hello thank you for the assistance.
have deleted and renewed java.
have removed limewire (do not need it).
including 2 logs as requested, combofix and hijack this.
ComboFix 07-12-02.6 - Grumpy 2007-12-04 21:57:51.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.100 [GMT 1:00]
Running from: E:\exe files\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Grumpy\AppData\Local\qelfjd_navfx.dat
C:\Users\Grumpy\AppData\Local\rukbcc.dat
C:\Users\Grumpy\AppData\Local\rukbcc.exe
c:\Users\Grumpy\AppData\Local\rukbcc_nav.dat
C:\Users\Grumpy\AppData\Local\rukbcc_navps.dat
C:\Users\Grumpy\AppData\Roaming\inst.exe
C:\Windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-04 21:49 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
2007-12-04 21:44 . 2007-12-04 21:48 <DIR> d-------- C:\Program Files\Java
2007-12-04 21:43 . 2007-12-04 21:43 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-03 13:54 . 2007-12-03 13:54 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-03 13:16 . 2007-12-03 13:16 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-03 13:15 . 2007-12-03 13:15 <DIR> d-------- C:\Users\All Users\Lavasoft
2007-12-03 13:15 . 2007-12-03 13:15 <DIR> d-------- C:\ProgramData\Lavasoft
2007-12-03 13:07 . 2007-12-03 13:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-03 10:19 . 2007-12-03 10:19 <DIR> d-------- C:\Users\All Users\Tarma Installer
2007-12-03 10:19 . 2007-12-03 10:19 <DIR> d-------- C:\ProgramData\Tarma Installer
2007-12-03 10:19 . 2007-12-03 10:20 <DIR> d-------- C:\Program Files\Bulk Rename Utility
2007-12-01 11:04 . 2007-12-01 11:05 148,086,416 --a------ C:\Windows\MEMORY.DMP
2007-11-29 21:40 . 2007-11-29 21:40 268 --ah----- C:\sqmdata00.sqm
2007-11-29 21:40 . 2007-11-29 21:40 244 --ah----- C:\sqmnoopt00.sqm
2007-11-28 19:18 . 2007-11-29 10:36 <DIR> d-------- C:\Users\Grumpy\AppData\Roaming\Lavasoft
2007-11-28 15:16 . 2007-11-28 18:38 <DIR> d-------- C:\Users\Grumpy\AppData\Roaming\Uniblue
2007-11-28 15:16 . 2007-11-28 15:16 <DIR> d-------- C:\Users\All Users\Uniblue
2007-11-28 15:16 . 2007-11-28 15:16 <DIR> d-------- C:\ProgramData\Uniblue
2007-11-27 20:47 . 2007-11-27 20:50 <DIR> d-------- C:\Program Files\MagicDisc
2007-11-27 20:47 . 2007-09-05 01:46 92,544 --a------ C:\Windows\System32\drivers\mcdbus.sys
2007-11-23 18:06 . 2007-11-23 18:06 <DIR> d-------- C:\Users\All Users\Office Genuine Advantage
2007-11-23 18:06 . 2007-11-23 18:06 <DIR> d-------- C:\ProgramData\Office Genuine Advantage
2007-11-21 17:00 . 2007-11-21 17:00 <DIR> d-------- C:\Program Files\Frameworkx
2007-11-21 13:56 . 2007-11-21 13:56 <DIR> d-------- C:\Users\All Users\MSScanAppDataDir
2007-11-21 13:56 . 2007-11-21 13:56 <DIR> d-------- C:\ProgramData\MSScanAppDataDir
2007-11-16 22:15 . 2007-11-16 22:15 <DIR> d-------- C:\Program Files\InterMute
2007-11-16 17:25 . 2007-11-16 17:25 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2007-11-16 17:25 . 2007-11-16 17:25 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2007-11-16 17:24 . 2007-11-27 16:53 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-15 15:17 . 2007-11-15 17:34 <DIR> d-------- C:\Users\All Users\STOPzilla!
