Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst exeC:\WINDOWS\Explorer. EXEC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32 exeC:\WINDOWS\system32\spoolsv exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst exeC:\WINDOWS\system32\gearsec exeC:\WINDOWS\system32\gearsec exeC:\schedule Files\Common Files\Microsoft Shared\VS7Debug\mdm exeC:\WINDOWS\system32\RioMSC exeC:\WINDOWS\System32\tcpsvcs exeC:\WINDOWS\System32\svchost exeC:\Program Files\Sony\giga pocket\GPVSvr exeC:\WINDOWS\System32\MsPMSPSv exeC:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeC:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeC:\WINDOWS\htpatch exeC:\Program Files\STOPzilla!\Stopzilla exeC:\WINDOWS\System32\ezSP_Px exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXEC:\Program Files\QuickTime\qttask exeC:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exeC:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exeC:\Program Files\Java\jre1.6.0_01\bin\jusched exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 exeC:\Program Files\HP\hpcoretech\hpcmpmgr exeC:\WINDOWS\system32\hphmon06 exeC:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist exeC:\Program Files\HP\HP Software Update\HPWuSchd2 exeC:\WINDOWS\system32\ctfmon exeC:\Program Files\Common Files\Symantec Shared\ccApp exeC:\schedule Files\Cactus Spam Filter 2.13\cactusspamfilter exeC:\Program Files\sony\giga pocket\usbsircs exeC:\WINDOWS\system32\rundll32 exeC:\WINDOWS\system32\HPZipm12 exeC:\Program Files\Sony\VAIO Action Setup\VAServ exeC:\Program Files\HP\Digital Imaging\bin\hpqgalry exeC:\Program Files\Internet Explorer\iexplore exeC:\Program Files\Trend Micro\HijackThis\HijackThis exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O2 - BHO: AcroIEHlprObj categorise - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper ocxO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside dllO2 - BHO: BetaDivX - {48BF2BC0-2945-11D8-8CAC-00080FC65465} - C:\WINDOWS\system32\IR9V0_QCX dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv dllO2 - BHO: BrowserHelper Class - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\StopzillaBHO dllO4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch exeO4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray exe" /rO4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\Stopzilla exe /autorunO4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px exeO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck exeO4 - HKLM\..\Run: [CTHelper] CTHELPER. EXEO4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [RoxioEngineUtility] "C:\schedule Files\Common Files\Roxio Shared\System\EngUtil exe"O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exe"O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\schedule Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exe"O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched exe"O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 exeO4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 exeO4 - HKLM\..\Run: [HP Component Manager] "C:\schedule Files\HP\hpcoretech\hpcmpmgr exe"O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06 exeO4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE. EXE /AUTORUNO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2 exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp exe"O4 - HKLM\..\Run: [osCheck] "C:\schedule Files\Norton AntiVirus\osCheck exe"O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng dll"O4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [NVIEW] rundll32 exe nview dll,nViewLoadHookO4 - HKCU\..\Run: [com codeode cactusspamfilter] "C:\Program Files\Cactus Spam Filter 2.13\cactusspamfilter exe" -minimizedO4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF. EXE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator exe (User 'SYSTEM')O4 - HKUS\. DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF. EXE (User 'Default user')O4 - Global Startup: Giga Pocket Remocon Driver lnk = ?O4 - Global Startup: HP Digital Imaging Monitor lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08 exeO4 - Global Startup: HP Image Zone abstain Start lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08 exeO4 - Global Startup: VAIO Action Setup (Server) lnk = ?O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL. EXE/3000O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO14 - IERESET. INF: go away_summon_URL=http://www ucs att netO16 - DPF: RaptisoftGameLoader - O16 - DPF: symsupportutil - O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo. CMClass) - O16 - DPF: {0957C19A-D854-482A-A4F9-18856C723D7D} (XNC600NetCam Control) - O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (incise Control) - O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (CSonyPicturesGameDownloaderCtl Object) - O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier categorise) - O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager. CacheManagerCtrl) - O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl categorise) - O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - O16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB} (sonyctl sonycm) - O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin dllO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeO23 - function: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\system32\gearsec exeO23 - Service: GEARSecurity_BackUp - GEAR Software - C:\WINDOWS\system32\gearsec exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT exeO23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1. EXEO23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12 exeO23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America. Inc. - C:\WINDOWS\system32\RioMSC exeO23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv exeO23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc exeO23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32 exeO23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Music Server\SSSvr exeO23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd exeO23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeO23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv exeO23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeO23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeO23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\giga pocket\GPVSvr exeO23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeO23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exe
Your StopZilla may also interfere with our fix so please disable that while we are running our tools/scans. Reboot into Safemode:Turn on the computer. Immediately begin tapping the F8 key. Use the arrow keys to highlight Safe Mode and press the Enter key. Please launch HijackThis and place a checkmark next to this:O2 - BHO: BetaDivX - {48BF2BC0-2945-11D8-8CAC-00080FC65465} - C:\WINDOWS\system32\IR9V0_QCX dllClose all windows except HijackThis and click "Fix Checked". Reboot normally. Please download Combofix from here:** Take note that the link is case sensitiveSave ComboFix to the desktop.1. Double move on combo exe & follow the prompts.2. When finished it will produce a logfile located at C:\ComboFix txt.3. Post the contents of that log in your next reply with a new HijackThis log. Note:Do not mouseclick Combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run ComboFix.
((((((((((((((((((((((((((((((((((((((((  Find3M inform  )))))))))))))))))))))))))))))))))))))))))))))))))))).2007-10-26 12:44 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\Roxio2007-10-26 02:26 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. INF2007-10-26 02:26 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1. DLL2007-10-26 02:26 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. SYS2007-10-26 02:26 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. CAT2007-10-26 02:26 --------- d-----w C:\Program Files\Symantec2007-10-23 15:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared2007-10-22 02:25 --------- d-----w C:\Program Files\Microsoft Money2007-10-14 21:44 --------- d-----w C:\Program Files\Microsoft Games2007-09-26 02:07 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\PDF reDirect2007-09-26 02:03 --------- d-----w C:\Program Files\PDF reDirect2007-09-18 19:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx cat2007-09-18 19:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl cat2007-09-18 19:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp cat2007-09-18 19:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl inf2007-09-18 19:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx inf2007-09-18 19:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp inf2007-09-18 19:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx sys2007-09-18 19:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl sys2007-09-18 19:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp sys2007-09-06 02:52 --------- d-----w C:\Program Files\Norton AntiVirus2007-09-06 02:48 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\Uniblue2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm dll2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\system32\cdm dll2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\system32\wuapi dll2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt exe2007-07-31 00:19 43,352 ----a-w C:\WINDOWS\system32\wups2 dll2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\system32\wucltui dll2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\system32\wuweb dll2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng dll2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\system32\wups dll2006-05-25 23:35 88,488 ----a-w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\GDIPFONTCACHEV1. DAT2004-04-05 22:33 462,919 ----a-w C:\Documents and Settings\Ryan_Kim_Sullivan\gotomypc exe.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"HTpatch"="C:\WINDOWS\htpatch exe" [2002-10-30 20:40]"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray exe" [2002-06-18 03:01]"STOPzilla"="C:\Program Files\STOPzilla!\Stopzilla exe" [2002-06-20 11:00]"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px exe" [2002-08-20 13:29]"NeroCheck"="C:\WINDOWS\system32\NeroCheck exe" [2001-07-09 02:50]"CTHelper"="CTHELPER. EXE" [2002-11-08 13:46 C:\WINDOWS\system32\cthelper exe]"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 exe" [2003-05-26 22:00]"QuickTime Task"="C:\Program Files\QuickTime\qttask exe" [2004-01-31 19:22]"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil exe" [2003-05-01 18:44]"RoxioDragToDisc"="C:\schedule Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exe" [2003-10-22 20:15]"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exe" [2003-07-15 12:38]"SunJavaUpdateSched"="C:\schedule Files\Java\jre1.6.0_01\bin\jusched exe" [2007-03-14 03:43]"HPDJ Taskbar Utility"="C:\WINDOWS\system32\transfer\drivers\w32x86\3\hpztsb11 exe" [2004-04-06 05:28]"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 exe" [2004-06-06 23:53]"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr exe" [2005-01-12 14:54]"HPHmon06"="C:\WINDOWS\system32\hphmon06 exe" [2004-06-06 23:42]"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE exe" [2002-02-04 22:32]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2 exe" [2005-02-16 23:11]"ccApp"="C:\schedule Files\Common Files\Symantec Shared\ccApp exe" [2007-01-10 00:59]"osCheck"="C:\Program Files\Norton AntiVirus\osCheck exe" [2007-01-14 02:11]"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exe" [2007-03-12 18:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon exe"="C:\WINDOWS\system32\ctfmon exe" [2004-08-04 02:56]"NVIEW"="nview dll" [2002-11-06 20:13 C:\WINDOWS\system32\nview dll]"com codeode cactusspamfilter"="C:\Program Files\Cactus Spam Filter 2.13\cactusspamfilter exe" [2006-04-30 16:27]
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp sysR2 PPCLASS;PPCLASS;C:\WINDOWS\system32\drivers\PPCLASS sysR2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost exe -k netsvcsR3 soma;SOMA Service;C:\WINDOWS\system32\DRIVERS\soma sysR3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\system32\DRIVERS\SonyWBMS. SYSR3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\system32\drivers\yacxgc sysS2 PPSCAN;PPSCAN;C:\WINDOWS\system32\drivers\PPSCAN sysS3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty exe"S3 GearAspiWDM_BackUp;GEARAspiWDM;C:\WINDOWS\system32\drivers\GEARAspiWDM sysS3 RIOUNIV;Rio universal USB driver;C:\WINDOWS\system32\Drivers\RIOUNIV sysS3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS. SYS
((((((((((((((((((((((((((((((((((((((((  Find3M Report  )))))))))))))))))))))))))))))))))))))))))))))))))))).2007-10-26 12:44 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\Roxio2007-10-26 02:26 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. INF2007-10-26 02:26 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1. DLL2007-10-26 02:26 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. SYS2007-10-26 02:26 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT. CAT2007-10-26 02:26 --------- d-----w C:\Program Files\Symantec2007-10-23 15:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared2007-10-22 02:25 --------- d-----w C:\Program Files\Microsoft Money2007-10-14 21:44 --------- d-----w C:\Program Files\Microsoft Games2007-09-26 02:07 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\PDF reDirect2007-09-26 02:03 --------- d-----w C:\Program Files\PDF reDirect2007-09-18 19:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx cat2007-09-18 19:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl cat2007-09-18 19:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp cat2007-09-18 19:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl inf2007-09-18 19:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx inf2007-09-18 19:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp inf2007-09-18 19:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx sys2007-09-18 19:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl sys2007-09-18 19:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp sys2007-09-06 02:52 --------- d-----w C:\Program Files\Norton AntiVirus2007-09-06 02:48 --------- d-----w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\Uniblue2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm dll2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\system32\cdm dll2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\system32\wuapi dll2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt exe2007-07-31 00:19 43,352 ----a-w C:\WINDOWS\system32\wups2 dll2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\system32\wucltui dll2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\system32\wuweb dll2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng dll2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\system32\wups dll2006-05-25 23:35 88,488 ----a-w C:\Documents and Settings\Ryan_Kim_Sullivan\Application Data\GDIPFONTCACHEV1. DAT2004-04-05 22:33 462,919 ----a-w C:\Documents and Settings\Ryan_Kim_Sullivan\gotomypc exe.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"HTpatch"="C:\WINDOWS\htpatch exe" [2002-10-30 20:40]"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray exe" [2002-06-18 03:01]"STOPzilla"="C:\Program Files\STOPzilla!\Stopzilla exe" [2002-06-20 11:00]"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px exe" [2002-08-20 13:29]"NeroCheck"="C:\WINDOWS\system32\NeroCheck exe" [2001-07-09 02:50]"CTHelper"="CTHELPER. EXE" [2002-11-08 13:46 C:\WINDOWS\system32\cthelper exe]"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 exe" [2003-05-26 22:00]"QuickTime Task"="C:\Program Files\QuickTime\qttask exe" [2004-01-31 19:22]"RoxioEngineUtility"="C:\schedule Files\Common Files\Roxio Shared\System\EngUtil exe" [2003-05-01 18:44]"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exe" [2003-10-22 20:15]"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exe" [2003-07-15 12:38]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched exe" [2007-03-14 03:43]"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 exe" [2004-04-06 05:28]"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 exe" [2004-06-06 23:53]"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr exe" [2005-01-12 14:54]"HPHmon06"="C:\WINDOWS\system32\hphmon06 exe" [2004-06-06 23:42]"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE exe" [2002-02-04 22:32]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2 exe" [2005-02-16 23:11]"ccApp"="C:\schedule Files\Common Files\Symantec Shared\ccApp exe" [2007-01-10 00:59]"osCheck"="C:\Program Files\Norton AntiVirus\osCheck exe" [2007-01-14 02:11]"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exe" [2007-03-12 18:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon exe"="C:\WINDOWS\system32\ctfmon exe" [2004-08-04 02:56]"NVIEW"="nview dll" [2002-11-06 20:13 C:\WINDOWS\system32\nview dll]"com codeode cactusspamfilter"="C:\Program Files\Cactus Spam Filter 2.13\cactusspamfilter exe" [2006-04-30 16:27]
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp sysR2 PPCLASS;PPCLASS;C:\WINDOWS\system32\drivers\PPCLASS sysR2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost exe -k netsvcsR3 soma;SOMA Service;C:\WINDOWS\system32\DRIVERS\soma sysR3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\system32\DRIVERS\SonyWBMS. SYSR3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\system32\drivers\yacxgc sysS2 PPSCAN;PPSCAN;C:\WINDOWS\system32\drivers\PPSCAN sysS3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty exe"S3 GearAspiWDM_BackUp;GEARAspiWDM;C:\WINDOWS\system32\drivers\GEARAspiWDM sysS3 RIOUNIV;Rio universal USB driver;C:\WINDOWS\system32\Drivers\RIOUNIV sysS3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS. SYS
Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst exeC:\WINDOWS\Explorer. EXEC:\schedule Files\Common Files\Symantec Shared\AppCore\AppSvc32 exeC:\WINDOWS\system32\spoolsv exeC:\WINDOWS\htpatch exeC:\WINDOWS\System32\ezSP_Px exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXEC:\WINDOWS\system32\ctfmon exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeC:\schedule Files\Common Files\Symantec Shared\ccSvcHst exeC:\WINDOWS\system32\gearsec exeC:\WINDOWS\system32\gearsec exeC:\Program Files\Common Files\Microsoft Shared\VS7correct\mdm exeC:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exeC:\WINDOWS\system32\RioMSC exeC:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exeC:\WINDOWS\System32\tcpsvcs exeC:\WINDOWS\System32\svchost exeC:\Program Files\Java\jre1.6.0_01\bin\jusched exeC:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist exeC:\Program Files\Sony\giga pocket\GPVSvr exeC:\Program Files\HP\hpcoretech\hpcmpmgr exeC:\WINDOWS\system32\hphmon06 exeC:\Program Files\HP\HP Software Update\HPWuSchd2 exeC:\schedule Files\Common Files\Symantec Shared\ccApp exeC:\WINDOWS\System32\MsPMSPSv exeC:\Program Files\Cactus Spam separate 2.13\cactusspamfilter exeC:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeC:\WINDOWS\system32\rundll32 exeC:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeC:\Program Files\sony\giga take\usbsircs exeC:\schedule Files\Sony\VAIO Action Setup\VAServ exeC:\WINDOWS\system32\HPZipm12 exeC:\Program Files\HP\Digital Imaging\bin\hpqgalry exeC:\WINDOWS\system32\wuauclt exeC:\Program Files\turn Micro\HijackThis\HijackThis exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper ocxO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv dllO2 - BHO: BrowserHelper categorise - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\StopzillaBHO dllO4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch exeO4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray exe" /rO4 - HKLM\..\Run: [STOPzilla] C:\schedule Files\STOPzilla!\Stopzilla exe /autorunO4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px exeO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck exeO4 - HKLM\..\Run: [CTHelper] CTHELPER. EXEO4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1. EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [RoxioEngineUtility] "C:\schedule Files\Common Files\Roxio Shared\System\EngUtil exe"O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc exe"O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon exe"O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched exe"O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 exeO4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 exeO4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr exe"O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06 exeO4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE. EXE /AUTORUNO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2 exeO4 - HKLM\..\Run: [ccApp] "C:\schedule Files\Common Files\Symantec Shared\ccApp exe"O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck exe"O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng dll"O4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [NVIEW] rundll32 exe nview dll,nViewLoadHookO4 - HKCU\..\Run: [com codeode cactusspamfilter] "C:\Program Files\Cactus Spam Filter 2.13\cactusspamfilter exe" -minimizedO4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF. EXE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator exe (User 'SYSTEM')O4 - HKUS\. DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF. EXE (User 'Default user')O4 - Global Startup: Giga Pocket Remocon Driver lnk = ?O4 - Global Startup: HP Digital Imaging Monitor lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08 exeO4 - Global Startup: HP Image govern Fast Start lnk = C:\schedule Files\HP\digital imaging\bin\hpqthb08 exeO4 - Global Startup: VAIO Action Setup (Server) lnk = ?O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL. EXE/3000O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-BF4DBB38B8E7} - C:\WINDOWS\Downloaded Program Files\fcplugin dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\schedule Files\Java\jre1.6.0_01\bin\ssv dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\schedule Files\Microsoft Money\System\mnyside dllO9 - Extra add: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO14 - IERESET. INF: START_PAGE_URL=http://www ucs att netO16 - DPF: RaptisoftGameLoader - O16 - DPF: symsupportutil - O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo. CMClass) - O16 - DPF: {0957C19A-D854-482A-A4F9-18856C723D7D} (XNC600NetCam Control) - O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine favor Validation Tool) - O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - O16 - DPF: {9C196458-4145-46AF-8A77-1506878DFECA} (FirstClass® Control) - O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (CSonyPicturesGameDownloaderCtl Object) - O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager. CacheManagerCtrl) - O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - O16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB} (sonyctl sonycm) - O18 - Protocol: fcp - {B3133379-8789-4D3C-9593-C205D7297501} - C:\WINDOWS\Downloaded Program Files\fcplugin dllO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeO23 - Service: Boonty Games - BOONTY - C:\schedule Files\Common Files\BOONTY Shared\Service\Boonty exeO23 - function: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\schedule Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - function: GEARSecurity - GEAR Software - C:\WINDOWS\system32\gearsec exeO23 - Service: GEARSecurity_BackUp - GEAR Software - C:\WINDOWS\system32\gearsec exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT exeO23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc exeO23 - function: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1. EXEO23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst exeO23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12 exeO23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America. Inc. - C:\WINDOWS\system32\RioMSC exeO23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv exeO23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc exeO23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32 exeO23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\schedule Files\Sony\VAIO Media Music Server\SSSvr exeO23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd exeO23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeO23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv exeO23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeO23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exeO23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\giga pocket\GPVSvr exeO23 - function: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd exeO23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework exe
if needed. Because the tools we used to scan the computer as well as tools to delete files and folders are no longer needed they should be removed along with the folders created by these tools.* Click Start then Run* Now type Combofix /u in the runbox and click OK. Notice the space between the X and the /u
This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points. That should have you in good shape. Here is my standard list of simple steps that you can take to reduce the chance of infection in the future. You may have already taken some of these steps and depending on your current security you may not need to implement all of these:1. Visit Windows Update:Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS. Windows Update: 2. Adjust your security settings for ActiveX:Go to Internet Options/Security/Internet touch 'fail level' then OK. Now press "Custom Level."In the ActiveX section set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt' and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.3. Consider installing the following free programs:a. SpywareBlaster: (Not recommended for Vista)Tutorial here: b. SpywareGuard:Tutorial here: Periodically check for updates in both programs.4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date. Note: Zone Alarm Firewall (by Checkpoint) has a free version 5. You might consider installing Mozilla / Firefox.6. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware still expose you to risks because of the very nature of the P2P file sharing process. By default most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network change state access to a shared directory on your computer. The reason for this is simple. register sharing relies on its members giving and gaining unfettered access to computers across the P2P communicate. However this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually include a disguised threat. Many very malicious worms and trojans such as the Storm Worm target and spread across P2P files sharing networks because of their knownvulnerabilities.7. Before using or purchasing any Spyware/Malware protection/removal program always check the following Rogue/Suspect Spyware Lists.8. If you have not already done so you might want to lay CCleaner and run it in each user's profile: ** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version or download the toolbar-free versions (Slim or Basic) when given the option for those.9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05 you should update to 6.05 preferably version 8.1.0 or higher. It would be best to remove prior versions before updating to a new version. If you need additional assistance the Adobe forums are here: 10.
You can go here to download the latest version of. Scroll down to where it says "Java Runtime Environment (JRE) 6u3 allows end-users to run Java applications". Click the link to transfer the Windows (Offline Installation) package: Save it do not run it. When the download is complete close the browser. Remove all prior versions using Add/Remove Programs and delete the Java folder in Program Files. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u3-windows-i586-p exe to install the newest version if needed. Reboot.11. Practice Safe Surfing with with by Trendmicro. TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the summon currently open is safe unsafe trusted or unrated or whether it contains unwanted content. The following color codes are used by TrendProtect to indicate the safety of each site.
Forex Groups - Tips on Trading
Related article:
http://www.dellcommunity.com/supportforums/board/message?board.id=si_hijack&message.id=70296#M70296
comments | Add comment | Report as Spam
|