Hello,
I've arrived after attempting multiple removals of one or more trojans affecting my computer. A pop up box repeatedly appears, labeled "Symantec" and telling me that 1 of 1 messages is being scanned. Then a centered popup box tells me that there is some Email Proxy Error and that the message, to some email address that I've never heard of could not be sent. Normally these messages come one after another, but of course, now that I want to desribe them in detail, they are no where to be found...
I've run Avira a number of times, as well as Windows Defender and CCleaner to try to catch any remnants. Avira has found a number of trojans, with files named A0097036.exe, A0097037.sys, and A0097040.exe, but seems to be having trouble deleting them. Windows Defender thinks that my computer is functioning normally.
Thanks for your time and help. Yay volunteers!
Here's my DDS log file:
DDS (Ver_09-06-26.01) - NTFSx86
Run by Owner at 8:06:57.20 on Fri 06/26/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.77 [GMT -4:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Norton AntiVirus *On-access scanning enabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\f.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\dldtcoms.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\matlab7\bin\win32\matlab.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\system32\S3tray2.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\f.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
C:\WINDOWS\system32\svchost.exe -k sys
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://qus7.hpwis.com/
mDefault_Search_URL = hxxp://srch-qus7.hpwis.com/
mSearch Page = hxxp://srch-qus7.hpwis.com/
mStart Page = hxxp://qus7.hpwis.com/
mSearch Bar = hxxp://srch-qus7.hpwis.com/
uInternet Connection Wizard,ShellNext = hxxp://qus7.hpwis.com/
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton antivirus\NavShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [StorageGuard] "c:\program files\veritas software\update manager\sgtray.exe" /r
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [ccRegVfy] "c:\program files\common files\symantec shared\ccRegVfy.exe"
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe
mRun: [S3TRAY2] S3tray2.exe
mRun: [dldtmon.exe] "c:\program files\dell v305\dldtmon.exe"
mRun: [dldtamon] "c:\program files\dell v305\dldtamon.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [sysldtray] c:\windows\ld10.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab
DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_01-win.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {743E9AA5-7C44-43FF-9D51-FCB42163ABEE} = 66.174.95.44 66.174.92.14
Notify: igfxcui - igfxsrvc.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\4gp2fxsx.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: network.proxy.http - localhost:8080
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\4gp2fxsx.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJPI140_01.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPOJI610.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R?2 6to4Alerter;IPv6 Helper Service 6to4Alerter;c:\windows\system32\f.exe service --> c:\windows\system32\f.exe service [?]
R?2 sys;sys;c:\windows\system32\svchost.exe -k sys [2003-4-10 14336]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-5-9 64160]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-6-24 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-6-24 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-6-24 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-6-24 55640]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2002-11-14 317128]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --> c:\windows\system32\dldtcoms.exe -service [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 953168]
R2 navapsvc;Norton AntiVirus Auto Protect Service;c:\program files\norton antivirus\Navapsvc.exe [2002-11-15 116336]
R2 SAVRTPEL;SAVRTPEL;c:\windows\system32\drivers\SAVRTPEL.SYS [2005-1-9 35552]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-28 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20041215.032\NAVENG.Sys [2004-12-16 72712]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20041215.032\NavEx15.Sys [2004-12-16 629544]
R3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2009-2-23 33024]
R3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2009-2-23 41344]
R3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2009-2-23 39936]
R3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2009-2-23 59904]
R3 SAVRT;SAVRT;c:\windows\system32\drivers\SAVRT.SYS [2005-1-9 235744]
S1 sysdrv;sysdrv;\??\c:\program files\sys\sys.sys --> c:\program files\sys\sys.sys [?]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2008-2-25 99568]
S2 lcacilq;lcacilq;\??\c:\windows\system32\drivers\loyjbqx.sys --> c:\windows\system32\drivers\loyjbqx.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\bw2ndis5.sys --> c:\windows\system32\drivers\BW2NDIS5.sys [?]
