Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
May 2 2009, 08:48 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 2-May 09 Member No.: 327,670 |
Edit: One of the anti-malware... things I use detects a VAIO update file / program as a trojan (I think it's COMODO BOClean, but it could be SUPERAntiSpyware), but I've told it to not delete the file because it was a VAIO program. Do you think I should have it removed or tell it to ignore the file or anything? Thanks. DDS (Ver_09-03-16.01) - NTFSx86 Run by user at 21:37:39.07 on Sat 05/02/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.852 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Stardock\MyColors\VistaSrv.exe C:\Program Files\Stardock\MyColors\WBVista.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Comodo\CBOClean\BOCORE.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Windows\system32\lxczcoms.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Windows\system32\stacsv.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Comodo\CBOClean\BOC427.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Apoint\ApMsgFwd.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Apoint\Apvfb.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Apoint\Apntex.exe C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE C:\PROGRAM FILES\STARDOCK\OBJECTDOCK\OBJECTDOCK.EXE C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE C:\Users\user\AppData\Roaming\Maxthon2\Maxthon.exe C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P0YZQDKA\dds[2].scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mDefault_Page_URL = hxxp://www.sony.com/vaiopeople mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 4.0\aoltb.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 4.0\aoltb.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File uRun: [<NO NAME>] uRun: [Google Update] "c:\users\user\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [VWLASU] "c:\program files\sony\vaio pc wireless lan wizard\AutoLaunchWLASU.exe" mRun: [VAIOSurvey] c:\program files\sony\vaio survey\Vista VAIO Survey.exe mRun: [VAIO Center Access Bar] "c:\program files\sony\vaio center access bar\VCAB.exe" 1 mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [lxczbmgr.exe] "c:\program files\lexmark 1200 series\lxczbmgr.exe" mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [BOC-427] c:\progra~1\comodo\cboclean\BOC427.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12 \ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Add animation to IncrediMail Style Box - c:\program files\incredimail\bin\resources\WebMenuImg.htm IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll/206 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 4.0\aoltb.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: microsoft.com\www DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab DPF: {0CC52A09-A146-4AC4-85E5-B9A575CA8196} - hxxp://www.ace-onlines.com/Downloads/pc_info.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {4DD988A3-8A9A-4CC1-A763-F822C09E4315} - hxxp://www.va-sa-ra.co.jp/mgx/win/MGXPlugin.cab DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} - hxxp://www.srtest.com/srl_bin/sysreqlab_ind.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} - hxxp://fate.netgame.com/launch/object/mglaunch_USAv1004.cab DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab DPF: {AB4ADC0F-2B4B-4B08-8B5C-CA4D6188A180} - hxxp://config.hyosungcdn.com/download/p3xset.cab DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll Notify: WBSrv - c:\progra~1\stardock\object~2\window~1\wbsrv.dll AppInit_DLLs: avgrsstx.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\mcpcore.dll SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes\deskscapes.dll STS: Stardock Vista ControlPanel Extension: {ec654325-1273-c2a9-2b7c-45d29bce68fd} - c:\program files\stardock\object desktop\deskscapes\DesktopControlPanel.dll STS: StardockDreamController: {ec654325-1273-c2a9-2b7c-45d29bce68ff} - c:\program files\stardock\object desktop\deskscapes\DreamControl.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("network.protocol-handler.warn-external.veoh2", false); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-16 325128] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-9-3 8944] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-9-3 55024] R2 BOCore;BOCore;c:\program files\comodo\cboclean\BOCore.exe [2008-11-12 73464] R2 lxcz_device;lxcz_device;c:\windows\system32\lxczcoms.exe -service --> c:\windows\system32\lxczcoms.exe -service [?] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632] R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2007-8-1 75008] R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2007-8-1 43904] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-9-3 7408] R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2007-8-1 31104] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-8-1 812544] S2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe --> c:\progra~1\avg\avg8\avgwdsvc.exe [?] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2007-8-1 28464] S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\stumbleupon\StumbleUponUpdateService.exe [2009-4-12 120168] S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\sony\vaio media integrated server\UCLS.exe [2007-8-17 745472] S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\sony\vaio media integrated server\platform\SV_Httpd.exe [2007-8-17 397312] S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\sony\vaio media integrated server\platform\UPnPFramework.exe [2007-8-17 1089536] S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2007-8-1 292152] S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2007-8-1 79736] ============== File Associations =============== txtfile=c:\windows\NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-05-02 13:23 <DIR> --d----- c:\programdata\Cobian 2009-05-02 13:23 <DIR> --d----- c:\progra~2\Cobian 2009-05-02 13:22 <DIR> --d----- c:\program files\Cobian Backup 9 2009-05-02 12:50 <DIR> --d----- c:\program files\Runtime Software 2009-04-24 23:08 <DIR> --d----- c:\users\user\appdata\roaming\Red Kawa 2009-04-24 23:04 <DIR> --d----- c:\program files\Regensoft 2009-04-24 23:04 <DIR> --d----- c:\program files\AviSynth 2.5 2009-04-24 23:04 <DIR> --d----- c:\program files\Red Kawa 2009-04-21 11:36 376,832 a------- c:\windows\system32\winhttp.dll 2009-04-21 11:36 562,176 a------- c:\windows\system32\msdtcprx.dll 2009-04-21 11:36 38,912 a------- c:\windows\system32\xolehlp.dll 2009-04-18 11:00 <DIR> --d----- c:\program files\Taskbar Shuffle 2009-04-16 10:50 <DIR> --d----- c:\program files\Sims2Pack Clean Installer 2009-04-15 21:23 <DIR> --d----- c:\program files\OpenPandora 2009-04-14 22:58 <DIR> --d----- c:\program files\common files\xing shared 2009-04-14 14:11 <DIR> --d----- c:\program files\StumbleUpon 2009-04-08 21:20 244 a---h--- C:\sqmnoopt08.sqm 2009-04-08 21:20 232 a---h--- C:\sqmdata08.sqm 2009-04-07 22:37 <DIR> --d----- c:\program files\Trillian Astra 2009-04-06 16:18 107,368 a------- c:\windows\system32\GEARAspi.dll 2009-04-06 16:18 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-04-06 16:18 <DIR> --d----- c:\program files\iPod 2009-04-06 16:18 <DIR> --d----- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-06 16:18 <DIR> --d----- c:\program files\iTunes 2009-04-06 16:18 <DIR> --d----- c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} ==================== Find3M ==================== 2009-03-23 07:53 143,360 a------- c:\windows\inf\infstrng.dat 2009-03-23 07:53 86,016 a------- c:\windows\inf\infstor.dat 2009-03-23 07:53 86,016 a------- c:\windows\inf\infpub.dat 2009-03-16 23:38 40,960 a------- c:\windows\apppatch\apihex86.dll 2009-03-16 23:38 13,824 a------- c:\windows\system32\apilogen.dll 2009-03-16 23:38 24,064 a------- c:\windows\system32\amxread.dll 2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll 2009-03-08 07:34 914,944 a------- c:\windows\system32\wininet.dll 2009-03-08 07:34 43,008 a------- c:\windows\system32\licmgr10.dll 2009-03-08 07:33 18,944 a------- c:\windows\system32\corpol.dll 2009-03-08 07:33 109,056 a------- c:\windows\system32\iesysprep.dll 2009-03-08 07:33 109,568 a------- c:\windows\system32\PDMSetup.exe 2009-03-08 07:33 132,608 a------- c:\windows\system32\ieUnatt.exe 2009-03-08 07:33 107,520 a------- c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 07:33 107,008 a------- c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 07:33 103,936 a------- c:\windows\system32\SetDepNx.exe 2009-03-08 07:33 420,352 a------- c:\windows\system32\vbscript.dll 2009-03-08 07:32 72,704 a------- c:\windows\system32\admparse.dll 2009-03-08 07:32 71,680 a------- c:\windows\system32\iesetup.dll 2009-03-08 07:32 66,560 a------- c:\windows\system32\wextract.exe 2009-03-08 07:32 169,472 a------- c:\windows\system32\iexpress.exe 2009-03-08 07:31 34,816 a------- c:\windows\system32\imgutil.dll 2009-03-08 07:31 48,128 a------- c:\windows\system32\mshtmler.dll 2009-03-08 07:31 45,568 a------- c:\windows\system32\mshta.exe 2009-03-08 07:22 156,160 a------- c:\windows\system32\msls31.dll 2009-03-05 23:59 1,900,544 a------- c:\windows\system32\usbaaplrc.dll 2009-03-05 23:59 36,864 a------- c:\windows\system32\drivers\usbaapl.sys 2009-03-03 00:46 3,599,328 a------- c:\windows\system32\ntkrnlpa.exe 2009-03-03 00:46 3,547,632 a------- c:\windows\system32\ntoskrnl.exe 2009-03-03 00:39 183,296 a------- c:\windows\system32\sdohlp.dll 2009-03-03 00:39 551,424 a------- c:\windows\system32\rpcss.dll 2009-03-03 00:39 26,112 a------- c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 00:37 98,304 a------- c:\windows\system32\iasrecst.dll 2009-03-03 00:37 54,784 a------- c:\windows\system32\iasads.dll 2009-03-03 00:37 44,032 a------- c:\windows\system32\iasdatastore.dll 2009-03-02 23:04 666,624 a------- c:\windows\system32\printfilterpipelinesvc.exe 2009-03-02 22:38 17,408 a------- c:\windows\system32\iashost.exe 2009-03-02 19:36 19,359,232 a------- c:\windows\system32\imageres.dll 2009-02-15 23:34 180,224 a------- c:\windows\system32\WinVd32.sys 2009-02-15 23:34 16,896 a------- c:\windows\system32\WinFl32.sys 2009-02-13 08:13 10,520 a------- c:\windows\system32\avgrsstx.dll 2009-02-13 04:49 72,704 a------- c:\windows\system32\secur32.dll 2009-02-13 04:49 1,255,936 a------- c:\windows\system32\lsasrv.dll 2009-02-08 23:10 2,033,152 a------- c:\windows\system32\win32k.sys 2008-09-17 16:18 174 a--sh--- c:\program files\desktop.ini 2008-09-17 16:04 665,600 a------- c:\windows\inf\drvindex.dat 2007-08-17 21:02 1,132,112 a------- c:\programdata\pswi_preloaded.exe 2007-08-17 21:02 1,132,112 a------- c:\progra~2\pswi_preloaded.exe 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2007-08-01 22:57 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT ============= FINISH: 21:39:29.31 =============== This post has been edited by Orca239: May 2 2009, 08:57 PM
Attached File(s)
|
|
|
|
May 16 2009, 05:43 PM
Post
#2
|
|
![]() Bleepin' Conundrum ![]() ![]() ![]() ![]() ![]() ![]() Group: Emeritus Posts: 19,461 Joined: 26-April 04 From: 65 miles due East of the "Logic Free Zone", in Md, USA Member No.: 235 |
Hello and welcome to Bleeping Computer
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far. Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware. If you have already posted a DDS log, please do so again, as your situation may have changed. Use the 'Add Reply' and add the new log to this thread. Thanks and again sorry for the delay. We need to see some information about what is happening in your machine. Please perform the following scan:
Information on A/V control HERE R, K -------------------- The only easy day was yesterday.
...some do, some don't; some will, some won't (WR) |
|
|
|
May 16 2009, 09:29 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 2-May 09 Member No.: 327,670 |
Here's some more of one of the errors that have been showing up on the crash dump screen. I might be getting more than one type.
----------------- WinFl32.sys PAGE_FAULT_IN_NONPAGED_AREA stop: 0x00000050 (0xB1037000, 0x00000001, 0xAD3E3E9C, 0x00000000) ... WinFl32.sys - address AD3E3E9C base at AD3E2000, DateStamp 49806827 ------------------ DDS (Ver_09-05-14.01) - NTFSx86 Run by user at 22:23:05.43 on Sat 05/16/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.860 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Stardock\MyColors\VistaSrv.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Stardock\MyColors\WBVista.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Comodo\CBOClean\BOCORE.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Windows\system32\lxczcoms.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Windows\system32\stacsv.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe C:\Program Files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Apoint\ApMsgFwd.exe C:\Program Files\Apoint\Apvfb.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRAM FILES\STARDOCK\OBJECTDOCK\OBJECTDOCK.EXE C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE C:\Program Files\Windows Live\Mail\wlmail.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Users\user\AppData\Roaming\Maxthon2\Maxthon.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\user\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe C:\Users\user\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mDefault_Page_URL = hxxp://www.sony.com/vaiopeople mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 4.0\aoltb.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 4.0\aoltb.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File uRun: [<NO NAME>] uRun: [Google Update] "c:\users\user\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [VWLASU] "c:\program files\sony\vaio pc wireless lan wizard\AutoLaunchWLASU.exe" mRun: [VAIOSurvey] c:\program files\sony\vaio survey\Vista VAIO Survey.exe mRun: [VAIO Center Access Bar] "c:\program files\sony\vaio center access bar\VCAB.exe" 1 mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [lxczbmgr.exe] "c:\program files\lexmark 1200 series\lxczbmgr.exe" mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [BOC-427] c:\progra~1\comodo\cboclean\BOC427.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Add animation to IncrediMail Style Box - c:\program files\incredimail\bin\resources\WebMenuImg.htm IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll/206 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 4.0\aoltb.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: microsoft.com\www DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab DPF: {0CC52A09-A146-4AC4-85E5-B9A575CA8196} - hxxp://www.ace-onlines.com/Downloads/pc_info.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {4DD988A3-8A9A-4CC1-A763-F822C09E4315} - hxxp://www.va-sa-ra.co.jp/mgx/win/MGXPlugin.cab DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} - hxxp://www.srtest.com/srl_bin/sysreqlab_ind.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} - hxxp://fate.netgame.com/launch/object/mglaunch_USAv1004.cab DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab DPF: {AB4ADC0F-2B4B-4B08-8B5C-CA4D6188A180} - hxxp://config.hyosungcdn.com/download/p3xset.cab DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll Notify: WBSrv - c:\progra~1\stardock\object~2\window~1\wbsrv.dll AppInit_DLLs: avgrsstx.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\mcpcore.dll SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes\deskscapes.dll STS: Stardock Vista ControlPanel Extension: {ec654325-1273-c2a9-2b7c-45d29bce68fd} - c:\program files\stardock\object desktop\deskscapes\DesktopControlPanel.dll STS: StardockDreamController: {ec654325-1273-c2a9-2b7c-45d29bce68ff} - c:\program files\stardock\object desktop\deskscapes\DreamControl.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("network.protocol-handler.warn-external.veoh2", false); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-16 325128] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-9-3 8944] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-9-3 55024] R2 BOCore;BOCore;c:\program files\comodo\cboclean\BOCore.exe [2008-11-12 73464] R2 lxcz_device;lxcz_device;c:\windows\system32\lxczcoms.exe -service --> c:\windows\system32\lxczcoms.exe -service [?] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632] R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2007-8-1 75008] R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2007-8-1 43904] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-9-3 7408] R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2007-8-1 31104] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-8-1 812544] S2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe --> c:\progra~1\avg\avg8\avgwdsvc.exe [?] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2007-8-1 28464] S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\stumbleupon\StumbleUponUpdateService.exe [2009-4-12 120168] S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\sony\vaio media integrated server\UCLS.exe [2007-8-17 745472] S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\sony\vaio media integrated server\platform\SV_Httpd.exe [2007-8-17 397312] S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\sony\vaio media integrated server\platform\UPnPFramework.exe [2007-8-17 1089536] S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2007-8-1 292152] S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2007-8-1 79736] ============== File Associations =============== txtfile=c:\windows\NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-05-08 23:28 <DIR> --d----- c:\users\user\appdata\roaming\Uniblue 2009-05-08 23:28 <DIR> --d----- c:\programdata\DriverScanner 2009-05-08 23:28 <DIR> --d----- c:\program files\Uniblue 2009-05-08 23:28 <DIR> --d----- c:\progra~2\DriverScanner 2009-05-08 23:27 <DIR> -cd-h--- c:\programdata\{66E2F539-12B6-4870-A500-7689CDE75C5E} 2009-05-08 23:27 <DIR> -cd-h--- c:\progra~2\{66E2F539-12B6-4870-A500-7689CDE75C5E} 2009-05-08 23:12 <DIR> --d----- c:\program files\WhoCrashed 2009-05-08 22:02 <DIR> --d----- C:\Games 2009-05-02 13:23 <DIR> --d----- c:\programdata\Cobian 2009-05-02 13:23 <DIR> --d----- c:\progra~2\Cobian 2009-05-02 13:22 <DIR> --d----- c:\program files\Cobian Backup 9 2009-05-02 12:50 <DIR> --d----- c:\program files\Runtime Software 2009-04-24 23:08 <DIR> --d----- c:\users\user\appdata\roaming\Red Kawa 2009-04-24 23:04 <DIR> --d----- c:\program files\Regensoft 2009-04-24 23:04 <DIR> --d----- c:\program files\AviSynth 2.5 2009-04-24 23:04 <DIR> --d----- c:\program files\Red Kawa 2009-04-21 11:36 376,832 a------- c:\windows\system32\winhttp.dll 2009-04-21 11:36 562,176 a------- c:\windows\system32\msdtcprx.dll 2009-04-21 11:36 38,912 a------- c:\windows\system32\xolehlp.dll 2009-04-18 11:00 <DIR> --d----- c:\program files\Taskbar Shuffle ==================== Find3M ==================== 2009-03-23 07:53 143,360 a------- c:\windows\inf\infstrng.dat 2009-03-23 07:53 86,016 a------- c:\windows\inf\infstor.dat 2009-03-23 07:53 86,016 a------- c:\windows\inf\infpub.dat 2009-03-19 16:32 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-03-16 23:38 40,960 a------- c:\windows\apppatch\apihex86.dll 2009-03-16 23:38 13,824 a------- c:\windows\system32\apilogen.dll 2009-03-16 23:38 24,064 a------- c:\windows\system32\amxread.dll 2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll 2009-03-08 07:34 914,944 a------- c:\windows\system32\wininet.dll 2009-03-08 07:34 43,008 a------- c:\windows\system32\licmgr10.dll 2009-03-08 07:33 18,944 a------- c:\windows\system32\corpol.dll 2009-03-08 07:33 109,056 a------- c:\windows\system32\iesysprep.dll 2009-03-08 07:33 109,568 a------- c:\windows\system32\PDMSetup.exe 2009-03-08 07:33 132,608 a------- c:\windows\system32\ieUnatt.exe 2009-03-08 07:33 107,520 a------- c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 07:33 107,008 a------- c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 07:33 103,936 a------- c:\windows\system32\SetDepNx.exe 2009-03-08 07:33 420,352 a------- c:\windows\system32\vbscript.dll 2009-03-08 07:32 72,704 a------- c:\windows\system32\admparse.dll 2009-03-08 07:32 71,680 a------- c:\windows\system32\iesetup.dll 2009-03-08 07:32 66,560 a------- c:\windows\system32\wextract.exe 2009-03-08 07:32 169,472 a------- c:\windows\system32\iexpress.exe 2009-03-08 07:31 34,816 a------- c:\windows\system32\imgutil.dll 2009-03-08 07:31 48,128 a------- c:\windows\system32\mshtmler.dll 2009-03-08 07:31 45,568 a------- c:\windows\system32\mshta.exe 2009-03-08 07:22 156,160 a------- c:\windows\system32\msls31.dll 2009-03-05 23:59 1,900,544 a------- c:\windows\system32\usbaaplrc.dll 2009-03-03 00:46 3,599,328 a------- c:\windows\system32\ntkrnlpa.exe 2009-03-03 00:46 3,547,632 a------- c:\windows\system32\ntoskrnl.exe 2009-03-03 00:39 183,296 a------- c:\windows\system32\sdohlp.dll 2009-03-03 00:39 551,424 a------- c:\windows\system32\rpcss.dll 2009-03-03 00:39 26,112 a------- c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 00:37 98,304 a------- c:\windows\system32\iasrecst.dll 2009-03-03 00:37 54,784 a------- c:\windows\system32\iasads.dll 2009-03-03 00:37 44,032 a------- c:\windows\system32\iasdatastore.dll 2009-03-02 23:04 666,624 a------- c:\windows\system32\printfilterpipelinesvc.exe 2009-03-02 22:38 17,408 a------- c:\windows\system32\iashost.exe 2009-03-02 19:36 19,359,232 a------- c:\windows\system32\imageres.dll 2009-02-15 23:34 180,224 a------- c:\windows\system32\WinVd32.sys 2009-02-15 23:34 16,896 a------- c:\windows\system32\WinFl32.sys 2008-09-17 16:18 174 a--sh--- c:\program files\desktop.ini 2008-09-17 16:04 665,600 a------- c:\windows\inf\drvindex.dat 2007-08-17 21:02 1,132,112 a------- c:\programdata\pswi_preloaded.exe 2007-08-17 21:02 1,132,112 a------- c:\progra~2\pswi_preloaded.exe 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2007-08-01 22:57 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT ============= FINISH: 22:24:29.31 ===============
Attached File(s)
|
|
|
|
May 17 2009, 08:14 AM
Post
#4
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,960 Joined: 10-March 08 Member No.: 195,473 |
Hello.
There are two suspicious files that I would like you to scan. Submit File to Online Scanner
Download and run MalwareBytes Anti-Malware If you already have MBAM installed, simply update and run a quick scan. Please download Malwarebytes Anti-Malware setup and to your desktop. alternate download link 1 alternate download link 2 Refer to the steps given here on installing MalwareBytes, running the scan, and saving the log file (not on using File Assasin).
With Regards, The Panda -------------------- |
|
|
|
May 17 2009, 12:39 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 2-May 09 Member No.: 327,670 |
--For WinVd32.sys--
MD5: 58997182304759f46902a62128d44d5c First received: - Date: 05.04.2009 03:55:41 (CET) [>13D] Results: 0/40 Permalink: http://www.virustotal.com/analisis/369f526...3ad859c89dd044a --For WinFl32.sys-- MD5: ebce1626b49c3f3fecd2077447275482 First received: 02.08.2009 17:47:04 (CET) Date: 02.08.2009 22:38:51 (CET) [>97D] Results: 1/39 Permalink: http://www.virustotal.com/analisis/c4f06a4...3130d6f9fdcf2ee Malwarebytes' Anti-Malware 1.36 Database version: 2145 Windows 6.0.6001 Service Pack 1 5/17/2009 1:35:44 PM mbam-log-2009-05-17 (13-35-44).txt Scan type: Quick Scan Objects scanned: 95228 Time elapsed: 10 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) This post has been edited by Orca239: May 17 2009, 12:41 PM |
|
|
|
May 17 2009, 04:43 PM
Post
#6
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,960 Joined: 10-March 08 Member No.: 195,473 |
Hello Orca.
The files WinVd32.sys and WinFl32.sys are related to the program Folder Lock. I would suggest uninstalling it using Add/Remove Programs. Tell me if the crashes still occur after. With Regards, The Panda -------------------- |
|
|
|
May 20 2009, 07:13 PM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 2-May 09 Member No.: 327,670 |
I waited a bit to reply to make sure, but the crashes seem to have stopped. Thanks for the help.
|
|
|
|
Jun 2 2009, 07:37 PM
Post
#8
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,960 Joined: 10-March 08 Member No.: 195,473 |
Hello.
If you are still here, please respond to this topic. If there is not reply within 5 days of this post, this topic may be closed. With Regards, The Panda -------------------- |
|
|
|
Jun 2 2009, 09:39 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 2-May 09 Member No.: 327,670 |
|
|
|
|
Jun 3 2009, 07:02 AM
Post
#10
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,960 Joined: 10-March 08 Member No.: 195,473 |
Hello.
Just want to make sure that we can close this topic. I had assumed that you would reply again when you said "waited" but after re-reading it I see that you meant you already waited. With Regards, The Panda -------------------- |
|
|
|
Jun 16 2009, 07:44 AM
Post
#11
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,960 Joined: 10-March 08 Member No.: 195,473 |
Hello.
Since this issue appears to be resolved, this topic is now closed. If you are the topic starter and need this topic reopened, send me a message. Everyone else, please begin a new topic. With Regards, The Panda -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 9th February 2010 - 10:36 AM |