Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - physicsforfun

Pages: [1] 2
1
Tech Clinic / red x and java applet issues
« on: January 03, 2006, 01:57:07 AM »
I can't easily find the other site I was on, regarding the dll files, but I did run accross this one where Firefox was working but not IE.
So,  this may be relevant

http://www.experts-exchange.com/Web/Browse...Q_21565697.html

2
Tech Clinic / red x and java applet issues
« on: January 01, 2006, 09:00:57 PM »
Firefox setting:  "direct connection to the internet"

IE:  "automatically detect settings"

Java control panel network settings:  "use browser settings"

here is the HJT file you requested

# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost

3
Tech Clinic / red x and java applet issues
« on: December 31, 2005, 12:46:21 AM »
mapquest.com does not show maps with IE but does show maps with Firefox
java.com does not show the middle frame of the homepage entitled "java.com showcase" with IE ,  but it does appear correctly  with Firefox

4
Tech Clinic / red x and java applet issues
« on: December 30, 2005, 11:49:05 PM »
Wow!  Firefox actually works...neither IE or Netscape will function properly...

Can you explain what is going on?

I suggested that some DLL file (unknown to me which one) might be missing because I saw that suggestion on another forum discussing malfunctioning of Java and the red x problem...

Is there a way to fix IE and Netscape so they will work also, or should I just give it up and move to Firefox?

5
Tech Clinic / red x and java applet issues
« on: December 30, 2005, 11:09:25 PM »
I still cannot get certain java applets to run properly and many important web sites do not display for me.

I have removed the old and reinstalled the latest JRE as a full off line install and its still not working.  This has been going on for some time and a month or so ago I tried in this forum to get a handle on it, but nothing seemed to work.

Now with the new JRE upgrade 6,  the Java console gives me the following, potentially relevant,  information:

Java Plug-in 1.5.0_06
Using JRE version 1.5.0_06 Java HotSpot(tm) Client VM
User home directory = C:\Documents and Settings\Paul


----------------------------------------------------
c:   clear console window
f:   finalize objects on finalization queue
g:   garbage collect
h:   display this help message
l:   dump classloader list
m:   print memory usage
o:   trigger logging
p:   reload proxy configuration
q:   hide console
r:   reload policy configuration
s:   dump system and deployment properties
t:   dump thread list
v:   dump thread stack
x:   clear classloader cache
0-5: set trace level to <n>
----------------------------------------------------

java.lang.StringIndexOutOfBoundsException: String index out of range: 41
   at java.lang.String.charAt(Unknown Source)
   at sun.plugin.viewer.context.AppletAudioClipFactory$1.run(Unknown Source)
   at java.security.AccessController.doPrivileged(Native Method)
   at sun.plugin.viewer.context.AppletAudioClipFactory.createAudioClip(Unknown Source)
   at sun.plugin.viewer.context.DefaultPluginAppletContext.getAudioClip(Unknown Source)
   at java.applet.Applet.getAudioClip(Unknown Source)
   at java.applet.Applet.getAudioClip(Unknown Source)
   at apPopupMenu.IIl1(Unknown Source)
   at apPopupMenu.run(Unknown Source)
   at java.lang.Thread.run(Unknown Source)
java.lang.StringIndexOutOfBoundsException: String index out of range: 41
   at java.lang.String.charAt(Unknown Source)
   at sun.plugin.viewer.context.AppletAudioClipFactory$1.run(Unknown Source)
   at java.security.AccessController.doPrivileged(Native Method)
   at sun.plugin.viewer.context.AppletAudioClipFactory.createAudioClip(Unknown Source)
   at sun.plugin.viewer.context.DefaultPluginAppletContext.getAudioClip(Unknown Source)
   at java.applet.Applet.getAudioClip(Unknown Source)
   at java.applet.Applet.getAudioClip(Unknown Source)
   at apPopupMenu.IIl1(Unknown Source)
   at apPopupMenu.run(Unknown Source)
   at java.lang.Thread.run(Unknown Source)



I would really like to fix whatever is missing or corrupted and make my computer work properly again.  

One concern I have is that in past episodes of cleaning this computer of malware, that some key DLL file was inadvertently deleted.  Is ther a way to check for this?

Help!!!

6
Tech Clinic / trouble with Java (I think)
« on: November 15, 2005, 11:52:37 PM »
I did as you requested and there was no change . I still cannot see the center box labeled Java.com showcase at the Java.com site, for example.

JRE 1.5 is checked

All Java entries in ZAP have the green checkmark, so I think they are allowed.

I also tried with ZAP disabled and got the same result.

What I am unsure of at this point is if this is a Java problem or something else.  Is there some way to check this.  Is the little red x unique to a Java script problem (applets are not running?)  or is there potentially some other source for this symptom?

I also emailed Java and this is what they responded with:

Thank you very much for your interest in Java(tm) technology. We highly encourage you to spend some time reading the solutions published on the Java.com Help and FAQ pages.

Although, majority of the users who download and install Java Runtime Environment (JRE) didn't experience any problems when verifying JRE install, we recognize that there are currently some users having complications with the verify install applet.
In effort to find the root cause of the problem we need your help to identify and reproduce the error. We need you to follow the steps below to extract the information from your system in regard to JRE verify install.

