It is currently Tue Sep 01, 2026 1:29 pm


Kindly check this HijackThis log, will you please?

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Kindly check this HijackThis log, will you please?

Postby cc481613 » Sun Dec 21, 2008 7:34 pm

Hey whoever is reading this,

My computer as been acting a bit strangely over the past few days (Internet Explorer homepage changed, slow responsiveness, a few BSoDs, S&D going crazy about registry changes, etc.), so I was just wondering if you could please check this log.
Thanks a lot!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:00 AM, on 21/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sympatico.msn.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://sympatico.zone.msn.com/binFrameW ... b55579.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://sympatico.zone.msn.com/BinFrameW ... b55579.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://sympatico.zone.msn.com/binframew ... b55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://sympatico.zone.msn.com/bingame/z ... b56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://sympatico.zone.msn.com/binframew ... b55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4317457-1F4F-4725-A304-0136F144D81B}: NameServer = 75.154.133.68,75.154.133.100
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 10004 bytes
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Kindly check this HijackThis log, will you please?

Postby Gecko » Tue Dec 23, 2008 1:00 pm

cc481613,

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.


When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Kindly check this HijackThis log, will you please?

Postby cc481613 » Tue Dec 23, 2008 5:56 pm

OK here it is... Thanks for your help, btw.

ComboFix 08-12-21.04 - Calvin 2008-12-23 8:36:48.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3325.2256 [GMT -8:00]
Running from: c:\users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\windows\system32\drivers\msqpdxcfotvqpp.sys
c:\windows\system32\msqpdxuvfntpsc.dll
D:\resycled
d:\resycled\boot.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_MSQPDXSERV.SYS
-------\Service_RelevantKnowledge


((((((((((((((((((((((((( Files Created from 2008-11-23 to 2008-12-23 )))))))))))))))))))))))))))))))
.

2008-12-22 21:14 . 2008-12-22 21:14 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Plogue
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Garritan
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\program files\Plogue
2008-12-22 20:52 . 2008-12-22 20:52 <DIR> d-------- c:\program files\Garritan
2008-12-22 20:50 . 2008-12-22 22:01 <DIR> d-------- c:\program files\Finale 2009
2008-12-22 16:53 . 2008-12-22 16:53 <DIR> d-------- c:\users\All Users\TomTom
2008-12-22 16:53 . 2008-12-22 16:53 <DIR> d-------- c:\progra~2\TomTom
2008-12-22 09:40 . 2008-12-22 09:40 <DIR> d-------- c:\program files\Bonjour
2008-12-21 10:30 . 2008-12-21 10:30 <DIR> d-------- c:\program files\Trend Micro
2008-12-20 07:13 . 2008-12-20 07:13 <DIR> d-------- c:\program files\Kontakt Player 2
2008-12-20 07:09 . 2008-12-22 21:43 <DIR> d-------- c:\program files\Finale 2008
2008-12-19 10:53 . 2008-12-19 10:53 <DIR> d-------- C:\PSFONTS
2008-12-19 10:53 . 2008-12-22 20:54 <DIR> d-------- c:\program files\Finale SongWriter 2007
2008-12-19 09:30 . 2008-12-19 09:30 <DIR> d-------- c:\users\All Users\Musicnotes
2008-12-19 09:30 . 2008-12-19 09:30 <DIR> d-------- c:\progra~2\Musicnotes
2008-12-17 23:08 . 2008-12-17 23:08 <DIR> d-------- c:\program files\Sun
2008-12-17 21:49 . 2008-12-17 21:49 <DIR> d-------- c:\windows\System32\Profiles
2008-12-17 18:18 . 2008-12-17 18:20 <DIR> d-------- c:\program files\RegCure
2008-12-17 16:45 . 2008-12-12 22:23 1,659,392 --a------ c:\windows\System32\mshtml.tlb
2008-12-14 23:13 . 2008-12-14 23:13 <DIR> d-------- c:\users\Guest\AppData\Roaming\Apple Computer
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\program files\iTunes
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\program files\iPod
2008-12-14 12:50 . 2008-12-14 12:50 <DIR> d-------- c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-14 12:47 . 2008-12-14 12:50 <DIR> d-------- c:\program files\Common Files\Apple
2008-12-12 21:17 . 2008-12-12 21:17 <DIR> d-------- c:\users\Guest\AppData\Roaming\InstallShield
2008-12-12 13:39 . 2008-12-12 14:54 <DIR> d-------- c:\users\All Users\WINPENJR
2008-12-12 13:39 . 2008-12-12 13:39 <DIR> d-------- c:\program files\WINPENJR
2008-12-12 13:39 . 2008-12-12 14:54 <DIR> d-------- c:\progra~2\WINPENJR
2008-12-12 13:39 . 2003-04-04 20:07 4,795,092 --------- c:\windows\DFSCSK5U.TTE
2008-12-12 13:39 . 2003-04-04 20:05 3,639,720 --------- c:\windows\DFSCSM3U.TTE
2008-12-12 13:39 . 2003-04-04 20:21 2,581,314 --------- c:\windows\DFSCSM3U.EUF
2008-12-12 13:39 . 2003-04-04 20:20 2,581,314 --------- c:\windows\DFSCSK5U.EUF
2008-12-12 13:39 . 2006-09-08 10:16 131,072 --------- c:\windows\System32\PPWORDW.DLL
2008-12-12 13:39 . 2007-01-26 15:01 53,248 --------- c:\windows\System32\PPadApi.dll
2008-12-12 11:18 . 2008-12-12 11:18 87,336 --a------ c:\windows\System32\dns-sd.exe
2008-12-12 11:11 . 2008-12-12 11:11 61,440 --a------ c:\windows\System32\dnssd.dll
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\users\All Users\Electronic Arts
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\program files\Electronic Arts
2008-12-10 17:25 . 2008-12-10 17:25 <DIR> d-------- c:\progra~2\Electronic Arts
2008-12-10 17:15 . 2008-12-10 17:15 <DIR> d-------- c:\users\Calvin\AppData\Roaming\Leadertech
2008-12-10 17:15 . 2008-12-10 17:15 1,830 --a------ c:\windows\System32\ealregsnapshot1.reg
2008-12-10 17:09 . 2006-07-28 09:30 236,824 --a------ c:\windows\System32\xactengine2_3.dll
2008-12-10 17:09 . 2006-07-28 09:30 62,744 --a------ c:\windows\System32\xinput1_2.dll
2008-12-10 07:26 . 2008-12-10 07:26 <DIR> d-------- c:\program files\PowerISO
2008-12-09 12:56 . 2008-10-21 17:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-09 10:14 . 2008-10-31 17:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-09 10:14 . 2008-10-28 22:29 2,927,104 --a------ c:\windows\explorer.exe
2008-12-09 10:14 . 2008-06-22 17:59 2,868,736 --a------ c:\windows\System32\mf.dll
2008-12-09 10:14 . 2008-06-22 17:59 996,352 --a------ c:\windows\System32\WMNetMgr.dll
2008-12-09 10:14 . 2008-10-20 21:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-09 10:14 . 2008-06-22 17:58 94,720 --a------ c:\windows\System32\logagent.exe
2008-12-09 10:14 . 2008-10-31 19:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-08 14:17 . 2008-12-08 14:17 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2008-12-08 12:14 . 2008-12-08 12:14 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\InstallShield
2008-12-07 09:25 . 2008-12-07 17:07 <DIR> d-------- c:\program files\Motorola Phone Tools
2008-12-07 09:25 . 2008-12-07 09:25 <DIR> d-------- c:\program files\Common Files\Motorola Shared
2008-12-07 08:00 . 2008-01-18 23:34 1,788,928 --ah---t- c:\windows\System32\146b59f8.dll
2008-12-07 08:00 . 2008-01-18 23:34 1,788,928 --ah---t- c:\windows\System32\1274a8ca.dll
2008-12-07 08:00 . 2008-01-18 23:37 179,200 --ah---t- c:\windows\System32\2fa598e9.dll
2008-12-07 08:00 . 2008-01-18 23:37 179,200 --ah---t- c:\windows\System32\1b11fa18.dll
2008-12-06 16:08 . 2008-12-06 17:23 <DIR> d-------- c:\users\Guest\AppData\Roaming\MiniDm
2008-12-06 09:03 . 2008-12-06 09:03 <DIR> d--hs---- c:\users\Calvin\E3FEC7F416167B67
2008-12-06 09:03 . 2008-12-06 09:03 <DIR> d--hs---- c:\users\Calvin\DDE87BF4A91B1F47
2008-12-04 19:58 . 2008-12-04 19:58 <DIR> d-------- c:\users\Calvin\AppData\Roaming\TomTom
2008-12-04 19:56 . 2008-12-04 19:56 <DIR> d-------- c:\program files\TomTom HOME 2
2008-12-03 19:33 . 2008-12-09 11:38 <DIR> d-------- c:\users\Guest\AppData\Roaming\FrostWire
2008-12-03 19:33 . 2008-12-03 19:33 <DIR> d-------- c:\users\Guest\AppData\Roaming\DivX
2008-12-02 01:49 . 2008-12-02 01:54 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\MiniDm
2008-11-29 22:54 . 2008-12-06 09:08 <DIR> d-------- c:\users\Calvin\AppData\Roaming\MiniDm
2008-11-29 22:22 . 2008-12-15 12:37 <DIR> d-------- c:\users\Mom.Calvin-PC\AppData\Roaming\FrostWire
2008-11-26 15:13 . 2008-11-26 15:13 69,632 --a------ c:\windows\System32\MSDATLST.oca
2008-11-26 15:13 . 2008-11-26 15:13 65,536 --a------ c:\windows\System32\MSDATGRD.oca
2008-11-26 15:13 . 2008-11-26 15:13 44,032 --a------ c:\windows\System32\MSDATREP.oca
2008-11-26 15:13 . 2008-11-26 15:13 35,840 --a------ c:\windows\System32\MSADODC.oca
2008-11-26 08:23 . 2008-12-22 22:03 <DIR> d-------- c:\users\Calvin\Incomplete
2008-11-25 10:14 . 2008-10-20 21:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-25 10:14 . 2008-08-27 19:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-25 10:14 . 2008-08-27 19:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-25 10:14 . 2008-08-27 19:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-25 10:14 . 2008-10-21 19:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-24 15:58 . 2008-11-24 15:58 <DIR> d-------- c:\users\Calvin\AppData\Roaming\teamspeak2
2008-11-24 15:57 . 2008-11-24 15:57 34,064 --a------ c:\windows\System32\lhacm.acm
2008-11-23 10:20 . 2007-09-17 00:07 134,270 --a------ c:\windows\System32\nvapps.xml

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-23 16:26 --------- d-----w c:\program files\Dl_cats
2008-12-23 07:38 --------- d-----w c:\users\Calvin\AppData\Roaming\FrostWire
2008-12-23 05:50 --------- d-----w c:\program files\EA Sports
2008-12-23 05:02 --------- d---a-w c:\users\Calvin\AppData\Roaming\U3
2008-12-22 16:28 --------- d-----w c:\progra~2\Spybot - Search & Destroy
2008-12-22 16:21 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-18 14:53 --------- d-----w c:\progra~2\Microsoft Help
2008-12-18 07:07 --------- d-----w c:\program files\Java
2008-12-17 02:42 --------- d-----w c:\program files\Dell
2008-12-15 07:12 --------- d-----w c:\program files\McAfee
2008-12-12 22:45 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-10 00:21 --------- d-----w c:\program files\Windows Mail
2008-12-04 04:37 --------- d-----w c:\program files\NCH Swift Sound
2008-12-03 23:43 --------- d--h--w c:\users\Guest\AppData\Roaming\GTek
2008-11-24 01:35 --------- d-----w c:\program files\FrostWire
2008-11-23 18:39 --------- d-----w c:\progra~2\NVIDIA
2008-11-23 18:03 --------- d-----w c:\program files\MSECACHE
2008-11-23 05:33 --------- d-----w c:\program files\Common Files\Microsoft Games
2008-11-23 05:05 --------- d-----w c:\program files\Microsoft Games
2008-11-20 16:53 --------- d-----w c:\program files\Windows Live
2008-11-20 16:45 --------- d-----w c:\progra~2\WLInstaller
2008-11-20 16:44 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-20 05:39 --------- d-----w c:\program files\Common Files\Windows Live
2008-11-18 15:10 --------- d-----w c:\program files\ToniArts
2008-11-18 02:17 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-17 05:12 --------- d-----w c:\program files\DivX
2008-11-16 06:43 891,448 ----a-w c:\windows\system32\drivers\tcpip.sys
2008-11-07 22:23 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-11-06 01:39 --------- d-----w c:\progra~2\NCH Swift Sound
2008-11-06 01:13 --------- d-----w c:\program files\NCH Software
2008-11-04 13:37 --------- d-----w c:\program files\DVDVideoSoft
2008-11-04 13:37 --------- d-----w c:\program files\Common Files\DVDVideoSoft
2008-11-03 12:44 --------- d-----w c:\users\Calvin\AppData\Roaming\NCH Swift Sound
2008-11-02 08:44 56,572 ----a-w c:\windows\system32\drivers\scdemu.sys
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-25 11:50 --------- d-----w c:\users\Calvin\AppData\Roaming\DivX
2008-05-23 02:33 174 --sha-w c:\program files\desktop.ini
2008-04-20 16:33 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
2008-06-15 03:08 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-15 03:08 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-15 03:08 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-08-19 21:00 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-08-19 21:00 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081920080820\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Google Update"="c:\users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-12-08 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 292080]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8497696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 106496]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 c:\windows\RtHDVCpl.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

