Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

browser redirecting and crashing, error messages...


  • This topic is locked This topic is locked
5 replies to this topic

#1 kriscoop

kriscoop

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:43 PM

Posted 22 April 2009 - 09:55 PM

hi there-

I've been having terrible problems for a month or more...I've tried various anti-virus programs (Norton, Malwarebytes, Avast...) to no avail.

I'm not sure if it's just virus(es) and/or malware, or if I messed up my machine by doing too many system restores...

My primary problem is that my google searches keep getting redirected. My Firefox browser keeps crashing as well (I've reinstalled it more than once). I'm also getting error messages - "Generic Host Process for Win32 Services has encountered a problem". And after that, my sound doesn't work on my laptop. Not sure if this is one giant problem from one source or a variety of different issues (oh joy).

I thought that Malwarebytes took care of the problem - it found the Daonal trojan and removed it, and I thought the browser stopped re-directing, but then the re-directing started again and now Malwarebytes doesn't find any more problems.

I followed the steps in the prep guide, but was unable to get DDS to run (the black screen opens, but just flashes on the screen for a moment and then disappears).

Here is my HijackThis info -- also, I will be out of town for the next few days with limited access to the internet...so I will be back to check this thread, I'm desperate for help!! Thanks in advance for any assistance you can provide :D

--kristin

********************

Logfile of random's system information tool 1.06 (written by random/random)
Run by Kristin at 2009-04-22 22:36:16
Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (22%) free of 57 GB
Total RAM: 1406 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:36:33 PM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Documents and Settings\Kristin\Local Settings\Application

Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kristin\Desktop\RSIT.exe
C:\Program Files\trend micro\Kristin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul...com/ext/search/

search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride

= *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-

0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-

784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-

4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

c:\program files\google\googletoolbar3.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-

0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-

9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control

Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless

Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch

Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti

-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1

\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software

Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe"

runtime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile

Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version

Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe

/auto
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1

\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\system32\RunDLL32.exe

C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNow
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Kristin\Local

Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI

Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program

Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10

\OSA.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1

\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-

f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-

0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-

0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-

00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) -

C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/.../wuweb_site.cab

?1123417917062
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -

http://download.abacast.com/download/files/abasetup162.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} -

C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll

(file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common

Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program

Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32

\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company,

L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -

C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) -

Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program

Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common

Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program

Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

--
End of file - 11254 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Malwarebytes' Scheduled Scan for Kristin.job
C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Kristin.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0

\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar3.dll [2006-10-12

2108480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-23

35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\B

rowser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6

\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-23 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program

Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program

files\google\googletoolbar3.dll [2006-10-12 2108480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04

-11 339968]
"hpWirelessAssistant"=C:\Program Files\hpq\HP Wireless Assistant\HP Wireless

Assistant.exe [2005-04-01 794624]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2005-02-02 102492]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-02-02 692316]
"eabconfg.cpl"=C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe [2004-12-

03 290816]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2005-02-17 233534]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2004-10-14 253952]
"Logitech Utility"=C:\WINDOWS\Logi_MwX.Exe [2003-12-17 19968]
""= []
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-

Malware\mbamgui.exe [2009-04-06 401040]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-

05-06 185896]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-23

148888]
"ISUSScheduler"=C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe [2004-08-09 81920]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe

[2004-08-09 221184]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[2007-05-08 54840]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-12 45056]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleSyncNotifier.exe [2008-11-07 111936]
"Adobe Version Cue CS2"=C:\Program Files\Adobe\Adobe Version Cue CS2

\ControlPanel\VersionCueCS2Tray.exe [2005-04-04 856064]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-13

169984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2006-11-30

4662776]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"OfotoNow USB Detection"=C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL [2002-11-

05 77824]
"Google Update"=C:\Documents and Settings\Kristin\Local Settings\Application

Data\Google\Update\GoogleUpdate.exe [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cobian

Backup 8 interface]
C:\Program Files\Cobian Backup 8\cbInterface.exe [2007-09-27 2425856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google

Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-11-18

1838592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start

Menu^Programs^Startup^QuickBooks Update Agent.lnk]
C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe [2008-10-22

972064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CobBMService"=2
"Bonjour Service"=2
"Apple Mobile Device"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-

7760-000000000002}\SC_Acrobat.exe
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe

Gamma Loader.exe
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-09-14 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServi

ceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Syste

m]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explor

er]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explor

er]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters

\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program

Files\Abacast\Abaclient.exe:*:Disabled:Abaclient"
"C:\Program Files\Adobe\Adobe Version Cue CS2

\bin\VersionCueCS2.exe"="C:\Program Files\Adobe\Adobe Version Cue CS2

\bin\VersionCueCS2.exe:*:Disabled:Adobe Version Cue CS2"
"C:\Program Files\Common Files\AOL\1161264367\ee\aim6.exe"="C:\Program

Files\Common Files\AOL\1161264367\ee\aim6.exe:*:Disabled:AIM"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant

Messenger"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program

Files\Common Files\AOL\Loader\aolload.exe:*:Disabled:AOL Loader"
"C:\Program Files\Common Files\AOL\1161264367\ee\aolsoftware.exe"="C:\Program

Files\Common Files\AOL\1161264367\ee\aolsoftware.exe:*:Disabled:AOL Services"
"C:\Program Files\AVG\AVG8\avgam.exe"="C:\Program Files\AVG\AVG8

\avgam.exe:*:Disabled:avgam.exe"
"C:\Program Files\AVG\AVG8\avgdiag.exe"="C:\Program Files\AVG\AVG8

\avgdiag.exe:*:Disabled:avgdiag.exe"
"C:\Program Files\AVG\AVG8\avgdiagex.exe"="C:\Program Files\AVG\AVG8

\avgdiagex.exe:*:Disabled:avgdiagex.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8

\avgnsx.exe:*:Disabled:avgnsx.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8

\avgupd.exe:*:Disabled:avgupd.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program

Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour"
"C:\Program Files\Intuit\QuickBooks Point of Sale 6.0

\DatabaseServer\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks Point of Sale

6.0\DatabaseServer\QBDBMgrN.exe:LocalSubNet:Disabled:Database manager for

QBPOS v6"
"C:\Program Files\Intuit\QuickBooks Point of Sale 6.0

\DatabaseServer\QBDBMgr.exe"="C:\Program Files\Intuit\QuickBooks Point of Sale

6.0\DatabaseServer\QBDBMgr.exe:LocalSubNet:Disabled:Database manager for

QBPOS v6"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink

TotalAccess\TaskPanl.exe:*:Disabled:Earthlink"
"C:\Program Files\Intuit\QuickBooks Point of Sale 6.0\EftSvr.exe"="C:\Program

Files\Intuit\QuickBooks Point of Sale 6.0\EftSvr.exe:LocalSubNet:Disabled:EFT server

for QBPOS v6"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Disabled:File

Transfer Program"
"C:\Program Files\Hp\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe"
"C:\Program Files\Hp\Digital Imaging\Unload\HpqDIA.exe"="C:\Program

Files\Hp\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqnrs08.exe:*:Disabled:hpqnrs08.exe"
"C:\Program Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program

Files\Hp\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe"
"C:\Program Files\Hp\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\Hp\Digital

Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program

Files\iTunes\iTunes.exe:*:Disabled:iTunes"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Disabled:Java

™ 2 Platform Standard Edition binary"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program

Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data

Manager"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32

\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\SmartFTP\SmartFTP.exe"="C:\Program

Files\SmartFTP\SmartFTP.exe:*:Disabled:SmartFTP Client"
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe"="C:\Program Files\SmartFTP

Client 2.0\SmartFTP.exe:*:Disabled:SmartFTP Client 2.0"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!

\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!

\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program

Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters

\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32

\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant

Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network

Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-04-22 22:36:16 ----D---- C:\rsit
2009-04-22 22:36:16 ----D---- C:\Program Files\trend micro
2009-04-21 10:36:40 ----D---- C:\WINDOWS\pss
2009-04-20 20:48:37 ----D---- C:\Program Files\Cobian Backup 8
2009-04-20 20:29:47 ----D---- C:\Program Files\2BrightSparks
2009-04-17 15:46:34 ----D---- C:\Program Files\AVG
2009-04-05 22:44:42 ----D---- C:\WINDOWS\CSC
2009-04-01 19:12:05 ----D---- C:\Documents and Settings\Kristin\Application

Data\Uniblue
2009-04-01 19:12:05 ----D---- C:\Documents and Settings\All Users\Application

Data\DriverScanner
2009-04-01 19:12:04 ----D---- C:\Program Files\Uniblue
2009-04-01 19:11:18 ----HDC---- C:\Documents and Settings\All Users\Application

Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-04-01 17:08:10 ----D---- C:\Documents and Settings\All Users\Application

Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-04-01 17:05:40 ----D---- C:\Documents and Settings\All Users\Application

Data\Norton
2009-04-01 17:05:01 ----D---- C:\Documents and Settings\All Users\Application

Data\NortonInstaller
2009-03-31 19:01:02 ----N---- C:\WINDOWS\ntbtlog.txt
2009-03-25 16:09:21 ----D---- C:\WINDOWS\ie8updates
2009-03-25 16:03:34 ----HDC---- C:\WINDOWS\ie8
2009-03-23 09:59:04 ----N---- C:\WINDOWS\system32\javaws.exe
2009-03-23 09:59:04 ----N---- C:\WINDOWS\system32\javaw.exe
2009-03-23 09:59:04 ----N---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 1 months======

2009-04-22 22:36:16 ----RD---- C:\Program Files
2009-04-22 22:36:10 ----D---- C:\WINDOWS\Prefetch
2009-04-22 20:28:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-22 20:11:13 ----D---- C:\Program Files\Mozilla Firefox
2009-04-22 20:10:04 ----SH---- C:\boot.ini
2009-04-22 20:10:04 ----A---- C:\WINDOWS\win.ini
2009-04-22 20:10:04 ----A---- C:\WINDOWS\system.ini
2009-04-22 20:05:33 ----D---- C:\WINDOWS
2009-04-22 20:05:26 ----D---- C:\WINDOWS\Temp
2009-04-22 20:05:23 ----D---- C:\WINDOWS\system32\drivers
2009-04-21 16:02:29 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-21 10:35:10 ----SD---- C:\WINDOWS\Tasks
2009-04-21 10:08:50 ----D---- C:\Documents and Settings\Kristin\Application

Data\Mozilla
2009-04-21 09:25:27 ----D---- C:\WINDOWS\system32
2009-04-21 09:04:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-21 07:37:51 ----D---- C:\WINDOWS\Help
2009-04-20 20:08:51 ----HD---- C:\WINDOWS\inf
2009-04-20 09:14:16 ----HD---- C:\Config.Msi
2009-04-20 09:14:15 ----SHD---- C:\WINDOWS\Installer
2009-04-17 15:46:18 ----D---- C:\WINDOWS\WinSxS
2009-04-17 15:46:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-04-12 20:12:01 ----SD---- C:\Documents and Settings\All Users\Application

Data\Microsoft
2009-04-11 11:34:28 ----N---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-11 11:29:31 ----SHD---- C:\System Volume Information
2009-04-11 11:29:31 ----D---- C:\Program Files\Common Files
2009-04-07 22:46:27 ----A---- C:\WINDOWS\imsins.BAK
2009-04-07 22:46:25 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-04-07 22:45:00 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-04-07 22:44:58 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-04-07 22:43:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-04-07 22:43:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-04-07 22:43:08 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-04-07 22:42:54 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-04-07 22:42:40 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-04-07 22:42:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-04-07 22:41:34 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-04-07 22:41:14 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-04-06 10:57:24 ----N---- C:\WINDOWS\system32\MRT.exe
2009-04-02 00:01:17 ----D---- C:\Documents and Settings\All Users\Application

Data\Symantec
2009-04-01 20:36:01 ----D---- C:\WINDOWS\system32\config
2009-04-01 19:01:01 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-01 17:08:24 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-03-25 16:15:47 ----D---- C:\WINDOWS\system32\en-US
2009-03-25 16:15:45 ----D---- C:\WINDOWS\Media
2009-03-25 16:15:45 ----D---- C:\Program Files\Internet Explorer
2009-03-23 16:30:57 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-23 09:58:39 ----N---- C:\WINDOWS\system32\deploytk.dll
2009-03-23 09:58:34 ----D---- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand,

4=Disabled)======

R1 eabfiltr;EABFiltr; \??\C:\WINDOWS\system32\drivers\EABFiltr.sys []
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program

Files\UltraISO\drivers\ISODrive.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI;

C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment;

C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17

13059]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32

\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-09-14

1339392]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32

\DRIVERS\bcmwl5.sys [2005-03-10 371712]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camc6aud.sys

[2005-02-18 38016]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2005-02

-18 349696]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32

\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32

\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-12-15

1038208]
R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004

-12-15 200192]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-

04-13 61824]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;

