Hi first time here and just thought I'd get my Hijackthis log checked been awhile since I did some major house cleaning on the computer and thought it would be best to get an expert to look at it after doing the scans and such.
I just found CCleaner and it is most excellent.
Thanks alot for your time.
Logfile of HijackThis v1.99.1
Scan saved at 7:58:42 PM, on 11/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\user\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Steam] "c:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {7B41B7AC-3496-4C13-A70F-DE6B60A6A8A8} (MGAME manager Class) - http://www.legendofa...anagerv1001.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
My Hijackthis log
Started by Lans, Nov 17 2006 02:07 AM
5 replies to this topic
#1 OFFLINE
Posted 17 November 2006 - 02:07 AM
#2 OFFLINE
Posted 17 November 2006 - 02:28 AM
Hi Lans , Welcome to the Forum
Your log is fine but if you have the time could you run an online scan and Combofix so we can be sure there isnt any problems that are not showing in the HJT log,
Run Panda Activescan from Here.
Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.
Next download Combofix and save it to your desktop.
Double click combofix.exe & follow the prompts.
When it's finished, it will produce a log of what it found which can be post back
Please then post back the Pandascan report and the Combofix Report and we can take it from there.
Regards
Andy
Your log is fine but if you have the time could you run an online scan and Combofix so we can be sure there isnt any problems that are not showing in the HJT log,
Run Panda Activescan from Here.
Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.
Next download Combofix and save it to your desktop.
Double click combofix.exe & follow the prompts.
When it's finished, it will produce a log of what it found which can be post back
Please then post back the Pandascan report and the Combofix Report and we can take it from there.
Regards
Andy
#3 OFFLINE
Posted 17 November 2006 - 06:31 AM
Thank for the answer.
Panda Scan, didn't do anything to it just figured I would wait for you say.
Incident Status Location
Adware:adware/securityerror Not disinfected C:\Documents and Settings\user\Favorites\Antivirus Test Online.url
ComboFix
user - 06-11-17 0:25:17.23 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\user\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))
2006-11-16 19:31 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2006-11-03 17:30 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2006-11-03 17:25 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll
2006-11-03 17:25 33,408 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys
2006-11-03 17:25 32,256 -ra------ C:\WINDOWS\system32\nvconrm.dll
2006-11-03 17:25 261,504 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys
2006-11-03 17:25 208,256 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys
2006-11-03 17:25 200,192 -ra------ C:\WINDOWS\system32\fdco1.dll
2006-11-03 17:25 176,128 --a------ C:\WINDOWS\system32\nvunrm.exe
2006-11-03 17:25 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys
2006-11-03 12:49 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2006-11-03 12:49 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2006-10-27 15:09 6,049,280 --------- C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 --------- C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-10-22 12:22 888,832 --a------ C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86,016 --a------ C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81,920 --a------ C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794,624 --a------ C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7,700,480 --a------ C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581,632 --a------ C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5,644,288 --a------ C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5,619,712 --a------ C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5,255,168 --a------ C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466,944 --a------ C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458,752 --a------ C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 45,056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442,368 --a------ C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425,984 --a------ C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 35,840 --a------ C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35,840 --a------ C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 311,296 --a------ C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3,203,072 --a------ C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 3,047,424 --a------ C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 286,720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 229,376 --a------ C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 212,992 --a------ C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 2,973,696 --a------ C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 2,924,544 --a------ C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 2,859,008 --a------ C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 188,416 --a------ C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 159,810 --a------ C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147,456 --a------ C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1,732,608 --a------ C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 1,662,976 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 1,622,016 --a------ C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 1,470,464 --a------ C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1,339,392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1,236,992 --a------ C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 1,019,904 --a------ C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1,011,712 --a------ C:\WINDOWS\system32\nvcpluir.dll
2006-10-17 13:05 206,336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 --------- C:\WINDOWS\system32\ieapfltr.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-17 00:17 -------- d-------- C:\Program Files\WinRAR
2006-11-17 00:17 -------- d-------- C:\Program Files\Opera
2006-11-17 00:16 -------- d-------- C:\Program Files\Internet Explorer
2006-11-16 23:39 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-16 19:42 -------- d-------- C:\Program Files\SpywareBlaster
2006-11-16 19:25 -------- d-------- C:\Program Files\RegCleaner
2006-11-16 19:21 -------- d-------- C:\Program Files\NT Registry Optimizer
2006-11-16 19:14 -------- d-------- C:\Program Files\CCleaner
2006-11-16 18:29 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-16 18:26 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-10 21:31 -------- d-------- C:\Documents and Settings\user\Application Data\Xfire
2006-11-04 02:11 -------- d-------- C:\Documents and Settings\user\Application Data\InstallShield
2006-11-04 00:41 -------- d-------- C:\Program Files\NAMCO BANDAI Games
2006-11-03 23:21 -------- d---s---- C:\Documents and Settings\user\Application Data\Microsoft
2006-11-03 17:37 -------- d-------- C:\Program Files\Common Files\System
2006-11-03 17:37 -------- d-------- C:\Program Files\Common Files
2006-10-27 15:09 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-26 22:49 -------- d-------- C:\Documents and Settings\user\Application Data\Opera
2006-10-25 11:11 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-10-22 12:22 4527488 --a------ C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 3994624 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-17 13:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 12:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-07 13:06 -------- d-------- C:\Program Files\EA Games
2006-09-28 20:48 -------- d-------- C:\Program Files\Kazaa Lite Resurrection
2006-09-27 12:37 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-06 17:43 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"c:\\games\\steam\\steam.exe\" -silent"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"ezShieldProtector for Px"="C:\\WINDOWS\\system32\\ezSP_Px.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-11-17 0:25:44.21
C:\ComboFix.txt ... 06-11-17 00:25
Once again thanks for you time.
Panda Scan, didn't do anything to it just figured I would wait for you say.
Incident Status Location
Adware:adware/securityerror Not disinfected C:\Documents and Settings\user\Favorites\Antivirus Test Online.url
ComboFix
user - 06-11-17 0:25:17.23 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\user\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))
2006-11-16 19:31 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2006-11-03 17:30 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2006-11-03 17:25 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll
2006-11-03 17:25 33,408 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys
2006-11-03 17:25 32,256 -ra------ C:\WINDOWS\system32\nvconrm.dll
2006-11-03 17:25 261,504 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys
2006-11-03 17:25 208,256 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys
2006-11-03 17:25 200,192 -ra------ C:\WINDOWS\system32\fdco1.dll
2006-11-03 17:25 176,128 --a------ C:\WINDOWS\system32\nvunrm.exe
2006-11-03 17:25 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys
2006-11-03 12:49 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2006-11-03 12:49 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2006-10-27 15:09 6,049,280 --------- C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 --------- C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-10-22 12:22 888,832 --a------ C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86,016 --a------ C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81,920 --a------ C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794,624 --a------ C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7,700,480 --a------ C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581,632 --a------ C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5,644,288 --a------ C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5,619,712 --a------ C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5,255,168 --a------ C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466,944 --a------ C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458,752 --a------ C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 45,056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442,368 --a------ C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425,984 --a------ C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 35,840 --a------ C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35,840 --a------ C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 311,296 --a------ C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3,203,072 --a------ C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 3,047,424 --a------ C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 286,720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 229,376 --a------ C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 212,992 --a------ C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 2,973,696 --a------ C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 2,924,544 --a------ C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 2,859,008 --a------ C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 188,416 --a------ C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 159,810 --a------ C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147,456 --a------ C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1,732,608 --a------ C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 1,662,976 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 1,622,016 --a------ C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 1,470,464 --a------ C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1,339,392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1,236,992 --a------ C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 1,019,904 --a------ C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1,011,712 --a------ C:\WINDOWS\system32\nvcpluir.dll
2006-10-17 13:05 206,336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12,288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 266,752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:27 380,928 --------- C:\WINDOWS\system32\ieapfltr.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-17 00:17 -------- d-------- C:\Program Files\WinRAR
2006-11-17 00:17 -------- d-------- C:\Program Files\Opera
2006-11-17 00:16 -------- d-------- C:\Program Files\Internet Explorer
2006-11-16 23:39 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-16 19:42 -------- d-------- C:\Program Files\SpywareBlaster
2006-11-16 19:25 -------- d-------- C:\Program Files\RegCleaner
2006-11-16 19:21 -------- d-------- C:\Program Files\NT Registry Optimizer
2006-11-16 19:14 -------- d-------- C:\Program Files\CCleaner
2006-11-16 18:29 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-16 18:26 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-10 21:31 -------- d-------- C:\Documents and Settings\user\Application Data\Xfire
2006-11-04 02:11 -------- d-------- C:\Documents and Settings\user\Application Data\InstallShield
2006-11-04 00:41 -------- d-------- C:\Program Files\NAMCO BANDAI Games
2006-11-03 23:21 -------- d---s---- C:\Documents and Settings\user\Application Data\Microsoft
2006-11-03 17:37 -------- d-------- C:\Program Files\Common Files\System
2006-11-03 17:37 -------- d-------- C:\Program Files\Common Files
2006-10-27 15:09 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-26 22:49 -------- d-------- C:\Documents and Settings\user\Application Data\Opera
2006-10-25 11:11 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-10-22 12:22 4527488 --a------ C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 3994624 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-17 13:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 12:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-07 13:06 -------- d-------- C:\Program Files\EA Games
2006-09-28 20:48 -------- d-------- C:\Program Files\Kazaa Lite Resurrection
2006-09-27 12:37 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-06 17:43 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"c:\\games\\steam\\steam.exe\" -silent"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"ezShieldProtector for Px"="C:\\WINDOWS\\system32\\ezSP_Px.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-11-17 0:25:44.21
C:\ComboFix.txt ... 06-11-17 00:25
Once again thanks for you time.
#4 OFFLINE
Posted 17 November 2006 - 06:57 AM
Hey Lans
The file Pandascan found is just a shortcut in your favorites folder so its easy enough to remove
Goto Start > Run > and copy and paste
"C:\Documents and Settings\user\Favorites\"
Press Enter then when the favorites folder opens delete the Antivirus Test Online.url file
The ComboFix log looks fine so it only the above file that needs to go, let us know if your having any other problems.
Cheers
Andy
The file Pandascan found is just a shortcut in your favorites folder so its easy enough to remove
Goto Start > Run > and copy and paste
"C:\Documents and Settings\user\Favorites\"
Press Enter then when the favorites folder opens delete the Antivirus Test Online.url file
The ComboFix log looks fine so it only the above file that needs to go, let us know if your having any other problems.
Cheers
Andy
#5 OFFLINE
Posted 17 November 2006 - 07:06 AM
Thanks I figured it would be an easy delete but I figured if I have an expert around may as well use it.
Well all I can say is thanks for both the quick replies and help. I guess I will head off to bed now have a good night/day.
Well all I can say is thanks for both the quick replies and help. I guess I will head off to bed now have a good night/day.
#6 OFFLINE
Posted 17 November 2006 - 07:10 AM
Your welcome, we are always happy to help when we can 
Have a great Night
Andy
Have a great Night
Andy