We need the following information from you:

Browser Name and Version:
Conntection Type (DSL/Cable, Coporate LAN, Dialup) :
Connection Vendor (such as Comcast, SBC Yahoo etc) :
If protected by a Firewall, which make and version:
What version of the JRE was installed before attempting to Install?
What errors are displaying in the page?
What errors are showing in the JRE console Log?
(this link http://java.com/en/download/help/5000020900.xml  shows you how to enable JRE console, all you need to do afterwards is copy the log and paste it in to your email reply to us)
What "if any" errors are showing in the server log (such error messages as http://404 or http://500)?

Description:
(Please provide a full description of the problem that you experienced
and the exact steps to reproduce it)

We truly appreciate you patience and support while we investigate this specific bug.

Thank you very much for contacting Sun Microsystems. Java.com – The Source for Java Technology.

Regards,
Consumer Java Support
Sun Microsystems, Inc.

I do plan to follow up with them, but I have a strange feeling that their verification bug and my actual problem may be two distinct and separate problems.  The fact that the Java virtual machine test works fine makes me wonder if Java is actually the problem here...Hence my question above about the significance of the little red x.  Are there other potential sources of difficulty (Activex, etc.)

Any ideas on what to do next?

7
Tech Clinic / trouble with Java (I think)
« on: November 15, 2005, 06:41:47 PM »
OK,  I did the full offline installation and restarted everything.  Also checked the internet options, both  advanced and security to be sure Java was enabled.  Same for control panel Java network settings are set to use browser settings.

When I run the "verify installation"  on the Java website it hangs up. but when I check out help/cannot verify installation , I get an alternative "Test Java virtual machine" and that works fine....

Yet when I examine various web sites, such as Java.com itself, for example, there are regions that give no visual display and only the little red x in the upper lefthand corner.  For the Java site, the central panel entitled "Java.com showcase" is not displayed.  Only the blank box with the little red x...

Any suggestions as to what to do next would be appreciated...

8
Tech Clinic / trouble with Java (I think)
« on: November 15, 2005, 12:02:10 AM »
Sorry to report that I still have the little red x in upper left corner of various web sites...

I went back to Java.com again to try and download the software and got the same error (I have no yellow bar to click on):

Windows XP SP2 users: if you encounter an error, look at the top of this page for a yellow bar that reads "This site might require the following ActiveX control: 'J2SE Runtime Environment 5.0 Update 5' from 'Sun Microsystems, Inc.'. Click here to install..." Click the yellow bar and choose "Install ActiveX Control..." to allow installation to proceed.

We encountered an issue while trying to automatically install Java™ software onto your machine. As a result, Java software was not installed properly.


Do you think there is a problem with the registry or that some key piece of software is missing??

9
Tech Clinic / trouble with Java (I think)
« on: November 14, 2005, 11:03:16 PM »
That last entry was me.  I forgot to log in after restarting the computer.  sorry. PFF

10
Tech Clinic / trouble with Java (I think)
« on: November 14, 2005, 08:46:37 PM »
here is the result of the scan from jotti:

The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

11
Tech Clinic / trouble with Java (I think)
« on: November 14, 2005, 10:42:58 AM »
I am having trouble with web sites visited on this computer.  Online games, for example,  now have many sections of their sites filled with the blank box with the little red x in the upper left-hand corner.  I went to Sun.com and tried to download a new version of Java, but it would not download because of "issues" .  Here is the error message:  

Windows XP SP2 users: if you encounter an error, look at the top of this page for a yellow bar that reads "This site might require the following ActiveX control: 'J2SE Runtime Environment 5.0 Update 5' from 'Sun Microsystems, Inc.'. Click here to install..." Click the yellow bar and choose "Install ActiveX Control..." to allow installation to proceed.

We encountered an issue while trying to automatically install Java™ software onto your machine. As a result, Java software was not installed properly.

My system did NOT display the yellow bar described above, but I did manage to go to another Java site and successfully downloaded and installed J2SE Runtime environment 5.0 update 5,  but there was no improvement in the performance. (still the little red xs). I do not know if the needed Activex control is still missing or what.

I also have checked my Internet explorer options and on the security tab have enabled activex and java (at least I think I have).  Thus, I am concerned that some sort of malware or something has disabled Java, which makes the computer less than optimal for a variety of reasons.  Here is the recent Hijackthis file, if it can be used to diagnose the problem:

Logfile of HijackThis v1.99.1
Scan saved at 10:25:56 AM, on 11/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O21 - SSODL: Mp3ackbd - {1EA9FBEC-7406-47D3-A0D8-69C2EF5A8C3B} - C:\WINDOWS\system32\oleruurl.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

12
Tech Clinic / malware aurora, trojans, etc
« on: September 06, 2005, 06:20:34 PM »
Gestolo,

you had asked that I return in a few days to post another HJT file.


"I'll leave this topic open for a couple of days, after which
Would you mind returning and post a fresh hijackthis log

Just want to make sure it's still clean
I don't see any problems, but if something returns I know we can get you into safe mode now "



So here I am and here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 7:07:46 PM, on 9/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Hope all is still ok.