2007-11-15 15:17 . 2007-11-15 17:34 <DIR> d-------- C:\ProgramData\STOPzilla!
2007-11-14 15:31 . 2007-11-14 15:31 <DIR> d-------- C:\Users\All Users\vsosdk
2007-11-14 15:31 . 2007-11-14 15:31 <DIR> d-------- C:\ProgramData\vsosdk
2007-11-14 13:15 . 2007-11-17 00:01 <DIR> d-------- C:\Users\Grumpy\AppData\Roaming\Vso
2007-11-14 13:15 . 2007-11-14 13:15 47,360 --a------ C:\Windows\System32\drivers\pcouffin.sys
2007-11-14 13:15 . 2007-11-14 13:15 47,360 --a------ C:\Users\Grumpy\AppData\Roaming\pcouffin.sys
2007-11-14 13:14 . 2007-11-14 13:14 <DIR> d-------- C:\Program Files\VSO
2007-11-14 13:14 . 2006-09-29 11:24 217,127 --a------ C:\Windows\System32\drv43260.dll
2007-11-14 13:14 . 2006-09-29 11:25 208,935 --a------ C:\Windows\System32\drv33260.dll
2007-11-14 13:14 . 2006-09-29 11:26 176,165 --a------ C:\Windows\System32\drv23260.dll
2007-11-14 09:02 . 2007-11-14 09:02 185 --a------ C:\Windows\System32\msblcd32.dll
2007-11-14 09:01 . 2007-11-14 09:01 647,872 --a------ C:\Windows\System32\MSCOMCT2.OCX
2007-11-14 09:01 . 2007-11-14 09:01 165,680 --a------ C:\Windows\System32\AUTMGR32.EXE
2007-11-14 09:01 . 2007-11-14 09:01 140,488 --a------ C:\Windows\System32\Comdlg32.ocx
2007-11-14 09:01 . 2007-11-14 09:01 140,288 --a------ C:\Windows\System32\AUTPRX32.DLL
2007-11-14 09:01 . 2007-11-14 09:01 109,248 --a------ C:\Windows\System32\Mswinsck.ocx
2007-11-14 09:01 . 2007-11-14 09:01 61,440 --a------ C:\Windows\System32\RACMGR32.EXE
2007-11-14 09:00 . 2007-11-14 09:00 <DIR> d-------- C:\Program Files\AF Uninstalls
2007-11-12 08:56 . 2006-11-02 10:45 774,144 -r-hs---- C:\Windows\System32\dgilpd.exe
2007-11-12 08:14 . 2006-11-02 10:45 774,144 -r-hs---- C:\Windows\System32\nuyzpj.exe
2007-11-12 08:14 . 2006-11-02 10:45 774,144 -r-hs---- C:\Windows\System32\ihfrvz.exe
2007-11-10 22:14 . 2007-11-10 22:14 <DIR> d-------- C:\Windows\Sun
2007-11-10 03:15 . 2006-11-02 10:45 774,144 -r-hs---- C:\Windows\System32\mibnjo.exe
2007-11-10 02:15 . 2007-11-10 15:57 <DIR> d-------- C:\Users\Grumpy\Shared
2007-11-10 02:15 . 2007-11-10 16:09 <DIR> d-------- C:\Users\Grumpy\Incomplete
2007-11-10 02:13 . 2007-12-01 11:45 <DIR> d-------- C:\Users\Grumpy\AppData\Roaming\LimeWire
2007-11-08 16:42 . 2007-11-08 16:42 <DIR> d-------- C:\Program Files\M3U Creator
2007-11-06 23:31 . 2007-11-29 09:13 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2007-11-06 23:31 . 2007-11-29 09:13 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2007-11-06 18:14 . 2007-11-06 18:14 <DIR> d-------- C:\Program Files\MediaInfo
2007-11-06 18:09 . 2007-11-06 18:09 <DIR> d-------- C:\Users\All Users\eMule
2007-11-06 18:09 . 2007-11-06 18:09 <DIR> d-------- C:\ProgramData\eMule
2007-11-06 17:15 . 2007-11-06 17:15 <DIR> d-------- C:\Program Files\Torrent Harvester
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 21:00 --------- d-----w C:\Users\Grumpy\AppData\Roaming\BitTorrent DNA
2007-12-04 19:50 --------- d-----w C:\ProgramData\Symantec
2007-12-04 19:45 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-04 19:31 --------- d-----w C:\Program Files\Lx_cats
2007-12-02 14:11 --------- d-----w C:\Users\Grumpy\AppData\Roaming\BitTorrent
2007-12-02 11:56 --------- d-----w C:\Program Files\SpywareBlaster
2007-11-21 13:21 --------- d-----w C:\Program Files\Common Files\Real
2007-11-21 08:23 --------- d-----w C:\Program Files\TOSHIBA
2007-11-21 08:20 --------- d-----w C:\ProgramData\Ulead Systems
2007-11-21 08:20 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2007-11-21 08:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 17:45 --------- d-----w C:\Program Files\Norton Internet Security
2007-11-12 07:57 --------- d---a-w C:\ProgramData\TEMP