c:\users\Mom.Calvin-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-18 23:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe"
"EA Core"=c:\program files\Electronic Arts\EADM\Core.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 966\memcard.exe"
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Windows Mobile-based device management"=%windir%\WindowsMobile\wmdSync.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}c:\\windows\\explorer.exe"= UDP:c:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}c:\\windows\\explorer.exe"= TCP:c:\windows\explorer.exe:Windows Explorer
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:c:\windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:c:\windows\System32\dlcqcoms.exe:Dell Communications System
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{625BF72C-6185-4D8F-B800-F26772BBEA96}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{7FDCC7F9-7C63-4F32-A0FD-967282029470}"= UDP:3703:Adobe Version Cue CS3 Server
"{A54138F7-585B-45C2-B398-2708C437E641}"= UDP:3704:Adobe Version Cue CS3 Server
"{88F3E162-3910-4B5C-81C9-26A4EF828D5F}"= UDP:50900:Adobe Version Cue CS3 Server
"{CF41B43C-48BF-45B6-A844-345E7BD558F2}"= UDP:50901:Adobe Version Cue CS3 Server
"{E9035596-E03B-4100-8521-8ACD9A3F79FD}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{940BD430-EBCF-4C4B-83D7-C7AF61054A01}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{59007D0B-3B78-41DA-85DC-CBC43F6857C4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{F8D65109-5A54-4613-BE57-2860958BD620}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{EBF5BCD1-808E-4CE6-A528-ED1154649141}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{F0BB254B-2B56-4670-A0F8-D6A91169DE26}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{59BF8A74-AD16-4AB4-B2C3-67F7E805C283}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6D85EE90-91B7-47CC-B708-5A0DD1A806F9}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{673533C1-1567-476B-B0CA-880A5E0613A7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{17B6B88C-9ED5-4BAF-A064-7C3DC77EF063}"= UDP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{3B655E75-3E4B-4939-B38C-1A8B805B52BE}"= TCP:c:\program files\FrostWire\FrostWire.exe:FrostWire
"{E30B1ED6-3B27-4017-859A-73625F16C14B}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{A5272FB4-B372-4E5B-8044-3F64CF915C5B}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{F7DB8495-1B2A-48A4-A937-0457EADA98C2}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{736BCF32-1B55-4D28-B487-4A116A0DBA6C}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{D74796E9-F28D-4A12-9FC5-52CF837FFC3C}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{76C60FB8-9515-4942-BD58-DCF4DEBBF8F0}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{9F4618AB-AA21-4387-B49D-032F6F4351ED}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{D58E6597-A2F9-4BD8-9CCB-ABAEF7C6402A}"= TCP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:c:\program files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{27EAFB26-AD02-4DA7-A1C1-42ACB79D9BFD}"= UDP:c:\windows\System32\dlcqcoms.exe:Lexmark Communications System
"{2837EF02-5155-406F-83D4-AC9CA54B2E72}"= TCP:c:\windows\System32\dlcqcoms.exe:Lexmark Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:c:\program files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{19C938C0-9289-4C04-A2AA-47B1E9FB7336}"= UDP:85:BroadWave Web Server
"{C14A4084-33F4-47D5-9F1B-C929F5E45C64}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5A217F5D-ABFD-4E5E-A435-66F5452D8175}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FF05D992-4BAE-43AD-B25D-89B900B4DCAA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{A6593B8D-A94D-4691-BB69-793594987B23}c:\\program files\\microsoft games\\microsoft flight simulator x\\fsx.exe"= UDP:c:\program files\microsoft games\microsoft flight simulator x\fsx.exe:Microsoft Flight Simulator®
"UDP Query User{348C7E6D-1243-42A4-B350-113B89C8D52C}c:\\program files\\microsoft games\\microsoft flight simulator x\\fsx.exe"= TCP:c:\program files\microsoft games\microsoft flight simulator x\fsx.exe:Microsoft Flight Simulator®
"TCP Query User{72819F34-FEDA-4427-BE8E-EB70E0C500AF}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{EA0BAF55-95AF-4E47-8F68-7AEDAB3D5A86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7CAA56AD-F950-417F-BDBF-2B4CB5C08216}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E5571FED-1E30-4A0F-A188-BE56964019EC}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{F321E4C2-1EFD-48C6-B4BF-D9A328A6F6D3}c:\\program files\\ea sports\\nhl 09\\nhl2009.exe"= UDP:c:\program files\ea sports\nhl 09\nhl2009.exe:nhl2009
"UDP Query User{D00C2D17-0E99-4D9E-A4C0-7170EA3B6EB5}c:\\program files\\ea sports\\nhl 09\\nhl2009.exe"= TCP:c:\program files\ea sports\nhl 09\nhl2009.exe:nhl2009
"{54436CA8-E579-4E5A-8238-BE9AACE99214}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{29567BCB-3B27-4C75-B06F-E0D93411E436}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8E642E5E-539F-4659-9B56-A6A32A0D634D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8A64FD1C-3824-45CB-AACA-72A2660C912E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Nexon\\Combat Arms\\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Combat Arms\\CombatArms.exe"= c:\program files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Program Files\\Combat Arms\\Engine.exe"= c:\program files\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Nexon\\Combat Arms\\CombatArms.exe"= c:\program files\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Program Files\\Nexon\\Combat Arms\\Engine.exe"= c:\program files\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe

R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-11-21 809296]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - BEEP
.
Contents of the 'Scheduled Tasks' folder

2008-12-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 08:09]

2008-12-23 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-08 07:09]

2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-12-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 09:20]

2008-12-18 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 09:20]

2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]

2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{2B3DF531-795E-4B8F-852D-F9141689C0CD}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]

2008-12-23 c:\windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-23 08:45:03
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\dlcqcoms.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-12-23 8:53:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-23 16:53:00

Pre-Run: 364,595,970,048 bytes free
Post-Run: 364,325,277,696 bytes free

358 --- E O F --- 2008-12-18 21:46:03
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Kindly check this HijackThis log, will you please?

Postby Gecko » Sat Dec 27, 2008 2:58 pm

cc481613,

I don't see anything else bad in your combofix log
However, that FrostWire file sharing is not the safest p2p program out there and could be where the infection came from

Please post a new hijackthis log in your reply
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Kindly check this HijackThis log, will you please?

Postby cc481613 » Sat Dec 27, 2008 7:29 pm

Okay here it is...


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:40 AM, on 27/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\FrostWire\FrostWire.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://sympatico.zone.msn.com/binFrameW ... b55579.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://sympatico.zone.msn.com/BinFrameW ... b55579.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://sympatico.zone.msn.com/binframew ... b55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://sympatico.zone.msn.com/bingame/z ... b56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://sympatico.zone.msn.com/binframew ... b55579.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4317457-1F4F-4725-A304-0136F144D81B}: NameServer = 75.154.133.68,75.154.133.100
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 9063 bytes
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Kindly check this HijackThis log, will you please?

Postby Gecko » Sat Dec 27, 2008 9:10 pm

Do you what these IPs are for 75.154.133.68 and 75.154.133.100?
I scanned them but they came back as unknown and unreachable.

If you do not know what they are then and the following to the Hijackthis fix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4317457-1F4F-4725-A304-0136F144D81B}: NameServer = 75.154.133.68,75.154.133.100

Otherwise follow these instructions.

Start HijackThis and click "Do a system scan only" put a check next to each of the following entries:
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
Now click the "Fixed checked" button and then close HijackThis


Click Start, click My computer and then right click on your C: drive and select "Properties"
Now click the "Disk cleanup" button, in the next window put a check next to Recycle Bin, Temporary Internet Files and Temporary Files click OK and then click yes in the popup window.

Restart your computer and post a new HiJackThis log when you reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Kindly check this HijackThis log, will you please?

Postby cc481613 » Sun Dec 28, 2008 4:10 am

Okay I did that... Thanks for your help:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:09:27 PM, on 27/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Calvin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\FrostWire\FrostWire.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 7232 bytes
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Kindly check this HijackThis log, will you please?

Postby Gecko » Sun Dec 28, 2008 1:02 pm

cc481613,

Your log is clean.

How is it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Kindly check this HijackThis log, will you please?

Postby cc481613 » Sun Dec 28, 2008 4:00 pm

It's quite a bit better now, thanks a lot for the help!
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron