Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis
 |  Print Topic
Jump to first unread post. Pages: 1
Andybib
regular


Reg'd: Thu
Posts: 48
Unusual behaviour on comp.
      #391286 - Sun Apr 13 2008 12:48 AM

Hello folks,back again unfort.All running well until today, been v.careful which sites visiting ,however some crap seems to have slipped through!Got Advent 7082 lappy,1.2 g ram,40g H.D.Windows xp sp2.Using N.I.S 2008,Spywareguard+Blaster,Adaware,Spybot+reg.clean up with CC,so was shocked to see system behaving abnormally,Ive posted a HT log hope its a help.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:30:02, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6092 bytes


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: Andybib]
      #391308 - Sun Apr 13 2008 10:00 AM

forgot to add,cpu seems to be flat out, even when only desktop,Explorer.exe>100%,this cant be good?

Post Extras: Print Post   Remind Me!   Notify Moderator  
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 28633
Loc: belfast
Re: Unusual behaviour on comp. [Re: Andybib]
      #391365 - Sun Apr 13 2008 06:44 PM

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: bricat]
      #391372 - Sun Apr 13 2008 07:35 PM

Heres the logs as requested,had a result,
VundoFix V7.0.3

Scan started at 18:53:35 13/04/2008

Listing files found while scanning....

C:\Program Files\PowerISO\PWRISOSH.DLL

Beginning removal...

Attempting to delete C:\Program Files\PowerISO\PWRISOSH.DLL
C:\Program Files\PowerISO\PWRISOSH.DLL Has been deleted!

Performing Repairs to the registry.
Done!
;now the HT log,Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:08:33, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {A70BAFD9-D851-4918-879F-DB2B103D3E88} - C:\WINDOWS\system32\ddcAQgee.dll (file missing)
O2 - BHO: (no name) - {A98D0065-7326-41B5-B8D9-C5B692CDB82F} - C:\WINDOWS\system32\cbXRLcAq.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: cbXRLcAq - C:\WINDOWS\SYSTEM32\cbXRLcAq.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 7110 bytes
Seems to be a maked improvement already,however im now getting BHOwarnings for;c:\WINDOWS\system32\jkkjcyXN.dll,C:\WINDOWS\system32\cbXRLcAq.dll,C:\WINDOWS\System32\ddcAQgee.dll all with n/a for prog.id,plus a helper object for Spybot\sdhelper.dll.Isuspect the first set may be bad news as for Spybot,you de man!


Post Extras: Print Post   Remind Me!   Notify Moderator  
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 28633
Loc: belfast
Re: Unusual behaviour on comp. [Re: Andybib]
      #391405 - Mon Apr 14 2008 08:44 AM

Rerun HJT,and put a checkmark beside these :-

O2 - BHO: (no name) - {A70BAFD9-D851-4918-879F-DB2B103D3E88} - C:\WINDOWS\system32\ddcAQgee.dll (file missing)
O2 - BHO: (no name) - {A98D0065-7326-41B5-B8D9-C5B692CDB82F} - C:\WINDOWS\system32\cbXRLcAq.dll
O20 - Winlogon Notify: cbXRLcAq - C:\WINDOWS\SYSTEM32\cbXRLcAq.dll

now close all windows and browsers and click FIX CHECKED

Then boot up in SAFE MODE

Then navigate to and delete these files\folders in BOLD

C:\WINDOWS\SYSTEM32\cbXRLcAq.dll



then reboot and post a fresh Hijackthis log.

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: bricat]
      #391476 - Mon Apr 14 2008 07:33 PM

Back again,tried to remove three items listed from HT log,however,none were listed!Booted in SAFE mode,naved to file you said ,but i was unable to delete as said another program or user using said file,strange.Idid notice another file in Sys 32,CbxpjGAq.dll???Anyway,heres a new HT log,hope you can help!Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:30:09, on 14/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /M "Stylus DX4200" /EF "HKCU"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6326 bytes


Post Extras: Print Post   Remind Me!   Notify Moderator  
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 28633
Loc: belfast
Re: Unusual behaviour on comp. [Re: Andybib]
      #391515 - Mon Apr 14 2008 10:40 PM

we're going to have to look a bit deeper.

Please download ComboFix from either of these two locations

BleepingComputerComboFix
geeks to go combofix

And save it to your DESKTOP.

* Double click combofix.exe & follow the prompts.
* When finished, it shall produce a log for you. Post that log in your next reply

Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Post back with the log from ComboFix and a new HJT log please.

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: bricat]
      #391534 - Tue Apr 15 2008 05:32 AM

heres the logs as requestedComboFix 08-04-13.3 - Andy 2008-04-15 0:34:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.615 [GMT 1:00]
Running from: C:\Documents and Settings\Andy\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Andy\Application Data\inst.exe
C:\WINDOWS\system32\cbXPjGAq.dll
C:\WINDOWS\system32\cbXRLcAq.dll
C:\WINDOWS\system32\eegQAcdd.ini
C:\WINDOWS\system32\eegQAcdd.ini2
C:\WINDOWS\system32\iifcCrqr.dll
C:\WINDOWS\system32\khfEXqPG.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\NXycJkkj.ini
C:\WINDOWS\system32\NXycJkkj.ini2
C:\WINDOWS\system32\urqPjgdc.dll
C:\WINDOWS\system32\wvUoPfcb.dll
C:\WINDOWS\system32\xxyvuusq.dll
C:\WINDOWS\system32\yaywvsTN.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))
.

2008-04-13 19:11 . 272,896 C:\WINDOWS\system32\jkkJcyXN.dll_old
2008-04-13 18:53 . 2008-04-13 19:03 <DIR> d-------- C:\VundoFix Backups
2008-04-13 02:36 . 2008-04-14 20:43 153 --a------ C:\WINDOWS\wininit.ini
2008-04-13 01:29 . 2008-04-13 01:29 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 00:29 . 2008-04-13 00:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-11 18:59 . 2008-04-11 18:59 <DIR> d-------- C:\Setup
2008-04-11 18:54 . 2008-04-13 23:12 <DIR> d-------- C:\Program Files\AutoCAD Civil 3D 2008
2008-04-11 18:54 . 2008-04-11 18:54 <DIR> d-------- C:\Civil 3D Projects
2008-04-11 17:33 . 2008-04-13 19:03 <DIR> d-------- C:\Program Files\PowerISO
2008-04-10 13:44 . 2008-04-10 13:44 <DIR> d-------- C:\WINDOWS\WinRAR
2008-04-06 18:49 . 2008-04-06 18:53 <DIR> d-------- C:\Program Files\AutoCAD 2009
2008-04-06 18:47 . 2008-04-11 19:02 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-04-06 18:36 . 2008-04-11 19:02 <DIR> d-------- C:\Program Files\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-04-06 16:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-04-06 16:00 . 2008-04-06 16:00 <DIR> d-------- C:\Program Files\MSBuild
2008-04-06 15:58 . 2008-04-06 15:58 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-04-06 15:57 . 2008-04-06 15:57 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-04-06 15:57 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-04-06 13:35 . 2008-04-10 13:47 <DIR> d-------- C:\Program Files\MagicISO
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\WINDOWS\Performance
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-04-04 19:29 . 2008-04-04 19:29 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-04-02 20:58 . 2008-04-02 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\dvdcss
2008-03-30 14:50 . <DIR> C:\Documents and Settings\Andy\Application Data\NeroDigitalT
2008-03-29 20:58 . 2008-03-29 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\UseNeXT
2008-03-29 20:09 . 2008-03-29 20:09 <DIR> d-------- C:\Program Files\Softgogo
2008-03-29 17:58 . 2008-02-18 17:21 402,728 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-03-29 12:39 . 2008-03-29 12:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\vlc
2008-03-29 06:38 . 2008-03-29 06:38 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-29 01:37 . 2008-03-30 23:59 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
2008-03-28 18:50 . 2008-03-28 19:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-03-26 21:39 . 2008-04-12 17:58 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-26 21:37 . 2008-03-26 21:37 2,525 --a------ C:\WINDOWS\system32\NMMediaServer.cfg
2008-03-26 19:24 . 2008-03-26 19:24 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-03-26 19:21 . 2008-03-26 19:21 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Program Files\Nero
2008-03-26 19:17 . 2008-03-26 19:19 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-24 22:48 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-03-24 22:48 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-03-24 22:48 . 2006-05-11 20:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-03-24 22:48 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-03-24 22:48 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-03-24 22:48 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-03-24 22:48 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-03-24 18:24 . 2002-12-16 19:09 30,970 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys
2008-03-24 18:24 . 2002-12-11 12:48 27,235 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys
2008-03-24 18:13 . 2008-03-24 18:13 0 --a------ C:\Documents and Settings\Andy\Application Data\wklnhst.dat
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\ODM
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\directx
2008-03-24 17:53 . 2003-02-27 18:14 226,688 --a------ C:\WINDOWS\system32\drivers\cccp106.sys
2008-03-24 17:53 . 2003-03-08 17:02 192,512 --a------ C:\WINDOWS\select.exe
2008-03-24 17:53 . 2003-02-18 15:48 61,440 --a------ C:\WINDOWS\system32\dcccp106.dll
2008-03-24 17:53 . 2003-02-18 15:48 45,056 --a------ C:\WINDOWS\system32\vcccp106.dll
2008-03-24 17:53 . 2002-11-13 16:54 36,864 --a------ C:\WINDOWS\CleanDev.exe
2008-03-24 17:53 . 2003-02-18 15:48 28,672 --a------ C:\WINDOWS\system32\dcccp106.ax
2008-03-24 17:53 . 2003-02-18 15:48 15,542 --a------ C:\WINDOWS\cccp106.ini
2008-03-24 17:53 . 2003-02-18 15:48 13,023 --a------ C:\WINDOWS\cccp106.src
2008-03-24 17:53 . 2003-03-14 21:45 320 --a------ C:\WINDOWS\DC2110a.ini
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll
2008-03-24 16:05 . 2008-03-24 16:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-03-24 11:22 . 2008-03-24 11:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-03-24 11:22 . 2008-03-24 11:22 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-03-24 11:22 . 2008-02-27 14:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-03-24 10:49 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-24 03:12 . 2008-03-24 03:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Motive
2008-03-24 03:10 . 2008-03-24 03:10 <DIR> d-------- C:\WINDOWS\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\btbb_wcm
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-03-24 03:08 . 2008-03-24 03:08 <DIR> d-------- C:\Program Files\Motive
2008-03-24 03:08 . 2008-03-24 03:10 <DIR> d-------- C:\Program Files\BT Broadband Desktop Help
2008-03-24 00:39 . 2008-03-24 00:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\TuneUp Software
2008-03-24 00:38 . 2008-04-12 18:31 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-03-23 20:31 . 2008-03-23 20:31 22 --a------ C:\WINDOWS\system32\ati64hlp.stb
2008-03-23 19:47 . 2008-04-13 12:22 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 19:46 . 2008-04-12 18:33 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-03-23 19:46 . 2005-08-25 19:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-03-23 19:29 . 2008-04-13 01:04 <DIR> d-------- C:\Program Files\SpywareGuard
2008-03-23 16:11 . 2008-03-23 16:11 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\AVSMedia
2008-03-23 16:11 . 2008-03-23 16:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-03-23 16:10 . 2008-03-23 16:10 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-03-23 16:09 . 2008-03-23 16:09 <DIR> d-------- C:\Program Files\AVSMedia
2008-03-23 13:41 . 2008-04-06 18:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-21 17:22 . 2008-04-13 02:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-21 17:12 . 2008-04-06 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-21 15:47 . 2008-03-21 15:47 <DIR> d-------- C:\Program Files\CCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-04-14 22:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-13 17:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-10 19:35 --------- d-----w C:\Documents and Settings\Andy\Application Data\ImgBurn
2008-03-30 13:50 --------- d-----w C:\Documents and Settings\Andy\Application Data\NeroDigital™
2008-03-24 22:28 --------- d-----w C:\Documents and Settings\Andy\Application Data\DVD Flick
2008-03-24 17:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-17 18:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-14 06:04 46,652 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys
2008-03-08 11:55 --------- d-----w C:\Program Files\Xvid
2008-03-07 20:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-03-07 20:05 --------- d-----w C:\Documents and Settings\Andy\Application Data\PC Suite
2008-03-07 20:04 --------- d-----w C:\Documents and Settings\Andy\Application Data\Nokia
2008-03-07 20:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-07 20:02 --------- d-----w C:\Program Files\DIFX
2008-03-07 20:01 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-03-07 20:01 --------- d-----w C:\Program Files\Nokia
2008-03-07 20:01 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-03-07 20:01 --------- d-----w C:\Program Files\Common Files\Nokia
2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-03-06 14:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-06 14:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-06 14:20 --------- d-----w C:\Documents and Settings\Andy\Application Data\AdobeUM
2008-03-06 14:18 --------- d-----w C:\Program Files\DVD Flick
2008-03-06 12:24 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-06 11:50 --------- d-----w C:\Program Files\Kontiki
2008-03-06 11:49 --------- d-----w C:\Program Files\Channel4
2008-03-06 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Channel4
2008-03-06 11:17 --------- d-----w C:\Program Files\Norton Internet Security
2008-03-06 11:11 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-06 11:11 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-06 11:11 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-06 11:11 --------- d-----w C:\Program Files\Symantec
2008-03-06 04:37 --------- d-----w C:\Program Files\Synaptics
2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek Semiconductor Corp
2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek AC97
2008-03-06 04:37 --------- d-----w C:\Program Files\RALINK
2008-03-06 04:36 --------- d-----w C:\Program Files\NewTech Infosystems
2008-03-06 04:36 --------- d-----w C:\Program Files\Microsoft Works
2008-03-06 04:36 --------- d-----w C:\Program Files\InterVideo
2008-03-06 04:36 --------- d-----w C:\Program Files\AvRack
2008-03-06 04:36 --------- d-----w C:\Program Files\ATI Technologies
2008-03-06 04:36 --------- d-----w C:\Program Files\AMD
2008-03-06 03:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-06 02:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-03-06 01:05 --------- d-----w C:\Program Files\Yahoo!
2008-03-06 01:05 --------- d-----w C:\Documents and Settings\Andy\Application Data\Yahoo!
2008-03-06 00:48 --------- d-----w C:\Documents and Settings\Andy\Application Data\Symantec
2008-03-06 00:46 --------- d-----w C:\Program Files\Windows Sidebar
2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2008-02-19 15:44 96,432 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-02-19 15:44 41,008 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-02-19 15:44 38,576 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-02-19 15:44 37,424 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-02-19 15:44 31,408 ----a-w C:\WINDOWS\system32\drivers\SymIM.sys
2008-02-19 15:44 22,320 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-02-19 15:44 188,464 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-02-19 15:44 13,616 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-02-19 15:44 13,021 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-02-19 15:44 1,612 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-02-18 16:21 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
2008-02-18 16:21 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
2003-08-27 21:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CFCC23E-F175-47F6-B8D8-FD96A0EC8B51}]
C:\WINDOWS\system32\jkkJcyXN.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-25 04:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-06 02:11 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A70BAFD9-D851-4918-879F-DB2B103D3E88}]
C:\WINDOWS\system32\ddcAQgee.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-25 04:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-25 04:51 316784]

[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.exe" [2005-03-07 20:00 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-15 00:50 233472]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]

C:\Documents and Settings\Andy\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXRLcAq]
cbXRLcAq.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"btbb_McciTrayApp"=C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
"CardReaderReset"=C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe
"SM1BG"=C:\WINDOWS\SM1BG.EXE
"EPSON Stylus DX4200 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /O6 "USB001" /M "Stylus DX4200"
"4oD"="C:\Program Files\Kontiki\KHost.exe" -all
"btbb_wcm_McciTrayApp"=C:\Program Files\btbb_wcm\McciTrayApp.exe
"SoundMan"=SOUNDMAN.EXE
"YBrowser"=C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 13:00]
R3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-02-27 18:14]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 22:32]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-24 11:22]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 00:03:49 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-04-13 19:49:35 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Andy.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 01:04:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\SoftwareDistribution\Download\991099a35378d98f420ab4028323ec84\update\update.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-04-15 1:08:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-15 00:08:28
ComboFix2.txt 2008-03-21 02:21:11

Pre-Run: 15,628,410,880 bytes free
Post-Run: 15,528,751,104 bytes free
.
2008-03-25 05:36:23 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:19:01, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CFCC23E-F175-47F6-B8D8-FD96A0EC8B51} - C:\WINDOWS\system32\jkkJcyXN.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {A70BAFD9-D851-4918-879F-DB2B103D3E88} - C:\WINDOWS\system32\ddcAQgee.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /M "Stylus DX4200" /EF "HKCU"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: cbXRLcAq - cbXRLcAq.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8096 bytes


Post Extras: Print Post   Remind Me!   Notify Moderator  
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 28633
Loc: belfast
Re: Unusual behaviour on comp. [Re: Andybib]
      #391544 - Tue Apr 15 2008 08:44 AM

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Open *notepad* and copy/paste the text in the quotebox below into it:

Quote:



Killall::

File::
C:\WINDOWS\system32\jkkJcyXN.dll_old
C:\WINDOWS\system32\ddcAQgee.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\BrowserHelperObjects\{3CFCC23E-F175-47F6-B8D8-FD96A0EC8B51}]
[-HKEY_LOCAL_MACHINE\~\BrowserHelperObjects\{A70BAFD9-D851-4918-879F-DB2B103D3E88}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\cbXRLcAq]






Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.




Referring to the picture above, drag CFScript.txt into ComboFix.exe

Restart your computer.

When finished, it shall produce a log for you at C:\ComboFix.txt

Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please and
let me know how it is running.


*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall*

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: bricat]
      #391599 - Tue Apr 15 2008 06:54 PM

Hi there Bricat,when exactly do i run CF,before restart cmp. or after?Cheers for assistance.Andyb.

Post Extras: Print Post   Remind Me!   Notify Moderator  
bricatModerator
HijackThis Helper


Reg'd: Wed
Posts: 28633
Loc: belfast
Re: Unusual behaviour on comp. [Re: Andybib]
      #391629 - Tue Apr 15 2008 11:07 PM

you don't run CF it will run itself once you have dragged and dropped the text file into it then restarted the computer.

--------------------
MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.

You don't stop laughing when you get old, you get old when you stop laughing!


Post Extras: Print Post   Remind Me!   Notify Moderator  
Andybib
regular


Reg'd: Thu
Posts: 48
Re: Unusual behaviour on comp. [Re: bricat]
      #391644 - Wed Apr 16 2008 12:46 AM

Heres CF + HT logs,as requested,certainly seems more responsive,no hanging,with definate drop off in CPU usage,although time will tell;ComboFix 08-04-13.3 - Andy 2008-04-16 0:24:58.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.646 [GMT 1:00]
Running from: C:\Documents and Settings\Andy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andy\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\ddcAQgee.dll
C:\WINDOWS\system32\jkkJcyXN.dll_old
.

((((((((((((((((((((((((( Files Created from 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))
.

2008-04-15 05:58 . 2008-04-15 05:58 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-15 05:57 . 2008-04-15 05:59 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-13 18:53 . 2008-04-13 19:03 <DIR> d-------- C:\VundoFix Backups
2008-04-13 02:36 . 2008-04-14 20:43 153 --a------ C:\WINDOWS\wininit.ini
2008-04-13 01:29 . 2008-04-13 01:29 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 00:29 . 2008-04-13 00:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-11 18:59 . 2008-04-11 18:59 <DIR> d-------- C:\Setup
2008-04-11 18:54 . 2008-04-13 23:12 <DIR> d-------- C:\Program Files\AutoCAD Civil 3D 2008
2008-04-11 18:54 . 2008-04-11 18:54 <DIR> d-------- C:\Civil 3D Projects
2008-04-11 17:33 . 2008-04-13 19:03 <DIR> d-------- C:\Program Files\PowerISO
2008-04-10 13:44 . 2008-04-10 13:44 <DIR> d-------- C:\WINDOWS\WinRAR
2008-04-06 18:49 . 2008-04-06 18:53 <DIR> d-------- C:\Program Files\AutoCAD 2009
2008-04-06 18:47 . 2008-04-11 19:02 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-04-06 18:36 . 2008-04-11 19:02 <DIR> d-------- C:\Program Files\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Autodesk
2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-04-06 16:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-04-06 16:00 . 2008-04-06 16:00 <DIR> d-------- C:\Program Files\MSBuild
2008-04-06 15:58 . 2008-04-06 15:58 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-04-06 15:57 . 2008-04-06 15:57 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-04-06 15:57 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-04-06 13:35 . 2008-04-10 13:47 <DIR> d-------- C:\Program Files\MagicISO
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\WINDOWS\Performance
2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-04-04 19:29 . 2008-04-04 19:29 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-04-02 20:58 . 2008-04-02 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\dvdcss
2008-03-30 14:50 . <DIR> C:\Documents and Settings\Andy\Application Data\NeroDigitalT
2008-03-29 20:58 . 2008-03-29 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\UseNeXT
2008-03-29 20:09 . 2008-03-29 20:09 <DIR> d-------- C:\Program Files\Softgogo
2008-03-29 17:58 . 2008-02-18 17:21 402,728 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-03-29 12:39 . 2008-03-29 12:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\vlc
2008-03-29 06:38 . 2008-03-29 06:38 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-29 01:37 . 2008-03-30 23:59 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
2008-03-28 18:50 . 2008-03-28 19:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
2008-03-26 21:39 . 2008-04-12 17:58 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-26 21:37 . 2008-03-26 21:37 2,525 --a------ C:\WINDOWS\system32\NMMediaServer.cfg
2008-03-26 19:24 . 2008-03-26 19:24 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-03-26 19:21 . 2008-03-26 19:21 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Program Files\Nero
2008-03-26 19:17 . 2008-03-26 19:19 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-24 22:48 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-03-24 22:48 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-03-24 22:48 . 2006-05-11 20:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-03-24 22:48 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-03-24 22:48 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-03-24 22:48 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-03-24 22:48 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-03-24 18:24 . 2002-12-16 19:09 30,970 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys
2008-03-24 18:24 . 2002-12-11 12:48 27,235 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys
2008-03-24 18:13 . 2008-03-24 18:13 0 --a------ C:\Documents and Settings\Andy\Application Data\wklnhst.dat
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\ODM
2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\directx
2008-03-24 17:53 . 2003-02-27 18:14 226,688 --a------ C:\WINDOWS\system32\drivers\cccp106.sys
2008-03-24 17:53 . 2003-03-08 17:02 192,512 --a------ C:\WINDOWS\select.exe
2008-03-24 17:53 . 2003-02-18 15:48 61,440 --a------ C:\WINDOWS\system32\dcccp106.dll
2008-03-24 17:53 . 2003-02-18 15:48 45,056 --a------ C:\WINDOWS\system32\vcccp106.dll
2008-03-24 17:53 . 2002-11-13 16:54 36,864 --a------ C:\WINDOWS\CleanDev.exe
2008-03-24 17:53 . 2003-02-18 15:48 28,672 --a------ C:\WINDOWS\system32\dcccp106.ax
2008-03-24 17:53 . 2003-02-18 15:48 15,542 --a------ C:\WINDOWS\cccp106.ini
2008-03-24 17:53 . 2003-02-18 15:48 13,023 --a------ C:\WINDOWS\cccp106.src
2008-03-24 17:53 . 2003-03-14 21:45 320 --a------ C:\WINDOWS\DC2110a.ini
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll
2008-03-24 16:05 . 2008-03-24 16:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-03-24 11:22 . 2008-03-24 11:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-03-24 11:22 . 2008-03-24 11:22 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-03-24 11:22 . 2008-02-27 14:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-03-24 10:49 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-24 03:12 . 2008-03-24 03:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Motive
2008-03-24 03:10 . 2008-03-24 03:10 <DIR> d-------- C:\WINDOWS\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\btbb_wcm
2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-03-24 03:08 . 2008-03-24 03:08 <DIR> d-------- C:\Program Files\Motive
2008-03-24 03:08 . 2008-03-24 03:10 <DIR> d-------- C:\Program Files\BT Broadband Desktop Help
2008-03-24 00:39 . 2008-03-24 00:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\TuneUp Software
2008-03-24 00:38 . 2008-04-12 18:31 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-03-23 20:31 . 2008-03-23 20:31 22 --a------ C:\WINDOWS\system32\ati64hlp.stb
2008-03-23 19:47 . 2008-04-13 12:22 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 19:46 . 2008-04-12 18:33 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-03-23 19:46 . 2005-08-25 19:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-03-23 19:29 . 2008-04-16 00:23 <DIR> d-------- C:\Program Files\SpywareGuard
2008-03-23 16:11 . 2008-03-23 16:11 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\AVSMedia
2008-03-23 16:11 . 2008-03-23 16:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-03-23 16:10 . 2008-03-23 16:10 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-03-23 16:09 . 2008-03-23 16:09 <DIR> d-------- C:\Program Files\AVSMedia
2008-03-23 13:41 . 2008-04-06 18:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-21 17:22 . 2008-04-13 02:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-21 17:12 . 2008-04-06 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-04-15 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-13 17:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-10 19:35 --------- d-----w C:\Documents and Settings\Andy\Application Data\ImgBurn
2008-03-30 13:50 --------- d-----w C:\Documents and Settings\Andy\Application Data\NeroDigital™
2008-03-24 22:28 --------- d-----w C:\Documents and Settings\Andy\Application Data\DVD Flick
2008-03-24 17:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-17 18:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-14 06:04 46,652 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys
2008-03-08 11:55 --------- d-----w C:\Program Files\Xvid
2008-03-07 20:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-03-07 20:05 --------- d-----w C:\Documents and Settings\Andy\Application Data\PC Suite
2008-03-07 20:04 --------- d-----w C:\Documents and Settings\Andy\Application Data\Nokia
2008-03-07 20:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-07 20:02 --------- d-----w C:\Program Files\DIFX
2008-03-07 20:01 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-03-07 20:01 --------- d-----w C:\Program Files\Nokia
2008-03-07 20:01 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-03-07 20:01 --------- d-----w C:\Program Files\Common Files\Nokia
2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-03-06 14:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-06 14:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-06 14:20 --------- d-----w C:\Documents and Settings\Andy\Application Data\AdobeUM
2008-03-06 14:18 --------- d-----w C:\Program Files\DVD Flick
2008-03-06 12:24 --------- d-----w C:\Program Files\W