Paul

13
Tech Clinic / malware aurora, trojans, etc
« on: September 01, 2005, 11:48:36 PM »
vx2 was clean

here is the logfile from adaware


Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, September 02, 2005 12:37:30 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R64 31.08.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):5 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


9-2-2005 12:37:30 AM - Scan started. (Smart mode)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
    FilePath           : \SystemRoot\System32\
    ProcessID          : 596
    ThreadCreationTime : 9-2-2005 4:33:11 AM
    BasePriority       : Normal


#:2 [csrss.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 664
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal


#:3 [winlogon.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 688
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : High


#:4 [services.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 732
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Services and Controller app
    InternalName       : services.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : services.exe

#:5 [lsass.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 744
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : LSA Shell (Export Version)
    InternalName       : lsass.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : lsass.exe

#:6 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 900
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:7 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 976
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:8 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1068
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:9 [incdsrv.exe]
    FilePath           : C:\Program Files\Ahead\InCD\
    ProcessID          : 1092
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 4, 3, 20, 1
    ProductVersion     : 4, 3, 20, 1
    ProductName        : Nero AG incdsrv
    CompanyName        : Nero AG
    FileDescription    : incdsrv
    InternalName       : incdsrv
    LegalCopyright     : Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
    LegalTrademarks    : InCD is a trademark of Nero AG
    OriginalFilename   : incdsrv.exe

#:10 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1224
    ThreadCreationTime : 9-2-2005 4:33:18 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:11 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1344
    ThreadCreationTime : 9-2-2005 4:33:18 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:12 [spoolsv.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1512
    ThreadCreationTime : 9-2-2005 4:33:20 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion     : 5.1.2600.2696
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Spooler SubSystem App
    InternalName       : spoolsv.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : spoolsv.exe

#:13 [defwatch.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 1644
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Norton AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Virus Definition Daemon
    InternalName       : DefWatch
    LegalCopyright     : Copyright © 1998 Symantec Corporation
    OriginalFilename   : DefWatch.exe

#:14 [ewidoctrl.exe]
    FilePath           : C:\Program Files\ewido\security suite\
    ProcessID          : 1672
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 3, 0, 0, 1
    ProductVersion     : 3, 0, 0, 1
    ProductName        : ewido control
    CompanyName        : ewido networks
    FileDescription    : ewido control
    InternalName       : ewido control
    LegalCopyright     : Copyright © 2004
    OriginalFilename   : ewidoctrl.exe

#:15 [mdm.exe]
    FilePath           : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
    ProcessID          : 1704
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 7.00.9064.9150
    ProductVersion     : 7.00.9064.9150
    ProductName        : Microsoft Development Environment
    CompanyName        : Microsoft Corporation
    FileDescription    : Machine Debug Manager
    InternalName       : mdm.exe
    LegalCopyright     : Copyright © Microsoft Corp. 1997-2000
    OriginalFilename   : mdm.exe

#:16 [rtvscan.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 1880
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Symantec AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec AntiVirus
    LegalCopyright     : Copyright © Symantec Corporation 1991-2003

#:17 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1924
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:18 [vsmon.exe]
    FilePath           : C:\WINDOWS\SYSTEM32\ZoneLabs\
    ProcessID          : 1968
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 4.0.123.012
    ProductVersion     : 4.0.123.012
    ProductName        : TrueVector Service
    CompanyName        : Zone Labs Inc.
    FileDescription    : TrueVector Service
    InternalName       : vsmon
    LegalCopyright     : Copyright © 1998-2003, Zone Labs Inc.
    OriginalFilename   : vsmon.exe

#:19 [explorer.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 1856
    ThreadCreationTime : 9-2-2005 4:33:42 AM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows Explorer
    InternalName       : explorer
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : EXPLORER.EXE

#:20 [alg.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 524
    ThreadCreationTime : 9-2-2005 4:33:43 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Application Layer Gateway Service
    InternalName       : ALG.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : ALG.exe

#:21 [hkcmd.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1420
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        : 3,0,0,2104
    ProductVersion     : 7,0,0,2104
    ProductName        : Intel® Common User Interface
    CompanyName        : Intel Corporation
    FileDescription    : hkcmd Module
    InternalName       : HKCMD
    LegalCopyright     : Copyright 1999-2003, Intel Corporation
    OriginalFilename   : HKCMD.EXE

#:22 [bcmsmmsg.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 1776
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        :  3.5.25 08/27/2003 20:04:35
    ProductVersion     :  3.5.25 08/27/2003 20:04:35
    ProductName        : BCM Modem Messaging Applet
    CompanyName        : Broadcom Corporation
    FileDescription    : Modem Messaging Applet
    InternalName       : smdmstat.exe
    LegalCopyright     : Copyright © Broadcom Corporation 1998-2000
    OriginalFilename   : smdmstat.exe

#:23 [sgtray.exe]
    FilePath           : C:\Program Files\Common Files\Sonic\Update Manager\
    ProcessID          : 1820
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        : 1.01.11a
    CompanyName        : Sonic Solutions
    FileDescription    : Sonic Update Manager
    LegalCopyright     : Copyright © 2002 Sonic Solutions

#:24 [pcmservice.exe]
    FilePath           : C:\Program Files\Dell\Media Experience\
    ProcessID          : 2088
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 1.0.0826
    ProductVersion     : 1.0.0826
    ProductName        : PCM2Launcher Application
    CompanyName        : CyberLink Corp.
    FileDescription    : PowerCinema Resident Program for Dell
    InternalName       : PowerCinema Resident Program for Dell
    LegalCopyright     : Copyright c 2003 CyberLink Corp.
    OriginalFilename   : PCM2Launcher.EXE

#:25 [realsched.exe]
    FilePath           : C:\Program Files\Common Files\Real\Update_OB\
    ProcessID          : 2112
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 0.1.0.1622
    ProductVersion     : 0.1.0.1622
    ProductName        : RealOne Player (32-bit)
    CompanyName        : RealNetworks, Inc.
    FileDescription    : RealNetworks Scheduler
    InternalName       : schedapp
    LegalCopyright     : Copyright © RealNetworks, Inc. 1995-2002
    LegalTrademarks    : RealAudio(tm) is a trademark of RealNetworks, Inc.
    OriginalFilename   : realsched.exe

#:26 [mmtask.exe]
    FilePath           : C:\Program Files\MusicMatch\MusicMatch Jukebox\
    ProcessID          : 2128
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 1.0.0.1
    ProductVersion     : 1.0.0.1
    ProductName        : TODO: <Product name>
    CompanyName        : TODO: <Company name>
    FileDescription    : TODO: <File description>
    InternalName       : mmtask.exe
    LegalCopyright     : TODO: © <Company name>.  All rights reserved.
    OriginalFilename   : mmtask.exe

#:27 [support.exe]
    FilePath           : C:\Program Files\Common Files\Dell\EUSW\
    ProcessID          : 2136
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 2, 0, 0, 34
    ProductVersion     : 1, 0, 0, 1
    ProductName        : Dell Support
    CompanyName        : Dell
    FileDescription    : Support
    InternalName       : Support
    LegalCopyright     : Copyright © 2002
    OriginalFilename   : Support.exe

#:28 [vptray.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 2144
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Symantec AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec AntiVirus
    LegalCopyright     : Copyright © Symantec Corporation 1991-2003

#:29 [hpztsb09.exe]
    FilePath           : C:\WINDOWS\System32\spool\drivers\w32x86\3\
    ProcessID          : 2152
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 2.236.2.0
    ProductVersion     : 2.236.2.0
    ProductName        : HP DeskJet
    CompanyName        : HP
    LegalCopyright     : Copyright © Hewlett-Packard Company 1999-2003

#:30 [hpcmpmgr.exe]
    FilePath           : C:\Program Files\HP\hpcoretech\
    ProcessID          : 2180
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 2.1.1
    ProductVersion     : 2.1.1
    ProductName        : hp coretech  (COmponent REuse TECHnology)
    CompanyName        : Hewlett-Packard Company
    FileDescription    : HP Framework Component Manager Service
    InternalName       : HPComponentManagerService module
    LegalCopyright     : Copyright © Hewlett-Packard. 2002-2003
    OriginalFilename   : HPCmpMgr.exe

#:31 [hpwuschd2.exe]
    FilePath           : C:\Program Files\Hewlett-Packard\HP Software Update\
    ProcessID          : 2192
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 3, 0, 38, 1
    ProductVersion     : 3, 0, 38, 1
    ProductName        : HP Software Update Application
    CompanyName        : Hewlett-Packard Company
    FileDescription    : hpwuSchd
    InternalName       : hpwuSchd
    LegalCopyright     : Copyright © 2003
    OriginalFilename   : hpwuSchd.exe

#:32 [notifyalert.exe]
    FilePath           : C:\Program Files\Dell\Support\Alert\bin\
    ProcessID          : 2200
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal


#:33 [hpotdd01.exe]
    FilePath           : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
    ProcessID          : 2208
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : Hewlett-Packard hpotdd01
    CompanyName        : Hewlett-Packard
    FileDescription    : hpotdd01
    InternalName       : hpotdd01
    LegalCopyright     : Copyright © 2002
    OriginalFilename   : hpotdd01.exe

#:34 [ituneshelper.exe]
    FilePath           : C:\Program Files\iTunes\
    ProcessID          : 2216
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 4.6.0.15
    ProductVersion     : 4.6.0.15
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iTunesHelper Module
    InternalName       : iTunesHelper
    LegalCopyright     : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iTunesHelper.exe

#:35 [qttask.exe]
    FilePath           : C:\Program Files\QuickTime\
    ProcessID          : 2224
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 6.5.1
    ProductVersion     : QuickTime 6.5.1
    ProductName        : QuickTime
    CompanyName        : Apple Computer, Inc.
    InternalName       : QuickTime Task
    LegalCopyright     : © Apple Computer, Inc. 2001-2004
    OriginalFilename   : QTTask.exe

#:36 [ipodservice.exe]
    FilePath           : C:\Program Files\iPod\bin\
    ProcessID          : 2256
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 4.6.0.15
    ProductVersion     : 4.6.0.15
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iPodService Module
    InternalName       : iPodService
    LegalCopyright     : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iPodService.exe

#:37 [incd.exe]
    FilePath           : C:\Program Files\Ahead\InCD\
    ProcessID          : 2424
    ThreadCreationTime : 9-2-2005 4:33:50 AM
    BasePriority       : Normal
    FileVersion        : 4, 3, 20, 1
    ProductVersion     : 4, 3, 20, 1
    ProductName        : Nero AG InCD
    CompanyName        : Nero AG
    FileDescription    : InCD
    InternalName       : InCD
    LegalCopyright     : Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
    LegalTrademarks    : InCD is a trademark of Nero AG
    OriginalFilename   : InCD.exe

#:38 [ctfmon.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 2448
    ThreadCreationTime : 9-2-2005 4:33:51 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : CTF Loader
    InternalName       : CTFMON
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : CTFMON.EXE

#:39 [mssysmgr.exe]
    FilePath           : C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\
    ProcessID          : 2464
    ThreadCreationTime : 9-2-2005 4:33:51 AM
    BasePriority       : Normal
    FileVersion        : 2, 1, 1, 537
    ProductVersion     : 2, 1, 1, 537
    ProductName        : PhotoShow Deluxe
    CompanyName        : Simple Star, Inc.
    FileDescription    : PhotoShow Deluxe Media Manager
    InternalName       : PhotoShow Deluxe Media Manager
    LegalCopyright     : Copyright © 2003 Simple Star, Inc.
    OriginalFilename   : mssysmgr.exe

#:40 [gcasdtserv.exe]
    FilePath           : C:\Program Files\Microsoft AntiSpyware\
    ProcessID          : 2484
    ThreadCreationTime : 9-2-2005 4:33:52 AM
    BasePriority       : Normal
    FileVersion        : 1.00.0615
    ProductVersion     : 1.00.0615
    ProductName        : Microsoft AntiSpyware (Beta 1)
    CompanyName        : Microsoft Corporation
    FileDescription    : Microsoft AntiSpyware Data Service
    InternalName       : gcasDtServ
    LegalCopyright     : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
    LegalTrademarks    : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet(tm) is a trademark of Microsoft Corporation.
    OriginalFilename   : gcasDtServ.exe

#:41 [acrotray.exe]
    FilePath           : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
    ProcessID          : 2556
    ThreadCreationTime : 9-2-2005 4:33:55 AM
    BasePriority       : Normal
    FileVersion        : 5, 0, 0, 0
    ProductVersion     : 5, 0, 0, 0
    ProductName        : AcroTray - Adobe Acrobat Distiller helper application.
    CompanyName        : Adobe Systems Inc.
    FileDescription    : AcroTray
    InternalName       : AcroTray
    LegalCopyright     : Copyright © 2001
    OriginalFilename   : AcroTray.exe

#:42 [scannerfinder.exe]
    FilePath           : C:\Program Files\Microtek\ScanWizard 5\
    ProcessID          : 2772
    ThreadCreationTime : 9-2-2005 4:34:03 AM
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : SDII Application
    FileDescription    : SDII MFC Application
    InternalName       : SDII
    LegalCopyright     : Copyright © 2000
    OriginalFilename   : SDII.EXE

#:43 [zapro.exe]
    FilePath           : C:\Program Files\Zone Labs\ZoneAlarm\
    ProcessID          : 2784
    ThreadCreationTime : 9-2-2005 4:34:03 AM
    BasePriority       : Normal
    FileVersion        : 4.0.123.012
    ProductVersion     : 4.0.123.012
    ProductName        : ZoneAlarm Pro
    CompanyName        : Zone Labs Inc.
    FileDescription    : ZoneAlarm Pro
    InternalName       : zapro
    LegalCopyright     : Copyright © 1998-2003, Zone Labs Inc.
    OriginalFilename   : zapro.exe

#:44 [iexplore.exe]
    FilePath           : C:\Program Files\Internet Explorer\
    ProcessID          : 2916
    ThreadCreationTime : 9-2-2005 4:34:09 AM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : IEXPLORE.EXE

#:45 [wuauclt.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 3080
    ThreadCreationTime : 9-2-2005 4:34:18 AM
    BasePriority       : Normal
    FileVersion        : 5.8.0.2469 built by: lab01_n(wmbla)
    ProductVersion     : 5.8.0.2469
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Automatic Updates
    InternalName       : wuauclt.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : wuauclt.exe

#:46 [ad-aware.exe]
    FilePath           : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
    ProcessID          : 3416
    ThreadCreationTime : 9-2-2005 4:35:28 AM
    BasePriority       : Normal
    FileVersion        : 6.2.0.236
    ProductVersion     : SE 106
    ProductName        : Lavasoft Ad-Aware SE
    CompanyName        : Lavasoft Sweden
    FileDescription    : Ad-Aware SE Core application
    InternalName       : Ad-Aware.exe
    LegalCopyright     : Copyright © Lavasoft AB Sweden
    OriginalFilename   : Ad-Aware.exe
    Comments           : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0