2007-11-10 00:38 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-10 00:38 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-10 00:38 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-10 00:38 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-10 00:38 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-10 00:38 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-11-10 00:38 3,471,032 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-11-10 00:38 299,008 ----a-w C:\Windows\System32\wlansec.dll
2007-11-10 00:38 289,280 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-10 00:38 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-11-10 00:38 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-10 00:38 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-10 00:38 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-11-10 00:38 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-10 00:38 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-10 00:38 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-11-09 15:35 --------- d-----w C:\Users\Grumpy\AppData\Roaming\TOSHIBA
2007-11-03 18:17 --------- d-----w C:\Users\Grumpy\AppData\Roaming\Nero
2007-11-03 18:11 --------- d-----w C:\Program Files\Common Files\Nero
2007-11-03 18:06 --------- d-----w C:\ProgramData\Nero
2007-11-03 18:06 --------- d-----w C:\Program Files\Nero
2007-11-03 17:06 --------- d-----w C:\Program Files\CCleaner
2007-10-28 06:58 --------- d-----w C:\ProgramData\Cadsoft
2007-10-28 06:54 --------- d-----w C:\Program Files\Common Files\Cadsoft
2007-10-28 06:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-26 12:58 --------- d-----w C:\Program Files\ABBYY FineReader 6.0 Sprint
2007-10-23 11:47 --------- d-----w C:\Program Files\LizardTech
2007-10-20 19:44 --------- d-----w C:\Program Files\Microsoft.NET
2007-10-20 19:44 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-10-20 19:15 --------- d-----w C:\Program Files\Google
2007-10-13 00:35 --------- d-----w C:\Program Files\Wise Registry Cleaner
2007-10-12 23:27 --------- d-----w C:\Users\Grumpy\AppData\Roaming\PeerNetworking
2007-10-12 20:45 --------- d-----w C:\Program Files\MSN Messenger
2007-10-10 19:09 --------- d-----w C:\Program Files\Windows Mail
2007-10-10 17:29 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-10 17:29 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-10 17:29 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-10 17:28 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 17:14 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-10-10 17:14 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-10-10 17:14 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-10-10 17:07 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-10 17:07 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 17:07 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-10-06 08:09 --------- d-----w C:\Program Files\BitTorrent
2007-10-06 06:38 --------- d-----w C:\Users\Grumpy\AppData\Roaming\Talkback
2007-10-05 11:26 --------- d-----w C:\ProgramData\Ezprint
2007-10-05 11:26 --------- d-----w C:\Program Files\Lexmark 2300 Series
2007-09-25 18:37 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2007-09-25 18:37 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2007-09-25 18:37 39,936 ----a-w C:\Windows\System32\slcinst.dll
2007-09-25 18:37 351,232 ----a-w C:\Windows\System32\SLUI.exe
2007-09-25 18:37 33,280 ----a-w C:\Windows\System32\slwmi.dll
2007-09-25 18:37 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2007-09-25 18:37 223,232 ----a-w C:\Windows\System32\SLC.dll
2007-09-25 18:37 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2007-09-25 18:37 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2007-09-20 08:59 972,072 ----a-w C:\Windows\UNRecode.exe
2007-09-20 08:55 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2007-09-14 06:56 174 --sha-w C:\Program Files\desktop.ini
2007-09-14 06:47 88,576 ----a-w C:\Windows\System32\avifil32.dll
2007-09-14 06:47 82,944 ----a-w C:\Windows\System32\mciavi32.dll
