Hi,
I done the requested.
1st HJT log before running combofix and cc cleaner:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:00:18, on 02/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\foolyou.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=explorer.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O13 - Gopher Prefix:
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) -
http://h30155.www3.hp.com/ediags/dd/...sticsVista.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0352783-D1DD-4144-BA03-6965326F5637}: NameServer = 195.92.195.94,195.92.195.95
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: SessionLauncher - Unknown owner - C:\Users\Steven\AppData\Local\Temp\DX9\SessionLaun cher.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 8890 bytes
Here is the combfix log:
ComboFix 07-11-01.1 - Steven 2007-11-02 9:41:49.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1277 [GMT 0:00]
Running from: C:\Users\Steven\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-02 to 2007-11-02 )))))))))))))))))))))))))))))))
.
2007-11-02 09:38 51,200 --a------ C:\Windows\NirCmd.exe
2007-11-02 09:03 <DIR> d-------- C:\Program Files\CCleaner
2007-10-29 21:27 289,144 --a------ C:\Windows\System32\VCCLSID.exe
2007-10-29 21:27 288,417 --a------ C:\Windows\System32\SrchSTS.exe
2007-10-29 21:27 53,248 --a------ C:\Windows\System32\Process.exe
2007-10-29 21:27 51,200 --a------ C:\Windows\System32\dumphive.exe
2007-10-29 21:27 25,600 --a------ C:\Windows\System32\WS2Fix.exe
2007-10-29 18:38 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Grisoft
2007-10-29 18:38 <DIR> d-------- C:\Users\All Users\Grisoft
2007-10-29 18:38 <DIR> d-------- C:\ProgramData\Grisoft
2007-10-29 18:38 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2007-10-28 09:35 3,114 --a------ C:\Windows\System32\tmp.reg
2007-10-26 19:39 <DIR> d-------- C:\Program Files\Image Add-on
2007-10-22 20:32 <DIR> d-------- C:\Users\Steven\AppData\Roaming\SystemRequirements Lab
2007-10-22 16:30 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Template
2007-10-22 16:30 96 --a------ C:\Users\Steven\AppData\Roaming\wklnhst.dat
2007-10-22 16:04 <DIR> d-------- C:\Windows\Sun
2007-10-22 15:51 <DIR> d-------- C:\Program Files\Microsoft Picture It! 10
2007-10-12 15:59 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Lionhead Studios
2007-10-12 15:46 <DIR> d-------- C:\Program Files\MySoCo.com
2007-10-12 15:12 <DIR> d-------- C:\Program Files\Password Protect
2007-10-12 13:37 <DIR> d-------- C:\Program Files\Easy CD & DVD Cover Creator
2007-10-12 12:09 2,179,072 --a------ C:\Windows\System32\mfc71d.dll
2007-10-12 12:09 765,952 --a------ C:\Windows\System32\msvcp71d.dll
2007-10-12 12:09 544,768 --a------ C:\Windows\System32\msvcr71d.dll
2007-10-12 12:09 149,504 --a------ C:\Windows\System32\UNWISE.EXE
2007-10-12 12:08 <DIR> d-------- C:\MyVideos
2007-10-12 12:08 749,641 --a------ C:\Windows\System32\hcwtvwnd.dll
2007-10-12 12:08 258,104 --a------ C:\Windows\System32\hcwpnp32.dll
2007-10-12 12:08 159,744 --a------ C:\Windows\System32\hcwChDB.dll
2007-10-12 12:08 90,190 --a------ C:\Windows\System32\Bt848WST.DLL
2007-10-12 12:08 36,921 --a------ C:\Windows\System32\hcwutl32.dll
2007-10-12 12:08 28,672 --a------ C:\Windows\System32\hcwsched.dll
2007-10-12 12:07 213,050 --a------ C:\Windows\System32\hcwChan.dll
2007-10-12 12:07 106,559 --a------ C:\Windows\System32\hcwTVDlg.dll
2007-10-12 12:07 11,264 --a------ C:\Windows\System32\hcwhook.dll
2007-10-12 12:03 98,360 --------- C:\Windows\System32\hcwi2c32.dll
2007-10-12 11:44 <DIR> d-------- C:\Hauppauge
2007-10-12 11:44 467,456 --a------ C:\Windows\System32\drivers\hcw95bda.sys
2007-10-12 11:44 15,488 --a------ C:\Windows\System32\hcw95rc.sys
2007-10-12 11:44 15,488 --a------ C:\Windows\System32\drivers\hcw95rc.sys
2007-10-12 11:17 <DIR> d-------- C:\Program Files\WinTV
2007-10-12 11:17 69,632 --a------ C:\Windows\System32\3DES.dll
2007-10-12 11:17 65,536 --a------ C:\Windows\System32\dmcrypto.dll
2007-10-11 17:45 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2007-10-11 17:45 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll
2007-10-11 17:45 7,680 --a------ C:\Windows\System32\spwmp.dll
2007-10-11 17:45 4,096 --a------ C:\Windows\System32\dxmasf.dll
2007-10-11 17:43 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-10-11 17:43 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-10-11 17:43 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-10-08 19:25 <DIR> d-------- C:\Users\All Users\Lionhead Studios
2007-10-08 19:25 <DIR> d-------- C:\ProgramData\Lionhead Studios
2007-10-08 19:25 <DIR> d-------- C:\Program Files\Lionhead Studios Ltd
2007-10-08 19:22 <DIR> d--hs---- C:\Windows\ftpcache
2007-10-08 18:49 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Sonic
2007-10-08 18:49 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Leadertech
2007-10-07 13:02 <DIR> d-------- C:\Users\Steven\AppData\Roaming\Roxio
2007-10-07 13:00 <DIR> d-------- C:\Program Files\InterActual
2007-10-07 12:19 <DIR> d-------- C:\Users\All Users\SmartSound Software Inc
2007-10-07 12:19 <DIR> d-------- C:\Users\All Users\eSellerate
2007-10-07 12:19 <DIR> d-------- C:\ProgramData\SmartSound Software Inc
2007-10-07 12:19 <DIR> d-------- C:\ProgramData\eSellerate
2007-10-07 12:19 <DIR> d-------- C:\Program Files\SmartSound Software
2007-10-07 12:18 <DIR> d-------- C:\Users\All Users\InstallShield
2007-10-07 12:18 <DIR> d-------- C:\ProgramData\InstallShield
2007-10-07 12:17 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2007-10-07 12:17 1,123,696 --a------ C:\Windows\System32\D3DCompiler_33.dll
2007-10-07 12:17 443,752 --a------ C:\Windows\System32\d3dx10_33.dll
2007-10-07 12:15 <DIR> d-------- C:\Windows\System32\URTTEMP
2007-10-06 20:31 <DIR> d-------- C:\Program Files\LucasArts
2007-10-05 12:47 2,297,552 --a------ C:\Windows\System32\d3dx9_26.dll
2007-10-05 12:44 <DIR> d-------- C:\Program Files\Codemasters
2007-10-05 11:55 <DIR> d-------- C:\Users\All Users\DVD Shrink
2007-10-05 11:55 <DIR> d-------- C:\ProgramData\DVD Shrink
2007-10-05 11:55 <DIR> d-------- C:\Program Files\DVDFab HD Decrypter 3
2007-10-05 11:55 <DIR> d-------- C:\Program Files\DVD Shrink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-10-29 18:11 --------- d-----w C:\Users\Steven\AppData\Roaming\Azureus
2007-10-25 16:03 23,152 ----a-w C:\Windows\system32\drivers\aswRdr.sys
2007-10-25 16:01 45,648 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2007-10-25 16:01 42,912 ----a-w C:\Windows\system32\drivers\aswTdi.sys
2007-10-25 15:24 815,480 ----a-w C:\Windows\System32\aswBoot.exe
2007-10-25 15:14 95,608 ----a-w C:\Windows\System32\AvastSS.scr
2007-10-23 05:24 --------- d-----w C:\Program Files\Java
2007-10-19 12:23 --------- d-----w C:\ProgramData\Microsoft Help
2007-10-19 09:30 --------- d-----w C:\Users\Steven\AppData\Roaming\LimeWire
2007-10-11 21:17 --------- d-----w C:\Program Files\Windows Mail
2007-10-11 17:44 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-10-11 17:44 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-10-11 17:44 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-10-08 19:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-08 19:17 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-10-07 13:05 --------- d-----w C:\ProgramData\Sonic
2007-10-07 12:57 --------- d-----w C:\ProgramData\Roxio
2007-10-07 12:42 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2007-10-07 12:40 --------- d-----w C:\Program Files\Roxio
2007-10-07 12:26 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2007-10-07 12:18 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-05 07:32 --------- d-----w C:\Program Files\Azureus
2007-10-01 17:21 --------- d-----w C:\Program Files\QuickTime
2007-09-30 19:12 --------- d-----w C:\Program Files\Common Files\Ahead
2007-09-30 19:08 --------- d-----w C:\ProgramData\Nero
2007-09-21 10:11 47,360 ----a-w C:\Windows\system32\drivers\Pcouffin.sys
2007-09-21 10:11 --------- d-----w C:\Program Files\Super DVD Creator 9.25.0
2007-09-19 05:20 --------- d-----w C:\Program Files\dvdSanta
2007-09-18 17:32 --------- d-----w C:\Users\Steven\AppData\Roaming\Media Player Classic
2007-09-18 17:31 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-09-15 17:05 --------- d-----w C:\ProgramData\TEMP
2007-09-15 17:04 --------- d-----w C:\Program Files\Telltale Games
2007-09-10 15:52 --------- d-----w C:\Program Files\EA GAMES
2007-09-07 14:41 --------- d-----w C:\Users\Steven\AppData\Roaming\NeroDCTemplates
2007-09-07 14:18 639,224 ----a-w C:\Windows\system32\drivers\sptd.sys
2007-09-07 09:36 --------- d-----w C:\Users\Steven\AppData\Roaming\Ahead
2007-09-04 16:54 --------- d-----w C:\Program Files\Windows Calendar
2007-09-04 16:09 8,192 ----a-w C:\Windows\System32\riched32.dll
2007-09-04 16:08 77,824 ----a-w C:\Windows\System32\rascfg.dll
2007-09-04 16:08 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2007-09-04 16:08 694,784 ----a-w C:\Windows\System32\localspl.dll
2007-09-04 16:08 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2007-09-04 16:08 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2007-09-04 16:08 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2007-09-04 16:08 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2007-09-04 16:08 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2007-09-04 16:08 36,864 ----a-w C:\Windows\System32\cdd.dll
2007-09-04 16:08 33,280 ----a-w C:\Windows\System32\traffic.dll
2007-09-04 16:08 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2007-09-04 16:08 286,208 ----a-w C:\Windows\System32\ipnathlp.dll
2007-09-04 16:08 22,016 ----a-w C:\Windows\System32\rasser.dll
2007-09-04 16:08 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2007-09-04 16:08 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-09-04 16:08 134,656 ----a-w C:\Windows\System32\dps.dll
2007-09-04 16:08 13,824 ----a-w C:\Windows\System32\wshqos.dll
2007-09-04 16:08 13,824 ----a-w C:\Windows\System32\icsunattend.exe
2007-09-02 15:08 108,144 ----a-w C:\Windows\System32\CmdLineExt.dll
2007-09-02 14:24 --------- d-----w C:\Program Files\Common Files\EasyInfo
2007-09-02 13:07 174 --sha-w C:\Program Files\desktop.ini
2007-09-02 12:50 88,576 ----a-w C:\Windows\System32\avifil32.dll
2007-09-02 12:50 82,944 ----a-w C:\Windows\System32\mciavi32.dll
2007-09-02 12:50 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr
2007-09-02 12:50 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll
2007-09-02 12:50 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-09-02 12:50 69,632 ----a-w C:\Windows\System32\sendmail.dll
2007-09-02 12:50 65,024 ----a-w C:\Windows\System32\avicap32.dll
2007-09-02 12:50 61,440 ----a-w C:\Windows\System32\ntprint.exe
2007-09-02 12:50 31,232 ----a-w C:\Windows\System32\msvidc32.dll
2007-09-02 12:50 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-09-02 12:50 3,470,008 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-09-02 12:50 269,824 ----a-w C:\Windows\System32\schannel.dll
2007-09-02 12:50 220,160 ----a-w C:\Windows\System32\ntprint.dll
2007-09-02 12:50 123,904 ----a-w C:\Windows\System32\msvfw32.dll
2007-09-02 12:50 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll
2007-09-02 12:50 12,800 ----a-w C:\Windows\System32\msrle32.dll
2007-09-02 12:50 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll
2007-09-02 12:50 1,984,512 ----a-w C:\Windows\System32\authui.dll
2007-09-02 12:49 750,080 ----a-w C:\Windows\System32\qmgr.dll
2007-09-02 12:48 --------- d-----w C:\Program Files\Belkin
2007-08-28 10:48 98,304 ----a-w C:\Windows\system32CmdLineExt.dll
2007-08-24 17:08 1,275,392 ----a-w C:\Windows\System32\msxml4.dll
2007-08-24 11:07 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2007-08-24 11:07 43,352 ----a-w C:\Windows\System32\wups2.dll
2007-08-24 11:07 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2007-08-24 11:07 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2007-08-24 11:06 80,896 ----a-w C:\Windows\System32\wudriver.dll
2007-08-24 11:06 549,720 ----a-w C:\Windows\System32\wuapi.dll
2007-08-24 11:06 33,624 ----a-w C:\Windows\System32\wups.dll
2007-08-24 11:06 31,232 ----a-w C:\Windows\System32\wuapp.exe
2007-08-24 11:06 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2007-08-23 13:37 87,040 ----a-w C:\Windows\System32\msoert2.dll
2007-08-23 13:37 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2007-08-23 13:37 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2007-08-23 13:35 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2007-08-23 13:35 61,952 ----a-w C:\Windows\System32\cmifw.dll
2007-08-23 13:35 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2007-08-23 13:35 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2007-08-23 13:35 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2007-08-23 13:35 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2007-08-23 13:35 16,896 ----a-w C:\Windows\System32\wfapigp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-06-01 02:47]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 13:42]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 10:59]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-04-20 01:11]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-15 04:03]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-15 04:03]
"NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-05-15 04:03]
"CCUTRAYICON"="FactoryMode" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp. exe" [2007-10-25 15:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 12:23]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-01 03:07]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40]
"DMXLauncher"="C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe" [2007-08-14 02:44]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 15:24]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 12:35]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runonce]
"Launcher"=%WINDIR%\SMINST\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableLUA"=0 (0x0)
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\as wMonFlt.sys
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe"
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvld dmkm.sys
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe"
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;"C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe"
S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe"
S2 RoxWatch10;Roxio Hard Drive Watcher 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe"
S2 SessionLauncher;SessionLauncher;C:\Users\Steven\Ap pData\Local\Temp\DX9\SessionLauncher.exe
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;C:\Windows\system32\Drivers\hcw95bda.sys
S3 hcw95rc;Hauppauge MOD7700 IR Driver;C:\Windows\system32\DRIVERS\hcw95rc.sys
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;"C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe"
S3 RoxMediaDB10;RoxMediaDB10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe"
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\Windows\system32\DRIVERS\sis163u.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\J]
\shell\AutoRun\command - J:\SETUP.EXE AUTORUN=1
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\AUTOSTUB.EXE
*Newly Created Service* - CATCHME
.
************************************************** ************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-02 09:45:06
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-11-02 9:46:05
.
--- E O F ---
And finally here is the 2nd HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:51:13, on 02/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\notepad.exe
C:\Windows\Explorer.exe
C:\Program Files\HijackThis\foolyou.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O13 - Gopher Prefix:
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) -
http://h30155.www3.hp.com/ediags/dd/...sticsVista.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0352783-D1DD-4144-BA03-6965326F5637}: NameServer = 195.92.195.94,195.92.195.95
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: SessionLauncher - Unknown owner - C:\Users\Steven\AppData\Local\Temp\DX9\SessionLaun cher.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 8554 bytes
Regards,
Steve