C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-03 74496]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys

[2005-02-02 191456]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-03-16 159488]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;

C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-

04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver;

C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-12-15

703232]
S1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys []
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-

04-13 14592]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32

\Drivers\btwusb.sys [2005-01-18 55320]
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-

04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32

\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32

\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32

\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 eabusb;eabusb; \??\C:\WINDOWS\system32\drivers\eabusb.sys []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys

[2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32

\DRIVERS\HPZid412.sys [2005-10-27 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32

\DRIVERS\HPZipr12.sys [2005-10-27 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12;

C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-27 21568]
S3 LHidFlt2;Logitech HID/USB Mouse Filter Driver; C:\WINDOWS\system32

\DRIVERS\LHidFlt2.Sys [2003-12-17 25505]
S3 LHidUsb;Logitech USB Receiver device driver; C:\WINDOWS\System32

\Drivers\LHidUsb.Sys [2003-12-17 37887]
S3 LMouFlt2;Logitech Mouse Class Filter Driver; C:\WINDOWS\system32

\DRIVERS\LMouFlt2.Sys [2003-12-17 70801]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08

-17 12160]
S3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001

-08-17 19584]
S3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32

\DRIVERS\smcirda.sys [2001-08-17 35913]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32

\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32

\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys

[2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32

\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;

C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 VNUSB;VN Series Device; C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2003-

12-15 38448]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver;

C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector;

C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,

3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-09

-14 376832]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe

[2009-03-23 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program

Files\Common Files\LightScribe\LSSrvc.exe [2005-02-22 38912]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-

Malware\mbamservice.exe [2009-04-06 179856]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft

Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common

Files\Intuit\QuickBooks\QBCFMonitorService.exe [2008-10-22 20480]
R2 UPHClean;User Profile Hive Cleanup; C:\Program Files\UPHClean\uphclean.exe

[2005-04-27 241725]
R3 hpqwmi;HP WMI Interface; C:\Program Files\HPQ\SHARED\HPQWMI.exe [2005-03

-04 98304]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-09-14 516096]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe

[2005-03-14 69632]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe

Systems Shared\Service\Adobelmsvc.exe [2006-06-16 72704]
S3 Adobe Version Cue CS2;Adobe Version Cue CS2; C:\Program Files\Adobe\Adobe

Version Cue CS2\bin\VersionCueCS2.exe [2005-04-04 163840]
S3 aspnet_state;ASP.NET State Service;

C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24

33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service

v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

[2007-10-24 70144]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20

536872]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft

Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common

Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2007-05-24 61440]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program

Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework;

C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common

Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07

132424]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe

[2008-08-29 238888]
S4 CobBMService;Cobian Backup 8 service; C:\Program Files\Cobian Backup 8

\cbService.exe [2007-09-27 499200]

-----------------EOF-----------------

BC AdBot (Login to Remove)

 


#2 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Members
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the "Logic Free Zone", in Md, USA
  • Local time:07:43 PM

Posted 05 May 2009 - 10:53 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

//Since you cannot get DDS to run, please add another HJT log.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)

#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,962 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:43 PM

Posted 13 May 2009 - 05:19 PM

Topic reopened at member's request. ~ OB
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#4 kriscoop

kriscoop
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:07:43 PM

Posted 16 May 2009 - 06:16 PM

ok, poor timing on my part, I am leaving for FL for a week and will not be able to deal with this until I get back

if anyone has taken a look at this, do you think I would be best just re-installing the OS? from what I've read about the Daonol Trojan, it's a big PITA to remove. I also think my machine is just messed up in general because of too many system restores.

that's my current line of thinking...off to FL to see the grandparents...hopefully I'll have more time to deal with this when I get back

thanks
--kristin

#5 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,962 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:43 PM

Posted 16 May 2009 - 06:28 PM

Hello kriscoop,

I couldn't tell you if reformatting is the best option. If you know what you're doing with reformatting, it might be the quickest.

We'll keep this topic open for you. Have a safe trip and please post back on your return with the requested new logs.

If you decide to reformat, let us know that too.

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#6 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,962 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:43 PM

Posted 30 May 2009 - 01:50 PM

As it's now been 2 weeks since you said you would be gone for 1 week, I am closing this topic. In case you still have problems, please start a new topic.

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users