Deep scanning and examining files...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0

Disk Scan Result for C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0

Disk Scan Result for C:\DOCUME~1\Paul\LOCALS~1\Temp\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 0



 MRU List Object Recognized!
    Location:          : C:\Documents and Settings\Paul\recent
    Description        : list of recently opened documents


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru
    Description        : list of recent search terms used with the search assistant


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
    Description        : list of recent programs opened


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
    Description        : list of recently saved files, stored according to file extension


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs
    Description        : list of recent documents opened



Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 5

12:40:23 AM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:02:53.703
Objects scanned:87447
Objects identified:0
Objects ignored:0
New critical objects:0




also HJT



Logfile of HijackThis v1.99.1
Scan saved at 12:47:05 AM, on 9/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




I think/hope all is ok now...


thanks again, guestolo....

14
Tech Clinic / malware aurora, trojans, etc
« on: September 01, 2005, 11:01:13 PM »
oops!

I just updated and ran Adaware and there were 46 critical objects...Things like VX2  and browser hijack attempts listed.

I checked off the items and they were deleted by adaware...

here is the 9-1-05 Quaratine log from Ad-Aware:

ArchiveData(auto-quarantine- 2005-09-01 23-52-42.bckp)
Referencefile : SE1R64 31.08.2005
======================================================

MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\Paul\Application Data\microsoft\office\recent\directions.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\Paul\recent\directions.lnk
obj[2]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c1
obj[3]=MRU FileReference : C:\Documents and Settings\Paul\recent\filefindQ.txt.lnk
obj[4]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[5]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\internet explorer download directory
obj[6]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\microsoft management console\recent file list
obj[7]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru\5603
obj[8]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru\5604
obj[9]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[10]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.doc
obj[11]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj[12]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.pdf
obj[13]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
obj[14]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.zip
obj[15]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[16]=MRU FileReference : C:\Documents and Settings\Paul\recent\Scan report_20050831.txt.lnk
obj[17]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\runmru
obj[18]=MRU FileReference : C:\Documents and Settings\Paul\recent\software stuff.lnk
obj[19]=MRU FileReference : C:\Documents and Settings\Paul\recent\Spywarefrom the techguide.doc.lnk
obj[20]=MRU FileReference : C:\Documents and Settings\Paul\recent\WinPFind.lnk
obj[21]=MRU FileReference : C:\Documents and Settings\Paul\recent\WinPFind.Txt.lnk
obj[22]=MRU FileReference : C:\Documents and Settings\Paul\recent\~$ywarefrom the techguide.doc.lnk

VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[13]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3n5trMsgSDisp"
obj[14]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky1S"
obj[15]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky2S"
obj[16]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky3S"
obj[17]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky4S"
obj[18]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC1o3d5eOfSFinalAd"
obj[19]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3i5m7eOfSFinalAd"
obj[20]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUD3s5tSSEnd"
obj[21]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AU3N5a7tionSCode"
obj[22]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUP3D5om"
obj[23]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSCheckSIn"
obj[24]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSMots"
obj[25]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUM3o5deSSync"
obj[26]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSCab"
obj[27]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSEx"
obj[28]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSLstest"
obj[29]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3n5tFyl"
obj[30]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3a5stMotsSDay"
obj[31]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3a5stSSChckin"
obj[32]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUB3D5om"
obj[33]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUE3v5nt"
obj[34]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSBath"
obj[35]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSysSInf"
obj[36]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3n5Title"
obj[37]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3u5rrentSMode"
obj[38]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3g5noreS"
obj[39]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUS3t5atusOfSInst"
obj[54]=Regkey : system\controlset001\control\print\monitors\zepmon
obj[55]=Regkey : system\currentcontrolset\control\print\monitors\zepmon
obj[56]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[57]=RegData : software\microsoft\windows nt\currentversion\winlogon "Shell"

POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[40]=Regkey : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1
obj[41]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "DisplayName"
obj[42]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "URLInfoAbout"
obj[43]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Publisher"
obj[44]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "HelpLink"
obj[45]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Contact"

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[46]=IECache Entry : Cookie:[email protected]/cgi-bin
obj[47]=IECache Entry : Cookie:[email protected]/
obj[48]=IECache Entry : Cookie:[email protected]/
obj[49]=IECache Entry : Cookie:[email protected]/
obj[50]=IECache Entry : Cookie:[email protected]/
obj[51]=IECache Entry : Cookie:[email protected]/
obj[52]=IECache Entry : Cookie:[email protected]/
obj[53]=IECache Entry : Cookie:[email protected]/

15
Tech Clinic / malware aurora, trojans, etc
« on: September 01, 2005, 09:59:55 PM »
guestolo:

I found and deleted this file:
C:\WINDOWS\SYSTEM32\InstallerV4.exe
but the other one was not there.  

I did the system restore disable and reboot and reenabled sys restore.

I will download and use the spyware products you suggest.

In passing, I found out the problem with the inability to boot up in safe mode.  Basically, it arises from an older version of Nero 6.0 and its component InCD...After updating this software to a recent version, the safemode boot problem goes away...This is a known issue:

"IRQ_NOT_LESS_OR_EQUAL STOP: 0x0000000A can be caused by Nero InCD 4300. A side effect is that, very strangely, you cannot boot in safe mode, but you can boot in normal mode. You can try to update InCD to the latest version. There are conflicting reports about version 4303. If you keep having the problem, uninstall the program altogether."

Finally, I want to thank you for the excellent and concientious job you are doing here on this site.  Very remarkable that you can walk us through these minefields without a complete disaster taking place.

Thank you.  I think all is well.

Paul

16
Tech Clinic / malware aurora, trojans, etc
« on: September 01, 2005, 01:28:39 AM »
WinPfind


WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     9/1/2005 12:19:04 AM      S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     9/1/2005 12:21:48 AM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     9/1/2005 12:24:36 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     9/1/2005 12:19:16 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     9/1/2005 12:29:12 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     9/1/2005 1:19:54 AM      H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     9/1/2005 12:24:24 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     9/1/2005 12:19:06 AM     H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = explorer.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/1/2005 1:23:06 AM



Kaspersky  scan



-------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Thursday, September 01, 2005 02:27:06
 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.67.0
 Kaspersky Anti-Virus database last update:  1/09/2005
 Kaspersky Anti-Virus database records: 146498
-------------------------------------------------------------------------------

Scan Settings:
   Scan using the following antivirus database: extended
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - My Computer:
   A:\
   C:\
   D:\
   E:\

Scan Statistics:
   Total number of scanned objects: 102613
   Number of viruses found: 10
   Number of infected objects: 31
   Number of suspicious objects: 0
   Duration of the scan process: 3063 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05080000.VBN   Infected: not-a-virus:AdWare.Sahat.w
C:\Documents and Settings\All Users\Desktop\nailfix\Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix\Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix.exe/l2mfix/Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Program Files\Microsoft AntiSpyware\Quarantine\4163916C-5E58-4E33-8640-7613C1\FC443902-C7F7-4CCC-BFA6-41B0CF   Infected: Trojan-Downloader.Win32.Qoologic.aa
C:\Program Files\Microsoft AntiSpyware\Quarantine\83A9F9FA-6FBD-43BB-A617-7624E8\B7ED67A5-5E29-4371-8AC3-4F68F4   Infected: Trojan-Downloader.Win32.Qoologic.aa
C:\Program Files\Microsoft AntiSpyware\Quarantine\D17E3654-C1BC-4F33-AE54-CE16EF\7DC7882A-F408-4B0C-AE14-B62B96   Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000005.dll   Infected: Trojan.Win32.Agent.db
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000010.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000011.exe   Infected: Trojan.Win32.Agent.gp
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000012.exe   Infected: not-a-virus:AdWareBetterInternet.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000013.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000014.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000017.exe   Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000021.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000035.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000036.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000037.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000042.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000054.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000055.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000056.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000057.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000068.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000069.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000070.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000071.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000072.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\WINDOWS\SYSTEM32\InstallerV4.exe/data0001   Infected: not-a-virus:AdWare.SafeSurfing.o
C:\WINDOWS\SYSTEM32\InstallerV4.exe   Infected: not-a-virus:AdWare.SafeSurfing.o

Scan process completed.

17
Tech Clinic / malware aurora, trojans, etc
« on: August 31, 2005, 11:22:53 PM »
here it is:

Logfile of HijackThis v1.99.1
Scan saved at 12:19:53 AM, on 9/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe



FindQ



»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...
 
 
»»»»» 2K XP 9X and ME Misc check's...
 
 
»»»»» 9X and ME check's...

18
Tech Clinic / malware aurora, trojans, etc
« on: August 31, 2005, 10:00:33 PM »
When rebooting both times a windows info box opened and stated that "windows cannot find C:\windows\nail.exe"

when I ran the HJT file I could not check off the two entries:

O4 - Global Startup: nitc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


because they were not there.


I tried to run Panda but nothing seemed to happen and there was no file to save, it was not clear if it was running a scan or not...

It is hihgly likely that, in the last round,  I performed the tasks in the order that you prescribed

here is the recent HJT file


Logfile of HijackThis v1.99.1
Scan saved at 10:50:21 PM, on 8/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




here is the Find Q result


»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...
 
C:\WINDOWS\SYSTEM32\LSDDSL.EXE
C:\WINDOWS\SYSTEM32\BMOQDBC.EXE
C:\WINDOWS\SYSTEM32\JABKE.DLL
C:\WINDOWS\SYSTEM32\SSGDFSD.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\NITC.EXE
 
»»»»» 2K XP 9X and ME Misc check's...
 
C:\WINDOWS\SYSTEM32\PKVYW.DAT
 
»»»»» 9X and ME check's...

19
Tech Clinic / malware aurora, trojans, etc
« on: August 31, 2005, 09:58:19 AM »
There is still trouble in this computer because the bad guys are continuing to ask for access to the internet via the ZoneAlarmPro, I am denying this access.  Some reoccuring names are thnall1a.exe,  aurora still gives it a try everyso often, and a new one aurareco.exe is also trying once and a while (all are seeking permission to connect to the internet through ZAP...)

During the step to delet ateiua.exe, I was not fast enough in the delete step and the file name dissolved before my eyes and changed to anther file name.  So , I went back and ran APT again finding the new file and repeated the proces of Kill3 and then got to the delete step before it morphed again, at least I think so....because the name was changing the aphabetized ordering of the files in the system32 folder was also starting to hop around, so it was hard to keep track of what was happening...

Anyway...here is where we stand currently...

Here is HJT file:

Logfile of HijackThis v1.99.1
Scan saved at 10:47:31 AM, on 8/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nitc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\lvefze.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: nitc.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


Here is the WinPfind:



WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
abetterinternet.com  9/15/2001 3:33:08 AM        3506       C:\WINDOWS\abiuninst.htm
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 6/18/2004 1:18:18 AM        52736      C:\WINDOWS\Nail.exe
UPX!                 12/12/2001 12:01:24 AM      6656       C:\WINDOWS\svcproc.exe
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
UPX!                 11/16/2001 7:59:42 PM       79360      C:\WINDOWS\zbzszynli.exe

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 11/8/2002 5:56:18 PM        28160      C:\WINDOWS\SYSTEM32\DrPMon.dll
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
UPX!                 2/20/2004 6:49:02 PM        77312      C:\WINDOWS\SYSTEM32\Ia1cm.dll
69.59.186.63         8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
209.66.67.134        8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
web-nex              8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
winsync              8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU
UPX!                 11/20/2004 9:42:24 AM       91136      C:\WINDOWS\SYSTEM32\__delete_on_reboot__lvefze.exe
69.59.186.63         8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
209.66.67.134        8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
web-nex              8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
winsync              8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     8/31/2005 1:03:02 AM      S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     8/31/2005 10:31:30 AM    H  0          C:\WINDOWS\LastGood\INF\oem7.inf
                     8/31/2005 10:31:30 AM    H  0          C:\WINDOWS\LastGood\INF\oem7.PNF
                     8/31/2005 1:04:18 AM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     8/31/2005 3:01:06 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     8/31/2005 1:03:18 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     8/31/2005 9:03:24 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     8/31/2005 10:43:22 AM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     8/31/2005 10:31:40 AM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     8/31/2005 1:03:06 AM     H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     8/30/2005 10:01:40 PM       92160      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nitc.exe
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
   winsync   C:\WINDOWS\system32\lsddsl.exe reg_run

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = Explorer.exe C:\WINDOWS\Nail.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/31/2005 10:46:43 AM


Here is Ewido:


---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         10:19:46 AM, 8/31/2005
 + Report-Checksum:      938E8363

 + Scan result:

   [2032] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup
   [1076] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1124] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1164] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1148] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1116] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1216] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1268] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1332] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1348] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1388] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1404] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1412] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1436] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1464] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1480] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1836] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2024] C:\WINDOWS\system32\lvefze.exe -> Trojan.Agent.cp : Cleaned with backup
   [2044] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2068] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2116] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [3716] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   C:\Documents and Settings\Paul\Cookies\paul@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
   C:\WINDOWS\SYSTEM32\DrPMon.dll -> Trojan.Agent.db : Cleaned with backup
   C:\WINDOWS\SYSTEM32\lvefze.exe -> Trojan.Agent.gp : Cleaned with backup
   C:\WINDOWS\SYSTEM32\pkvyw.dat -> TrojanDownloader.Qoologic.ac : Cleaned with backup


::Report End

20
Tech Clinic / malware aurora, trojans, etc
« on: August 30, 2005, 09:55:08 PM »
here are the logs

Logfile of HijackThis v1.99.1
Scan saved at 10:40:32 PM, on 8/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ateiua.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [nvzsjwo] C:\WINDOWS\system32\ateiua.exe r
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




WindPfind




WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
abetterinternet.com  4/28/2002 9:07:34 AM        3506       C:\WINDOWS\abiuninst.htm
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 4/21/2005 4:28:22 PM        52736      C:\WINDOWS\Nail.exe
UPX!                 2/5/2003 11:10:06 AM        6656       C:\WINDOWS\svcproc.exe
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 2/24/2004 6:29:28 PM        28160      C:\WINDOWS\SYSTEM32\DrPMon.dll
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
UPX!                 2/20/2004 6:49:02 PM        77312      C:\WINDOWS\SYSTEM32\Ia1cm.dll
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     8/30/2005 10:39:00 PM     S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     8/30/2005 9:47:50 PM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     7/2/2005 4:18:16 AM       S 9445       C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB903235.cat
                     8/30/2005 10:40:06 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     8/30/2005 10:39:32 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     8/30/2005 10:40:06 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     8/30/2005 10:44:54 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     8/30/2005 10:44:54 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     8/30/2005 10:39:04 PM    H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
   nvzsjwo   C:\WINDOWS\system32\ateiua.exe r

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = Explorer.exe C:\WINDOWS\Nail.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/30/2005 10:45:35 PM

Pages: [1] 2