It is currently Tue Sep 01, 2026 2:45 pm


slow PC...

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

slow PC...

Postby cc481613 » Mon Jan 14, 2008 7:19 am

hello,
my computer has been running abnormally as of one week ago, and I'm not sure whether it's just me or something wrong. Could you please inspect my log? thanks a lot!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:04 PM, on 13/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineTrayIcon.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Calvin\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Dell DataSafe Scheduler] "C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 10590 bytes
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Jan 14, 2008 12:46 pm

cc481613,

Your log is clean.

What exactly is your system doing that make you think you have a problem?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby cc481613 » Tue Jan 15, 2008 1:35 am

its just that my computer is unable to properly shut down sometimes, and normal applications are just running slower than normal...
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Jan 15, 2008 12:26 pm

cc481613

Please download to your desktop.

Double click combofix.exe and follow the prompts.

When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

ComboFix Log

Postby cc481613 » Wed Jan 16, 2008 7:42 am

ComboFix 08-01-16.4 - Calvin 2008-01-15 22:37:15.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2052 [GMT -8:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

2008-01-15 22:34 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-12 23:38 . 2008-01-12 23:38 <DIR> d-------- C:\Fraps
2008-01-08 21:52 . 2008-01-08 22:18 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-08 17:58 . 2008-01-08 17:58 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-08 17:58 . 2008-01-08 17:58 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-08 17:58 . 2008-01-08 17:58 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-08 17:58 . 2008-01-08 17:58 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-08 17:58 . 2008-01-08 17:58 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-08 17:58 . 2008-01-08 17:58 118 --a------ C:\Windows\System32\MRT.INI
2008-01-08 17:56 . 2008-01-08 17:56 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-08 17:56 . 2008-01-08 17:56 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-08 17:56 . 2008-01-08 17:56 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-08 17:56 . 2008-01-08 17:56 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-08 17:56 . 2008-01-08 17:56 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-08 17:56 . 2008-01-08 17:56 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-08 17:56 . 2008-01-08 17:56 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-01-08 17:56 . 2008-01-08 17:56 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-07 11:14 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-01-07 11:13 . 2008-01-07 11:13 <DIR> d-------- C:\Program Files\McAfee.com
2008-01-07 11:13 . 2008-01-07 11:14 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-01-07 11:13 . 2006-12-22 16:02 170,408 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-01-07 11:13 . 2007-03-02 14:17 120,360 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-01-07 11:13 . 2006-12-22 16:02 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-01-07 11:13 . 2006-12-22 16:02 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-01-07 11:12 . 2008-01-15 16:29 <DIR> d-------- C:\Program Files\McAfee
2008-01-07 05:24 . 2008-01-07 05:24 <DIR> d--hs---- C:\Users\Calvin\'
2008-01-07 05:24 . 2008-01-07 19:04 147,456 --a------ C:\Users\Calvin\vbzip10.dll
2008-01-07 02:53 . 2008-01-15 00:09 <DIR> d-a------ C:\Users\All Users\TEMP
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles\All Users\Application Data\SupportSoft
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles
2008-01-05 16:31 . 2008-01-05 18:30 10,740 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-01-05 16:31 . 2008-01-05 18:30 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-01-05 16:29 . 2008-01-07 06:24 <DIR> d-------- C:\Users\All Users\Symantec
2008-01-05 16:29 . 2008-01-07 06:26 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-25 15:24 . 2007-12-25 15:24 78 --a------ C:\Windows\system\WIN32S.INI
2007-12-25 15:23 . 1994-08-24 00:00 188,960 --a------ C:\Windows\system\WINGDE.DLL
2007-12-25 15:23 . 1994-09-21 00:00 92,208 --a------ C:\Windows\system\WING.DLL
2007-12-25 15:23 . 1994-09-21 00:00 12,800 --a------ C:\Windows\system\WING32.DLL
2007-12-25 15:23 . 1994-09-21 00:00 6,736 --a------ C:\Windows\system\WINGDIB.DRV
2007-12-25 15:23 . 1994-09-21 00:00 5,024 --a------ C:\Windows\system\WINGPAL.WND
2007-12-25 15:23 . 1994-06-27 00:00 1,966 --a------ C:\Windows\system\DVA.386
2007-12-25 12:12 . 2007-12-25 12:12 <DIR> d-------- C:\Program Files\Dell DataSafe Online
2007-12-23 10:04 . 2007-12-23 10:05 <DIR> d-------- C:\Program Files\QuickTime
2007-12-20 14:15 . 2007-12-20 14:15 <DIR> d-------- C:\Nexon
2007-12-20 12:34 . 2007-12-20 12:34 <DIR> d-------- C:\Users\All Users\NexonUS
2007-12-19 22:42 . 2007-12-20 08:12 <DIR> d-------- C:\Users\All Users\NVIDIA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 08:08 --------- d---a-w C:\Users\Calvin\AppData\Roaming\U3
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 01:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 01:56 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 01:56 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 01:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-05 18:17 --------- d-----w C:\Program Files\Java
2007-12-13 06:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Apple Computer
2007-12-12 14:58 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 14:58 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 14:58 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 14:57 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-12 14:57 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 14:57 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 14:57 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 14:56 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 14:56 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 14:56 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 14:56 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 14:55 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-12 14:55 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell Photo AIO Printer 966
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell PC Fax
2007-12-09 20:41 --------- d-----w C:\Program Files\AC3Filter
2007-12-07 04:18 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Thunderbird
2007-12-03 05:00 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-03 04:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 17:31 --------- d-----w C:\Users\Calvin\AppData\Roaming\DataSafeOnline
2007-11-27 05:57 --------- d---a-w C:\Users\Calvin\AppData\Roaming\WeatherDPA
2007-11-25 16:58 --------- d-----w C:\Users\Calvin\AppData\Roaming\Roxio
2007-11-24 16:35 --------- d-----w C:\Program Files\Xvid
2007-11-21 04:49 --------- d-----w C:\Program Files\SoundSpectrum
2007-11-19 03:45 --------- d---a-w C:\Users\Calvin\AppData\Roaming\SoundSpectrum
2007-11-17 19:53 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-17 02:22 --------- d-----w C:\Users\Mom\AppData\Roaming\DellFaxCtr
2007-11-16 07:38 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-16 07:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\DellFaxCtr
2007-11-16 07:25 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-11-14 01:51 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 01:51 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 01:51 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 01:51 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 01:51 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 01:51 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 01:51 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 01:51 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 01:51 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 01:51 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2007-10-17 17:23 10,752 ----a-w C:\Windows\System32\WhoisCL.exe
2007-09-22 16:22 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 09:09 460784]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 17:56 1232896]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe" [2007-12-02 16:30 308464]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 10:57 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 05:26 4452352 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 08:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 08:22 221184]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 02:20 17920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2007-06-29 07:49 312560]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 07:47 292080]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 07:48 304368]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 21:31 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 08:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 08:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 08:07 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 19:05]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 00:22]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-01 23:30]
S2 0087771200443356mcinstcleanup;McAfee Application Installer Cleanup (0087771200443356);C:\Windows\TEMP\008777~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog []
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 14:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-01 23:36]
S4 RelevantKnowledge;RelevantKnowledge;C:\Windows\system32\rlservice.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d670c13-8f53-11dc-bc1e-001aa090d113}]
\shell\AutoRun\command - K:\LaunchU3.exe -a

*Newly Created Service* - NPPTNT2
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 09:29:33 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-01-08 02:58:01 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-15 04:00:02 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Calvin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-16 06:40:02 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-01-16 01:20:23 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 22:40:14
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\Windows\explorer.exe [6.00.6000.16549]
-> C:\Windows\system32\DLAAPI_W.DLL
.
Completion time: 2008-01-15 22:41:35
.
2008-01-16 00:34:42 --- E O F ---
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jan 16, 2008 1:15 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

{New} ComboFix Log

Postby cc481613 » Thu Jan 17, 2008 2:31 am

ComboFix 08-01-17.3 - Calvin 2008-01-16 17:24:42.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2165 [GMT -8:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
Command switches used :: C:\Users\Calvin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Users\Calvin\vbzip10.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\All Users\TEMP

.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.

2008-01-15 22:34 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-12 23:38 . 2008-01-12 23:38 <DIR> d-------- C:\Fraps
2008-01-08 21:52 . 2008-01-16 16:52 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-08 17:58 . 2008-01-08 17:58 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-08 17:58 . 2008-01-08 17:58 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-08 17:58 . 2008-01-08 17:58 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-08 17:58 . 2008-01-08 17:58 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-08 17:58 . 2008-01-08 17:58 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-08 17:58 . 2008-01-08 17:58 118 --a------ C:\Windows\System32\MRT.INI
2008-01-08 17:56 . 2008-01-08 17:56 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-08 17:56 . 2008-01-08 17:56 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-08 17:56 . 2008-01-08 17:56 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-08 17:56 . 2008-01-08 17:56 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-08 17:56 . 2008-01-08 17:56 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-08 17:56 . 2008-01-08 17:56 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-08 17:56 . 2008-01-08 17:56 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-01-08 17:56 . 2008-01-08 17:56 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-07 11:14 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-01-07 11:13 . 2008-01-07 11:13 <DIR> d-------- C:\Program Files\McAfee.com
2008-01-07 11:13 . 2008-01-07 11:14 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-01-07 11:13 . 2006-12-22 16:02 170,408 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-01-07 11:13 . 2007-03-02 14:17 120,360 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-01-07 11:13 . 2006-12-22 16:02 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-01-07 11:13 . 2006-12-22 16:02 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-01-07 11:12 . 2008-01-15 16:29 <DIR> d-------- C:\Program Files\McAfee
2008-01-07 05:24 . 2008-01-07 05:24 <DIR> d--hs---- C:\Users\Calvin\'
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles\All Users\Application Data\SupportSoft
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles
2008-01-05 16:31 . 2008-01-05 18:30 10,740 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-01-05 16:31 . 2008-01-05 18:30 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-01-05 16:29 . 2008-01-07 06:24 <DIR> d-------- C:\Users\All Users\Symantec
2008-01-05 16:29 . 2008-01-07 06:26 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-25 15:24 . 2007-12-25 15:24 78 --a------ C:\Windows\system\WIN32S.INI
2007-12-25 15:23 . 1994-08-24 00:00 188,960 --a------ C:\Windows\system\WINGDE.DLL
2007-12-25 15:23 . 1994-09-21 00:00 92,208 --a------ C:\Windows\system\WING.DLL
2007-12-25 15:23 . 1994-09-21 00:00 12,800 --a------ C:\Windows\system\WING32.DLL
2007-12-25 15:23 . 1994-09-21 00:00 6,736 --a------ C:\Windows\system\WINGDIB.DRV
2007-12-25 15:23 . 1994-09-21 00:00 5,024 --a------ C:\Windows\system\WINGPAL.WND
2007-12-25 15:23 . 1994-06-27 00:00 1,966 --a------ C:\Windows\system\DVA.386
2007-12-25 12:12 . 2007-12-25 12:12 <DIR> d-------- C:\Program Files\Dell DataSafe Online
2007-12-23 10:04 . 2007-12-23 10:05 <DIR> d-------- C:\Program Files\QuickTime
2007-12-20 14:15 . 2007-12-20 14:15 <DIR> d-------- C:\Nexon
2007-12-20 12:34 . 2007-12-20 12:34 <DIR> d-------- C:\Users\All Users\NexonUS
2007-12-19 22:42 . 2007-12-20 08:12 <DIR> d-------- C:\Users\All Users\NVIDIA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 08:08 --------- d---a-w C:\Users\Calvin\AppData\Roaming\U3
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 01:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 01:56 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 01:56 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 01:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-05 18:17 --------- d-----w C:\Program Files\Java
2007-12-13 06:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Apple Computer
2007-12-12 14:58 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 14:58 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 14:58 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 14:57 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-12 14:57 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 14:57 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 14:57 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 14:56 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 14:56 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 14:56 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 14:56 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 14:55 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-12 14:55 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell Photo AIO Printer 966
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell PC Fax
2007-12-09 20:41 --------- d-----w C:\Program Files\AC3Filter
2007-12-07 04:18 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Thunderbird
2007-12-03 05:00 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-03 04:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 17:31 --------- d-----w C:\Users\Calvin\AppData\Roaming\DataSafeOnline
2007-11-27 05:57 --------- d---a-w C:\Users\Calvin\AppData\Roaming\WeatherDPA
2007-11-25 16:58 --------- d-----w C:\Users\Calvin\AppData\Roaming\Roxio
2007-11-24 16:35 --------- d-----w C:\Program Files\Xvid
2007-11-21 04:49 --------- d-----w C:\Program Files\SoundSpectrum
2007-11-19 03:45 --------- d---a-w C:\Users\Calvin\AppData\Roaming\SoundSpectrum
2007-11-17 19:53 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-17 02:22 --------- d-----w C:\Users\Mom\AppData\Roaming\DellFaxCtr
2007-11-14 01:51 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 01:51 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 01:51 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 01:51 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 01:51 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 01:51 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 01:51 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 01:51 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 01:51 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 01:51 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2007-10-17 17:23 10,752 ----a-w C:\Windows\System32\WhoisCL.exe
2007-09-22 16:22 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2008-01-15_22.40.40.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 00:27:42 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-01-17 00:25:45 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-01-16 06:36:03 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-17 01:23:31 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-16 06:36:03 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
+ 2008-01-17 01:23:31 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
- 2008-01-16 06:36:03 3,780,608 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-17 01:23:31 3,780,608 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-16 06:36:04 2,613,248 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-17 01:23:31 2,613,248 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-16 05:42:51 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-17 00:40:52 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-16 05:16:13 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-01-17 00:27:28 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-01-16 00:38:11 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-16 07:07:08 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-16 00:38:11 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-16 07:07:08 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-16 05:47:48 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-17 00:28:39 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-16 00:38:11 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-16 07:07:08 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-16 06:39:58 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-01-17 01:27:26 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-01-16 05:12:41 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-17 00:29:35 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-16 05:12:41 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-17 00:29:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-16 05:12:41 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-17 00:29:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-16 06:37:10 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-01-17 01:24:34 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-01-16 00:29:52 14,870 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
+ 2008-01-17 00:28:12 14,926 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
- 2008-01-16 00:29:51 71,240 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-01-17 00:28:12 71,248 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-01-16 00:29:47 52,814 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-17 00:28:08 52,838 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 09:09 460784]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 17:56 1232896]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe" [2007-12-02 16:30 308464]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 10:57 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 05:26 4452352 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 08:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 08:22 221184]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 02:20 17920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2007-06-29 07:49 312560]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 07:47 292080]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 07:48 304368]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 21:31 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 08:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 08:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 08:07 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 19:05]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 00:22]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-01 23:30]
S2 0284681200529661mcinstcleanup;McAfee Application Installer Cleanup (0284681200529661);C:\Windows\TEMP\028468~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog []
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 14:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-01 23:36]
S4 RelevantKnowledge;RelevantKnowledge;C:\Windows\system32\rlservice.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d670c13-8f53-11dc-bc1e-001aa090d113}]
\shell\AutoRun\command - K:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 09:29:33 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-01-08 02:58:01 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-15 04:00:02 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Calvin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-17 01:25:02 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-01-17 00:29:34 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-16 17:27:31
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\Windows\Explorer.exe [6.00.6000.16549]
-> C:\Windows\system32\DLAAPI_W.DLL
.
Completion time: 2008-01-16 17:28:26
ComboFix2.txt 2008-01-16 06:41:37
.
2008-01-16 00:34:42 --- E O F ---
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby cc481613 » Thu Jan 17, 2008 3:34 am

also... how do I remove Norton AV? I already ran Norton Antivirus Removal Tool from Norton's official website...
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Thu Jan 17, 2008 1:37 pm

cc481613,

Do you mean removal tool?

Also I need to see a new hijackthis log
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

HJT/ComboFix log

Postby cc481613 » Thu Jan 17, 2008 2:40 pm

sorry for forgetting about the HijackThis log... here it is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:38:05 AM, on 17/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineTrayIcon.exe
C:\Program Files\Windows Mail\WinMail.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\system32\wbem\unsecapp.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Calvin\Desktop\HiJackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Dell DataSafe Scheduler] "C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: McAfee Application Installer Cleanup (0284681200529661) (0284681200529661mcinstcleanup) - Unknown owner - C:\Windows\TEMP\028468~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 9903 bytes

If you wanted the ComboFix log too, here it is:

ComboFix 08-01-17.3 - Calvin 2008-01-16 17:24:42.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2165 [GMT -8:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
Command switches used :: C:\Users\Calvin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Users\Calvin\vbzip10.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\All Users\TEMP

.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.

2008-01-15 22:34 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-12 23:38 . 2008-01-12 23:38 <DIR> d-------- C:\Fraps
2008-01-08 21:52 . 2008-01-16 16:52 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-08 17:58 . 2008-01-08 17:58 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-08 17:58 . 2008-01-08 17:58 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-08 17:58 . 2008-01-08 17:58 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-08 17:58 . 2008-01-08 17:58 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-08 17:58 . 2008-01-08 17:58 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-08 17:58 . 2008-01-08 17:58 118 --a------ C:\Windows\System32\MRT.INI
2008-01-08 17:56 . 2008-01-08 17:56 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-08 17:56 . 2008-01-08 17:56 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-08 17:56 . 2008-01-08 17:56 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-08 17:56 . 2008-01-08 17:56 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-08 17:56 . 2008-01-08 17:56 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-08 17:56 . 2008-01-08 17:56 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-08 17:56 . 2008-01-08 17:56 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-08 17:56 . 2008-01-08 17:56 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-01-08 17:56 . 2008-01-08 17:56 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-07 11:14 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-01-07 11:13 . 2008-01-07 11:13 <DIR> d-------- C:\Program Files\McAfee.com
2008-01-07 11:13 . 2008-01-07 11:14 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-01-07 11:13 . 2006-12-22 16:02 170,408 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-01-07 11:13 . 2007-03-02 14:17 120,360 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-01-07 11:13 . 2006-12-22 16:02 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-01-07 11:13 . 2006-12-22 16:02 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-01-07 11:13 . 2006-12-22 16:02 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-01-07 11:12 . 2008-01-15 16:29 <DIR> d-------- C:\Program Files\McAfee
2008-01-07 05:24 . 2008-01-07 05:24 <DIR> d--hs---- C:\Users\Calvin\'
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles\All Users\Application Data\SupportSoft
2008-01-05 17:27 . 2008-01-05 17:27 <DIR> d-------- C:\Windows\Profiles
2008-01-05 16:31 . 2008-01-05 18:30 10,740 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-01-05 16:31 . 2008-01-05 18:30 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-01-05 16:29 . 2008-01-07 06:24 <DIR> d-------- C:\Users\All Users\Symantec
2008-01-05 16:29 . 2008-01-07 06:26 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-25 15:24 . 2007-12-25 15:24 78 --a------ C:\Windows\system\WIN32S.INI
2007-12-25 15:23 . 1994-08-24 00:00 188,960 --a------ C:\Windows\system\WINGDE.DLL
2007-12-25 15:23 . 1994-09-21 00:00 92,208 --a------ C:\Windows\system\WING.DLL
2007-12-25 15:23 . 1994-09-21 00:00 12,800 --a------ C:\Windows\system\WING32.DLL
2007-12-25 15:23 . 1994-09-21 00:00 6,736 --a------ C:\Windows\system\WINGDIB.DRV
2007-12-25 15:23 . 1994-09-21 00:00 5,024 --a------ C:\Windows\system\WINGPAL.WND
2007-12-25 15:23 . 1994-06-27 00:00 1,966 --a------ C:\Windows\system\DVA.386
2007-12-25 12:12 . 2007-12-25 12:12 <DIR> d-------- C:\Program Files\Dell DataSafe Online
2007-12-23 10:04 . 2007-12-23 10:05 <DIR> d-------- C:\Program Files\QuickTime
2007-12-20 14:15 . 2007-12-20 14:15 <DIR> d-------- C:\Nexon
2007-12-20 12:34 . 2007-12-20 12:34 <DIR> d-------- C:\Users\All Users\NexonUS
2007-12-19 22:42 . 2007-12-20 08:12 <DIR> d-------- C:\Users\All Users\NVIDIA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 08:08 --------- d---a-w C:\Users\Calvin\AppData\Roaming\U3
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 03:04 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 01:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 01:56 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 01:56 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 01:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-05 18:17 --------- d-----w C:\Program Files\Java
2007-12-13 06:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Apple Computer
2007-12-12 14:58 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 14:58 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 14:58 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 14:57 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-12 14:57 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 14:57 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 14:57 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 14:56 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 14:56 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 14:56 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 14:56 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 14:55 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-12 14:55 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell Photo AIO Printer 966
2007-12-10 01:22 --------- d-----w C:\Program Files\Dell PC Fax
2007-12-09 20:41 --------- d-----w C:\Program Files\AC3Filter
2007-12-07 04:18 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Thunderbird
2007-12-03 05:00 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-03 04:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 17:31 --------- d-----w C:\Users\Calvin\AppData\Roaming\DataSafeOnline
2007-11-27 05:57 --------- d---a-w C:\Users\Calvin\AppData\Roaming\WeatherDPA
2007-11-25 16:58 --------- d-----w C:\Users\Calvin\AppData\Roaming\Roxio
2007-11-24 16:35 --------- d-----w C:\Program Files\Xvid
2007-11-21 04:49 --------- d-----w C:\Program Files\SoundSpectrum
2007-11-19 03:45 --------- d---a-w C:\Users\Calvin\AppData\Roaming\SoundSpectrum
2007-11-17 19:53 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-17 02:22 --------- d-----w C:\Users\Mom\AppData\Roaming\DellFaxCtr
2007-11-14 01:51 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 01:51 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 01:51 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 01:51 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 01:51 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 01:51 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 01:51 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 01:51 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 01:51 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 01:51 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2007-10-17 17:23 10,752 ----a-w C:\Windows\System32\WhoisCL.exe
2007-09-22 16:22 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2008-01-15_22.40.40.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 00:27:42 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-01-17 00:25:45 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-01-16 06:36:03 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-17 01:23:31 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-16 06:36:03 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
+ 2008-01-17 01:23:31 1,404,928 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
- 2008-01-16 06:36:03 3,780,608 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-17 01:23:31 3,780,608 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-16 06:36:04 2,613,248 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-17 01:23:31 2,613,248 ----a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-16 05:42:51 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-17 00:40:52 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-16 05:16:13 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-01-17 00:27:28 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-01-16 00:38:11 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-16 07:07:08 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-16 00:38:11 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-16 07:07:08 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-16 05:47:48 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-17 00:28:39 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-16 00:38:11 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-16 07:07:08 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-16 06:39:58 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-01-17 01:27:26 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-01-16 05:12:41 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-17 00:29:35 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-16 05:12:41 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-17 00:29:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-16 05:12:41 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-17 00:29:35 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-16 06:37:10 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-01-17 01:24:34 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-01-16 00:29:52 14,870 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
+ 2008-01-17 00:28:12 14,926 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
- 2008-01-16 00:29:51 71,240 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-01-17 00:28:12 71,248 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-01-16 00:29:47 52,814 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-17 00:28:08 52,838 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 09:09 460784]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 17:56 1232896]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe" [2007-12-02 16:30 308464]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 10:57 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 05:26 4452352 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 08:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 08:22 221184]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 02:20 17920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2007-06-29 07:49 312560]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 07:47 292080]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 07:48 304368]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 21:31 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 08:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 08:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 08:07 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 19:05]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 00:22]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-01 23:30]
S2 0284681200529661mcinstcleanup;McAfee Application Installer Cleanup (0284681200529661);C:\Windows\TEMP\028468~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog []
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 14:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-01 23:36]
S4 RelevantKnowledge;RelevantKnowledge;C:\Windows\system32\rlservice.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d670c13-8f53-11dc-bc1e-001aa090d113}]
\shell\AutoRun\command - K:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 09:29:33 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-01-08 02:58:01 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-15 04:00:02 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Calvin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-17 01:25:02 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-01-17 00:29:34 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-16 17:27:31
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\Windows\Explorer.exe [6.00.6000.16549]
-> C:\Windows\system32\DLAAPI_W.DLL
.
Completion time: 2008-01-16 17:28:26
ComboFix2.txt 2008-01-16 06:41:37
.
2008-01-16 00:34:42 --- E O F ---
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Thu Jan 17, 2008 6:14 pm

cc481613,

Your log is clean

I always like to check to make sure something didn't startup again.
And yes Norton is all gone.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby cc481613 » Fri Jan 18, 2008 1:42 am

Thanks a lot... It's working fine now!!! :) :) :) :) :) :) :) :) :) :)
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron