neal
ok done these last few bits - logs below.
from my last post you see an problems with the 'world' still spinning in the top RH corner even now even though the page loaded ages ago. Seems a bit odd???
also on the HJT log - i think i could also disable the itunes helper from start up - u think ok? don't think i ever use it.
I have also done an Ad-aware SE scan - it keep scoming upevery time with an error which is detailed as 'richardmiles@kontera.com. - can i get rid permanently?
also on a spybot scan it conyinually finds an 'MBS.' issues - i keep fixing it but it keeps finding it. any suggestions?
thanks for help
Combo fix log:
ComboFix 07-06-11 - C:\Documents and Settings\Richard Miles\Desktop\ComboFix.exe
"Richard Miles" - 10/06/2007 21:11:02 - Service Pack 4 NTFS
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-05-10 to 2007-06-10 )))))))))))))))))))))))))))))))
2007-06-10 21:15 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_510.dat
2007-06-10 21:09 49,152 --a------ C:\WINNT\nircmd.exe
2007-06-10 16:40 <DIR> d-------- C:\DOCUME~1\RICHAR~1\DoctorWeb
2007-06-10 16:39 <DIR> d-------- C:\Program Files\iTunes
2007-06-10 16:37 <DIR> d-------- C:\Program Files\QuickTime
2007-06-09 13:57 10,872 --a------ C:\WINNT\system32\drivers\AvgAsCln.sys
2007-06-08 19:11 <DIR> d-------- C:\HJT
2007-06-02 19:45 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\ZoomBrowser
2007-05-31 16:57 <DIR> d-------- C:\WINNT\system32\SoftwareDistribution
2007-05-20 21:18 <DIR> d-------- C:\canon user guides
2007-05-20 21:01 <DIR> d-------- C:\Program Files\New Folder
2007-05-20 21:01 <DIR> d-------- C:\photo library
2007-05-20 20:55 <DIR> d-------- C:\DOCUME~1\RICHAR~1\APPLIC~1\ZoomBrowser EX
2007-05-20 20:03 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-05-20 09:24 75,512 --a------ C:\WINNT\zllsputility.exe
2007-05-20 09:24 11,264 --a------ C:\WINNT\system32\SpOrder.dll
2007-05-20 09:24 1,087,216 --a------ C:\WINNT\system32\zpeng24.dll
2007-05-13 12:07 30,336 --a------ C:\WINNT\system32\drivers\glauiad.sys
2007-05-13 12:07 <DIR> d-------- C:\Program Files\MT882
2007-05-13 11:33 70,688 --a------ C:\WINNT\system32\drivers\alcaudsl.sys
2007-05-13 11:33 53,600 --a------ C:\WINNT\system32\drivers\alcan5wn.sys
2007-05-13 11:33 5,606 --a------ C:\WINNT\system32\stci.dll
2007-05-13 11:33 5,280 --a------ C:\WINNT\system32\drivers\alcawh.sys
2007-05-13 11:33 3,968 --a------ C:\WINNT\system32\drivers\alcacr.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-06-10 15:39:28 -------- d-----w C:\Program Files\iPod
2007-06-09 13:48:46 -------- d-----w C:\Program Files\SpywareBlaster
2007-06-02 18:46:35 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-02 18:46:27 -------- d-----w C:\Program Files\Canon
2007-06-02 18:06:31 -------- d-----w C:\Program Files\DriverGuide Toolkit
2007-05-28 07:20:12 -------- d-----w C:\Program Files\SpywareGuard
2007-05-20 08:25:48 4,212 ---h--w C:\WINNT\system32\zllictbl.dat
2007-05-09 20:57:20 26,944 ----a-w C:\WINNT\system32\drivers\avg7rsnt.sys
2007-05-09 18:13:25 -------- d-----w C:\Program Files\Common Files\SupportSoft
2007-04-16 21:47:36 33,624 ----a-w C:\WINNT\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINNT\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINNT\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINNT\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINNT\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINNT\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINNT\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINNT\system32\wups2.dll
2007-04-05 07:17:39 2,854,400 ----a-w C:\WINNT\system32\msi.dll
2007-03-13 09:44:49 245,520 ----a-w C:\WINNT\system32\WINSRV.DLL
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [01-03-02 12:02 ]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}=C:\Program Files\SpywareGuard\dlprotect.dll [03-08-03 00:24 ]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [05-05-31 01:04 ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc. exe" [07-05-09 21:58 ]
"Synchronization Manager"="mobsync.exe" [03-06-19 20:05 C:\WINNT\system32\mobsync.exe]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-03-09 01:02 ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-03-09 01:02 ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [07-06-01 16:51 ]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
"internat.exe"=internat.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [07-05-30 13:29 ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"Synchronization Manager"=mobsync.exe /logon
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
WmdmPmSN
*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
Contents of the 'Scheduled Tasks' folder
2007-06-01 16:15:04 C:\WINNT\tasks\1-Click Maintenance.job
2007-06-10 15:34:09 C:\WINNT\tasks\AppleSoftwareUpdate.job
************************************************** ************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-10 21:15:43
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-06-10 21:17:35 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-06-10 21:17
--- E O F ---
New HJT log
Logfile of HijackThis v1.99.1
Scan saved at 21:24:55, on 10/06/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Richard Miles\Desktop\hijackthis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) -
http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -
http://download.zonelabs.com/bin/pro...anner37380.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -
http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) -
http://register.btinternet.com/templ...control023.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) -
http://www5.incredimail.com/contents...r/imloader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe