![]() |
| |||||||
|
![]() |
| | Thread Tools |
|
#11
| |||
| |||
| Just post a RSIT log now. Download random's system information tool (RSIT) by random/random from and save it to your Desktop.
|
|
#12
| |||
| |||
| Here you go Logfile of random's system information tool 1.05 (written by random/random) Run by user at 2009-02-01 07:24:35 Microsoft® Windows Vista™ Home Premium Service Pack 1 System drive C: has 256 GB (67%) free of 382 GB Total RAM: 2046 MB (57% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:25:33 AM, on 1/02/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe C:\Windows\system32\Macromed\Flash\FlashUtil10a.ex e C:\Users\user\Downloads\RSIT.exe C:\Program Files\CA\CA Internet Security Suite\ccprovep.exe C:\Program Files\trend micro\user.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programs\PartyGaming\PartyGammon\RunBackGammon. exe (file missing) O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Programs\PartyGaming\PartyGammon\RunBackGammon. exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - (no file) O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe -- End of file - 7901 bytes ======Scheduled tasks folder====== C:\Windows\tasks\CAAntiSpywareScan_Daily as user at 12 38 AM.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-02-01 320920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-02-01 34816] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{FBF2401B-7447-4727-BE5D-C19B2075CA84}] CA Toolbar Helper - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-24 275896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - CA Toolbar - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-24 275896] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-08-17 4669440] "NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648] "RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2006-11-23 56928] "LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-12-05 54832] "cctray"=C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe [2009-01-29 181488] "CAVRID"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2008-08-30 234736] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792] "Skytel"=C:\Windows\Skytel.exe [2007-08-17 1826816] "NvSvc"=C:\Windows\system32\nvsvc.dll [2007-09-12 86016] "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-09-12 8497696] "NvMediaCenter"=C:\Windows\system32\NvMcTray.d ll [2007-09-12 81920] "cafw"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-08-28 771312] "capfasem"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-08-28 173296] "QOELOADER"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe [2008-09-29 14088] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-02-01 136600] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920] "WindowsWelcomeCenter"=C:\Windows\system32\oobefld r.dll [2008-01-19 2153472] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup CAAntiSpywareScan_Daily as user at 12 38 AM.job SA.DAT SCHEDLGU.TXT C:\Users\user\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Startup CAAntiSpywareScan_Daily as user at 12 38 AM.job SA.DAT SCHEDLGU.TXT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW] C:\Windows\system32\UmxWnp.Dll [2007-05-18 79368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks] "{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"=C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll [2008-07-24 1377720] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\explorer] "EnableShellExecuteHooks"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list] "C:\Program Files\PPMate\ppmate.exe"="C:\Program Files\PPMate\ppmate.exe:*:Enabled:PPMate" "C:\Program Files\PPMate\ppamnet.exe"="C:\Program Files\PPMate\ppamnet.exe:*:Enabled:PPMate" [HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{75b9cecb-4dd9-11dd-9512-001a4d4f73bf}] shell\Auto\command - Backup.exe shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Backup.exe ======List of files/folders created in the last 1 months====== 2009-02-01 07:24:35 ----D---- C:\rsit 2009-02-01 05:55:26 ----A---- C:\Windows\system32\javaws.exe 2009-02-01 05:55:26 ----A---- C:\Windows\system32\javaw.exe 2009-02-01 05:55:26 ----A---- C:\Windows\system32\java.exe 2009-02-01 05:43:11 ----A---- C:\Windows\system32\deploytk.dll 2009-02-01 04:58:05 ----D---- C:\Users\user\AppData\Roaming\Malwarebytes 2009-02-01 04:57:59 ----D---- C:\ProgramData\Malwarebytes 2009-02-01 04:57:59 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2009-02-01 03:53:26 ----D---- C:\ProgramData\SUPERAntiSpyware.com 2009-02-01 03:52:58 ----D---- C:\Users\user\AppData\Roaming\SUPERAntiSpyware.com 2009-02-01 03:52:58 ----D---- C:\Program Files\SUPERAntiSpyware 2009-02-01 02:41:55 ----D---- C:\Program Files\CCleaner 2009-02-01 02:35:11 ----D---- C:\Program Files\WinRAR 2009-01-29 19:57:34 ----A---- C:\Windows\system32\isafprod.dll 2009-01-09 14:58:32 ----A---- C:\Windows\system32\mshtml.dll 2009-01-09 14:57:31 ----A---- C:\Windows\system32\tzres.dll 2009-01-09 14:55:51 ----A---- C:\Windows\system32\wininet.dll 2009-01-09 14:55:51 ----A---- C:\Windows\system32\urlmon.dll 2009-01-09 14:55:51 ----A---- C:\Windows\system32\mstime.dll 2009-01-09 14:55:51 ----A---- C:\Windows\system32\ieframe.dll 2009-01-09 14:55:50 ----A---- C:\Windows\system32\jsproxy.dll 2009-01-09 14:55:50 ----A---- C:\Windows\system32\iertutil.dll 2009-01-09 14:55:47 ----A---- C:\Windows\system32\gdi32.dll 2009-01-09 14:55:42 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll 2009-01-09 14:55:42 ----A---- C:\Windows\system32\Apphlpdm.dll 2009-01-09 14:55:33 ----A---- C:\Windows\system32\shell32.dll 2009-01-09 14:54:08 ----A---- C:\Windows\explorer.exe 2009-01-09 14:53:57 ----A---- C:\Windows\system32\mf.dll 2009-01-09 14:53:56 ----A---- C:\Windows\system32\WMVCORE.DLL 2009-01-09 14:53:56 ----A---- C:\Windows\system32\WMNetMgr.dll 2009-01-09 14:53:56 ----A---- C:\Windows\system32\logagent.exe 2009-01-06 21:14:54 ----DC---- C:\Windows\system32\DRVSTORE ======List of files/folders modified in the last 1 months====== 2009-02-01 07:25:33 ----D---- C:\Program Files\Trend Micro 2009-02-01 07:24:56 ----SHD---- C:\Windows\Installer 2009-02-01 07:24:48 ----D---- C:\Windows\Temp 2009-02-01 07:24:29 ----HD---- C:\Config.msi 2009-02-01 06:20:37 ----D---- C:\Windows\System32 2009-02-01 06:20:37 ----D---- C:\Windows\inf 2009-02-01 06:20:37 ----A---- C:\Windows\system32\PerfStringBackup.INI 2009-02-01 06:13:15 ----D---- C:\Windows 2009-02-01 05:54:58 ----D---- C:\Program Files\Java 2009-02-01 05:54:48 ----SHD---- C:\System Volume Information 2009-02-01 04:58:02 ----D---- C:\Windows\system32\drivers 2009-02-01 04:57:59 ----HD---- C:\ProgramData 2009-02-01 04:57:59 ----D---- C:\Program Files 2009-02-01 04:46:02 ----D---- C:\Windows\Prefetch 2009-02-01 03:51:55 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2009-02-01 03:15:52 ----D---- C:\ProgramData\Adobe 2009-01-30 03:22:44 ----D---- C:\Users\user\AppData\Roaming\CallingID 2009-01-29 20:18:07 ----A---- C:\caisslog.txt 2009-01-29 20:05:59 ----A---- C:\Windows\DNAPrinters.ini 2009-01-29 19:57:35 ----A---- C:\caavsetupLog.txt 2009-01-29 19:57:22 ----HD---- C:\Program Files\InstallShield Installation Information 2009-01-29 19:57:22 ----D---- C:\Windows\rnapxs 2009-01-29 19:52:30 ----D---- C:\Users\user\AppData\Roaming\GetRightToGo 2009-01-29 19:49:54 ----D---- C:\Program Files\Mozilla Firefox 2009-01-24 16:52:48 ----D---- C:\Windows\system32\catroot2 2009-01-22 16:13:48 ----SD---- C:\Windows\Downloaded Program Files 2009-01-09 15:22:24 ----D---- C:\Windows\rescache 2009-01-09 15:16:12 ----D---- C:\Windows\winsxs 2009-01-09 15:06:07 ----D---- C:\Windows\system32\catroot 2009-01-09 15:03:11 ----D---- C:\Windows\system32\en-US 2009-01-09 15:03:11 ----D---- C:\Windows\AppPatch 2009-01-09 15:03:11 ----D---- C:\Program Files\Windows Mail 2009-01-09 15:02:12 ----D---- C:\Windows\Debug 2009-01-09 14:49:38 ----D---- C:\Program Files\Common Files 2009-01-09 14:48:17 ----D---- C:\Windows\system32\Tasks 2009-01-09 14:47:08 ----D---- C:\Program Files\HollywoodPoker 2009-01-09 14:44:18 ----AD---- C:\Program Files\PlayersOnly Poker 2009-01-09 14:41:38 ----D---- C:\Program Files\3DFiBs ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 KmxAgent;KmxAgent; C:\Windows\System32\DRIVERS\kmxagent.sys [2008-03-21 63504] R1 KmxFile;KmxFile; C:\Windows\System32\DRIVERS\KmxFile.sys [2008-03-21 45584] R1 KmxFilter;HIPS Core Filter Driver; C:\Windows\system32\DRIVERS\KmxFilter.sys [2008-05-30 51704] R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944] R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024] R1 VETEFILE;VET File Scan Engine; C:\Windows\system32\drivers\VETEFILE.sys [2009-01-29 880560] R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\Windows\system32\drivers\VETFDDNT.sys [2008-08-30 21488] R1 VET-FILT;VET File System Filter; C:\Windows\system32\drivers\VET-FILT.sys [2008-08-30 26352] R1 VETMONNT;VET File Monitor; C:\Windows\system32\drivers\VETMONNT.sys [2008-08-30 32240] R1 VET-REC;VET File System Recognizer; C:\Windows\system32\drivers\VET-REC.sys [2008-08-30 21104] R2 KmxCF;KmxCF; C:\Windows\System32\DRIVERS\KmxCF.sys [2008-06-04 138744] R2 KmxSbx;KmxSbx; C:\Windows\System32\DRIVERS\KmxSbx.sys [2008-03-21 66576] R3 AvsBluebird;FusionHDTV USB, AVStream Capture; C:\Windows\system32\drivers\bluebird2.sys [2007-06-20 360704] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-08-17 1841312] R3 KmxCfg;KmxCfg; C:\Windows\System32\DRIVERS\kmxcfg.sys [2008-05-30 88816] R3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] R3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2007-01-15 9728] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-12 7623968] R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-12-28 104448] R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408] R3 VETEBOOT;VET Boot Scan Engine; C:\Windows\system32\drivers\VETEBOOT.sys [2009-01-29 108368] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328] S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 ndiscm;Motorola USB Cable Modem Windows Driver; C:\Windows\system32\DRIVERS\NetMotCM.sys [2003-08-09 14336] S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 CAISafe;CAISafe; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe [2008-08-30 144696] R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-09-26 283912] R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120] R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-07 167936] R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192] R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296] R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2008-03-19 145936] R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-04-15 281104] R2 VETMSGNT;VET Message Service; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe [2008-08-30 255216] R3 CaCCProvSP;CaCCProvSP; C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe [2009-01-29 214256] R3 PPCtlPriv;PPCtlPriv; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-08-27 185584] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144] S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-02-06 266240] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] -----------------EOF----------------- |
|
#13
| |||
| |||
| info.txt logfile of random's system information tool 1.05 2009-02-01 07:25:36 ======Uninstall list====== -->"C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\setup\ccinstaller.exe" /u /silent /module="fw" -->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7} Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_acti veX.exe Adobe Flash Player Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plug in.exe Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003} ANWIDA Soft DX Reverb Light 2.0-->C:\Windows\IsUninst.exe -f"C:\Program Files\ANWIDA Soft\DX Reverb Light\Uninst.isu" CA Anti-Spyware-->"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\setup\ccinstaller.exe" /u /silent /module="pp" CA Anti-Virus-->C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\unvet32.exe CA Desktop DNA Migrator-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~ 1\IDriver.exe /M{0AFD47CE-CA9C-4372-AA20-CB05D33638FA} /l1033 /s /f1"C:\Program Files\CA\CA Internet Security Suite\CA Desktop DNA Migrator\dnaunset.iss" /s /f1"C:\Program Files\CA\CA Internet Security Suite\CA Desktop DNA Migrator\dnaunset.iss" CA Internet Security Suite-->"C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u CA Pest Patrol Realtime Protection-->MsiExec.exe /X{F05A5232-CE5E-4274-AB27-44EB8105898D} CA Website Inspector-->C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\CAWebsiteInspector.exe /uninstall CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall DVICO FusionHDTV 3.63.01 -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\ 00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5EBE62BD-774D-40F7-B777-EA7B2EE28F80}\Setup.exe" -l0x9 -removeonly GammonSite 5.52-->"C:\Program Files\GammonSite\unins000.exe" HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF} Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Live 7.0.5-->C:\PROGRA~1\Ableton\LIVE70~1.5\Install\UNWISE.E XE C:\PROGRA~1\Ableton\LIVE70~1.5\Install\INSTALL.LOG Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} myTV-->C:\Program Files\InstallShield Installation Information\{C54184D0-D281-4523-B357-0606209DB56C}\setup.exe -runfromtemp -l0x0009 -removeonly Nero 7 Essentials-->MsiExec.exe /X{55A960A6-0CAC-4EBB-9D7E-199545391033} NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0009 -removeonly Realtek High Definition Audio Driver-->RtlUpd.exe -r -m SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe ======Security center information====== AV: CA Anti-Virus FW: CA Personal Firewall AS: Windows Defender AS: CA Anti-Spyware AS: SUPERAntiSpyware (disabled) System event log Computer Name: user-PC Event Code: 7036 Message: The Office Source Engine service entered the stopped state. Record Number: 79527 Source Name: Service Control Manager Time Written: 20090131202402.000000-000 Event Type: Information User: Computer Name: user-PC Event Code: 7036 Message: The Office Source Engine service entered the running state. Record Number: 79528 Source Name: Service Control Manager Time Written: 20090131202418.000000-000 Event Type: Information User: Computer Name: user-PC Event Code: 7036 Message: The Office Source Engine service entered the stopped state. Record Number: 79529 Source Name: Service Control Manager Time Written: 20090131202427.000000-000 Event Type: Information User: Computer Name: user-PC Event Code: 7036 Message: The Office Source Engine service entered the running state. Record Number: 79530 Source Name: Service Control Manager Time Written: 20090131202427.000000-000 Event Type: Information User: Computer Name: user-PC Event Code: 7036 Message: The Office Source Engine service entered the stopped state. Record Number: 79531 Source Name: Service Control Manager Time Written: 20090131202429.000000-000 Event Type: Information User: Application event log Computer Name: user-PC Event Code: 1035 Message: Windows Installer reconfigured the product. Product Name: Microsoft Office Professional Edition 2003. Product Version: 11.0.5614.0. Product Language: 1033. Reconfiguration success or error status: 1602. Record Number: 15061 Source Name: MsiInstaller Time Written: 20090131202456.000000-000 Event Type: Information User: user-PC\user Computer Name: user-PC Event Code: 10000 Message: Starting session 1 - 2009-01-31T20:24:55.436Z. Record Number: 15062 Source Name: Microsoft-Windows-RestartManager Time Written: 20090131202455.436440-000 Event Type: Information User: user-PC\user Computer Name: user-PC Event Code: 10001 Message: Ending session 1 started 2009-01-31T20:24:55.436Z. Record Number: 15063 Source Name: Microsoft-Windows-RestartManager Time Written: 20090131202455.904440-000 Event Type: Information User: user-PC\user Computer Name: user-PC Event Code: 10000 Message: Starting session 1 - 2009-01-31T20:24:56.138Z. Record Number: 15064 Source Name: Microsoft-Windows-RestartManager Time Written: 20090131202456.138440-000 Event Type: Information User: user-PC\user Computer Name: user-PC Event Code: 10001 Message: Ending session 1 started 2009-01-31T20:24:56.138Z. Record Number: 15065 Source Name: Microsoft-Windows-RestartManager Time Written: 20090131202456.668840-000 Event Type: Information User: user-PC\user Security event log Computer Name: user-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\t cpip.sys Record Number: 21457 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090131202531.372240-000 Event Type: Audit Failure User: Computer Name: user-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\t cpip.sys Record Number: 21458 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090131202531.419040-000 Event Type: Audit Failure User: Computer Name: user-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\t cpip.sys Record Number: 21459 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090131202531.434640-000 Event Type: Audit Failure User: Computer Name: user-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\t cpip.sys Record Number: 21460 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090131202531.465840-000 Event Type: Audit Failure User: Computer Name: user-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\t cpip.sys Record Number: 21461 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090131202531.497040-000 Event Type: Audit Failure User: ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemR oot%\System32\Wbem "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;. WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=x86 "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% "PROCESSOR_LEVEL"=6 "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel "PROCESSOR_REVISION"=0f0b "NUMBER_OF_PROCESSORS"=2 "configsetroot"=%SystemRoot%\ConfigSetRoot -----------------EOF----------------- |
|
#14
| |||
| |||
| Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix |
|
#15
| |||
| |||
| I'm not sure how to disable my CA Spyware and Anti-Virus...in that link it only shows me how to disable my Firefox. I did a google search but didnt find much help I disabled my Firefox and ran ComboFix but recieved an error message, I've attached a screen shot Not sure if this is necessary but I just search the CA help section and this is what it says about the anti-virus Real-time Scanning Enabled by default, real-time scanning automatically scans your computer, including your incoming email, to detect and remove malware that attempts to install itself or run on your system. And this is what it says about the anti-spyware Real-time Scanning Enabled by default, real-time scanning automatically scans your computer to detect and remove spyware that attempts to install itself or run on your system. OH and it says something is infected (look at the attached picture) |
|
#16
| |||
| |||
| Sorry I mean Firewall not Firefox |
|
#17
| |||
| |||
| Can you just right click the icon in the Task Bar and turn off CA? |
|
#18
| |||
| |||
| I cant disable the whole of CA Security but it does offer me an option to 'Snooze' the anti-virus but even when I do this, ComboFix says that it has detected an antivirus to be active I've attached a screen shot I did a google search on how to disable the anti-virus and the only info I am finding is people saying to just 'Snooze' the CA antivirus which they say disables it ??? |
|
#19
| |||
| |||
| Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
When the scan is done, in the Scan is complete window, any infection is displayed. There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
![]() Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. |
|
#20
| |||
| |||
| -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, February 4, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, February 04, 2009 06:01:29 Records in database: 1742983 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ F:\ G:\ H:\ I:\ Scan statistics: Files scanned: 114978 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:14:42 File name / Threat name / Threats count C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.632 1 The selected area was scanned. |
![]() |
|
| Bookmarks |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Errors when installing software | brandoncrossman | Windows Operating Systems | 1 | 14th Jun 2009 07:48 |
| Trouble with Installing AOL Software - Need Help Please! | P5200 | Web Browsers & FTP Clients | 2 | 11th Mar 2009 17:01 |
| Cannot Update Virus and Spyware software on My Pc. | ddd13 | Virus, Spyware & Security | 18 | 28th Feb 2009 19:52 |
| Trouble with New disc drive - installing software | Jdouglas | Drives & Removable Media | 4 | 5th Jan 2008 18:40 |
| Installing software on several computers... at once! | jorgedbucaran | General Software Chat | 1 | 10th Oct 2007 08:52 |
| Thread Tools | |
| |