S3 ccPwdSvc;Symantec Password Validation Service;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-1-9 99352]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2004-8-27 15576]
=============== Created Last 30 ================
2009-06-26 07:17 <DIR> --d----- c:\program files\Trend Micro
2009-06-25 19:54 0 ac------ c:\windows\system32\dllcache\oledlg.dll.new
2009-06-25 13:02 6,553 a------- c:\windows\system32\spupdsvc.inf
2009-06-25 12:54 <DIR> --d----- c:\windows\system32\scripting
2009-06-25 12:54 <DIR> --d----- c:\windows\l2schemas
2009-06-25 12:54 <DIR> --d----- c:\windows\system32\en
2009-06-25 12:46 <DIR> --d----- c:\windows\network diagnostic
2009-06-25 12:44 1,374 a------- c:\windows\imsins.BAK
2009-06-24 21:00 <DIR> --d----- c:\program files\CCleaner
2009-06-24 20:36 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-06-24 20:36 <DIR> --d----- c:\program files\Avira
2009-06-24 20:36 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-06-24 19:20 <DIR> --d----- c:\windows\ERUNT
2009-06-23 18:30 <DIR> --d----- c:\program files\sys
2009-06-23 18:30 2 a------- c:\windows\010112010146118114.dat
2009-06-23 17:30 184 a------- c:\windows\22678h32.bat
2009-06-23 17:30 22,528 a---h--- c:\windows\system32\f.exe
2009-06-23 17:30 213,024 a------- c:\windows\system32\drivers\str.sys
2009-06-19 13:58 61,224 a------- c:\documents and settings\owner\GoToAssistDownloadHelper.exe
2009-06-02 22:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ThumbnailCache4R
==================== Find3M ====================
2009-06-25 12:59 79,179 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-05-09 20:17 15,688 a------- c:\windows\system32\lsdelete.exe
2009-05-09 20:16 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-29 00:46 666,624 a------- c:\windows\system32\wininet.dll
2009-04-29 00:46 81,920 -------- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2003-01-25 06:30 32 ac-sh--- c:\windows\{432DC6F6-968D-4F5B-A15F-5FECE3F263AD}.dat
2003-01-25 06:30 32 ac-sh--- c:\windows\system32\{7A423CBA-2B8A-4A0B-AE91-B7E63A03AA63}.dat
============= FINISH: 8:08:55.78 ===============
I've arrived after attempting multiple removals of one or more trojans affecting my computer. A pop up box repeatedly appears, labeled "Symantec" and telling me that 1 of 1 messages is being scanned. Then a centered popup box tells me that there is some Email Proxy Error and that the message, to some email address that I've never heard of could not be sent. Normally these messages come one after another, but of course, now that I want to desribe them in detail, they are no where to be found...
I've run Avira a number of times, as well as Windows Defender and CCleaner to try to catch any remnants. Avira has found a number of trojans, with files named A0097036.exe, A0097037.sys, and A0097040.exe, but seems to be having trouble deleting them. Windows Defender thinks that my computer is functioning normally.
Thanks for your time and help. Yay volunteers!
Here's my DDS log file:
DDS (Ver_09-06-26.01) - NTFSx86
Run by Owner at 8:06:57.20 on Fri 06/26/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.77 [GMT -4:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Norton AntiVirus *On-access scanning enabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\f.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\dldtcoms.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\matlab7\bin\win32\matlab.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\system32\S3tray2.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\f.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
C:\WINDOWS\system32\svchost.exe -k sys
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://qus7.hpwis.com/
mDefault_Search_URL = hxxp://srch-qus7.hpwis.com/
mSearch Page = hxxp://srch-qus7.hpwis.com/
mStart Page = hxxp://qus7.hpwis.com/
mSearch Bar = hxxp://srch-qus7.hpwis.com/
uInternet Connection Wizard,ShellNext = hxxp://qus7.hpwis.com/
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton antivirus\NavShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [StorageGuard] "c:\program files\veritas software\update manager\sgtray.exe" /r
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [ccRegVfy] "c:\program files\common files\symantec shared\ccRegVfy.exe"
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe
mRun: [S3TRAY2] S3tray2.exe
mRun: [dldtmon.exe] "c:\program files\dell v305\dldtmon.exe"
mRun: [dldtamon] "c:\program files\dell v305\dldtamon.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [sysldtray] c:\windows\ld10.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab
DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_01-win.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {743E9AA5-7C44-43FF-9D51-FCB42163ABEE} = 66.174.95.44 66.174.92.14
Notify: igfxcui - igfxsrvc.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\4gp2fxsx.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: network.proxy.http - localhost:8080
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\4gp2fxsx.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPJPI140_01.dll
FF - plugin: c:\program files\java\j2re1.4.0\bin\NPOJI610.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R?2 6to4Alerter;IPv6 Helper Service 6to4Alerter;c:\windows\system32\f.exe service --> c:\windows\system32\f.exe service [?]
R?2 sys;sys;c:\windows\system32\svchost.exe -k sys [2003-4-10 14336]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-5-9 64160]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-6-24 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-6-24 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-6-24 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-6-24 55640]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2002-11-14 317128]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --> c:\windows\system32\dldtcoms.exe -service [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 953168]
R2 navapsvc;Norton AntiVirus Auto Protect Service;c:\program files\norton antivirus\Navapsvc.exe [2002-11-15 116336]
R2 SAVRTPEL;SAVRTPEL;c:\windows\system32\drivers\SAVRTPEL.SYS [2005-1-9 35552]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-28 24652]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20041215.032\NAVENG.Sys [2004-12-16 72712]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20041215.032\NavEx15.Sys [2004-12-16 629544]
R3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2009-2-23 33024]
R3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2009-2-23 41344]
R3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2009-2-23 39936]
R3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2009-2-23 59904]
R3 SAVRT;SAVRT;c:\windows\system32\drivers\SAVRT.SYS [2005-1-9 235744]
S1 sysdrv;sysdrv;\??\c:\program files\sys\sys.sys --> c:\program files\sys\sys.sys [?]
S2 dldtCATSCustConnectService;dldtCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldtserv.exe [2008-2-25 99568]
S2 lcacilq;lcacilq;\??\c:\windows\system32\drivers\loyjbqx.sys --> c:\windows\system32\drivers\loyjbqx.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\bw2ndis5.sys --> c:\windows\system32\drivers\BW2NDIS5.sys [?]
S3 ccPwdSvc;Symantec Password Validation Service;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-1-9 99352]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2004-8-27 15576]
=============== Created Last 30 ================
2009-06-26 07:17 <DIR> --d----- c:\program files\Trend Micro
2009-06-25 19:54 0 ac------ c:\windows\system32\dllcache\oledlg.dll.new
2009-06-25 13:02 6,553 a------- c:\windows\system32\spupdsvc.inf
2009-06-25 12:54 <DIR> --d----- c:\windows\system32\scripting
2009-06-25 12:54 <DIR> --d----- c:\windows\l2schemas
2009-06-25 12:54 <DIR> --d----- c:\windows\system32\en
2009-06-25 12:46 <DIR> --d----- c:\windows\network diagnostic
2009-06-25 12:44 1,374 a------- c:\windows\imsins.BAK
2009-06-24 21:00 <DIR> --d----- c:\program files\CCleaner
2009-06-24 20:36 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-06-24 20:36 <DIR> --d----- c:\program files\Avira
2009-06-24 20:36 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-06-24 19:20 <DIR> --d----- c:\windows\ERUNT
2009-06-23 18:30 <DIR> --d----- c:\program files\sys
2009-06-23 18:30 2 a------- c:\windows\010112010146118114.dat
2009-06-23 17:30 184 a------- c:\windows\22678h32.bat
2009-06-23 17:30 22,528 a---h--- c:\windows\system32\f.exe
2009-06-23 17:30 213,024 a------- c:\windows\system32\drivers\str.sys
2009-06-19 13:58 61,224 a------- c:\documents and settings\owner\GoToAssistDownloadHelper.exe
2009-06-02 22:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ThumbnailCache4R
==================== Find3M ====================
2009-06-25 12:59 79,179 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-05-09 20:17 15,688 a------- c:\windows\system32\lsdelete.exe
2009-05-09 20:16 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-29 00:46 666,624 a------- c:\windows\system32\wininet.dll
2009-04-29 00:46 81,920 -------- c:\windows\system32\ieencode.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2003-01-25 06:30 32 ac-sh--- c:\windows\{432DC6F6-968D-4F5B-A15F-5FECE3F263AD}.dat
2003-01-25 06:30 32 ac-sh--- c:\windows\system32\{7A423CBA-2B8A-4A0B-AE91-B7E63A03AA63}.dat
============= FINISH: 8:08:55.78 ===============
Attached File(s)
-
Attach.txt (10.08K)
Number of downloads: 14

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










