\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Desktop Manager 5.8.811.4345 (GoogleDesktopManager-110408-113106) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Update Service (gupdate1ca0bc343ab1d86) (gupdate1ca0bc343ab1d86) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Hitman Pro 3.5 Crusader (Boot) (HitmanPro35CrusaderBoot) - Unknown owner - C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWYUBY7F\HitmanPro35[1].exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Online Backup Scheduler (OnlineBackupSchedulerService) - Unknown owner - C:\Program Files\Verizon\Online Backup\Scheduler\OnlineBackup.SchedulerService.exe
    O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
    O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
    O23 - Service: Verizon Internet Security Suite (Radialpoint Security Services) - Radialpoint SafeCare Inc. - C:\Program Files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe
    O23 - Service: Verizon Internet Security Suite SafeConnectAgent (RadialpointSafeConnectAgent) - Sana Security - C:\Program Files\Verizon\Verizon Internet Security Suite\SafeConnect\Bin\SanaAgent.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
    O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Verizon - C:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exe

    --
    End of file - 12476 bytes

    So far so good I hope. Ready for next step.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.