2007-09-14 06:47 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr
2007-09-14 06:47 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll
2007-09-14 06:47 69,632 ----a-w C:\Windows\System32\sendmail.dll
2007-09-14 06:47 65,024 ----a-w C:\Windows\System32\avicap32.dll
2007-09-14 06:47 61,440 ----a-w C:\Windows\System32\ntprint.exe
2007-09-14 06:47 31,232 ----a-w C:\Windows\System32\msvidc32.dll
2007-09-14 06:47 269,824 ----a-w C:\Windows\System32\schannel.dll
2007-09-14 06:47 220,160 ----a-w C:\Windows\System32\ntprint.dll
2007-09-14 06:47 123,904 ----a-w C:\Windows\System32\msvfw32.dll
2007-09-14 06:47 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll
2007-09-14 06:47 12,800 ----a-w C:\Windows\System32\msrle32.dll
2007-09-14 06:47 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll
2007-09-14 06:47 1,984,512 ----a-w C:\Windows\System32\authui.dll
2007-09-12 06:49 87,040 ----a-w C:\Windows\System32\msoert2.dll
2007-09-12 06:49 8,192 ----a-w C:\Windows\System32\riched32.dll
2007-09-12 06:49 77,824 ----a-w C:\Windows\System32\rascfg.dll
2007-09-12 06:49 694,784 ----a-w C:\Windows\System32\localspl.dll
2007-09-12 06:49 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2007-09-12 06:49 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2007-09-12 06:49 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2007-09-12 06:49 36,864 ----a-w C:\Windows\System32\cdd.dll
2007-09-12 06:49 33,280 ----a-w C:\Windows\System32\traffic.dll
2007-09-12 06:49 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2007-09-12 06:49 286,208 ----a-w C:\Windows\System32\ipnathlp.dll
2007-09-12 06:49 22,016 ----a-w C:\Windows\System32\rasser.dll
2006-11-02 09:45 774,144 --sh--r C:\Windows\System32\dgilpd.exe
2006-11-02 09:45 774,144 --sh--r C:\Windows\System32\ihfrvz.exe
2006-11-02 09:45 774,144 --sh--r C:\Windows\System32\mibnjo.exe
2006-11-02 09:45 774,144 --sh--r C:\Windows\System32\nuyzpj.exe
2006-11-02 09:45 774,144 --sh--r C:\Windows\System32\ucpruc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="TOSCDSPD.EXE" []
"BitTorrent DNA"="C:\Users\Grumpy\Program Files\BitTorrent_DNA\dna.exe" [2007-10-08 05:03]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 15:35]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:34]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"rukbcc"="c:\users\grumpy\appdata\local\rukbcc.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-05-25 07:48]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-13 15:19]
"NDSTray.exe"="NDSTray.exe" []
"Toshiba Registration"="C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 12:05]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-05 03:05]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"LXCGCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2007-02-22 04:20]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2007-04-29 21:55]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2007-04-29 21:57]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-08-24 18:54]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-08-24 18:54]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-08-24 18:54]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"PWRISOVM.EXE"="E:\power iso\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Users\Grumpy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2007-11-27 20:47:57]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071127.002\IDSvix86.sys
R2 ASLDRService;ASLDR Service;C:\Program Files\ATK Hotkey\ASLDRSrv.exe
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
R2 TNaviSrv;TOSHIBA Navi Support Service;C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService REG_MULTI_SZ nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 08:08:34 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Grumpy.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2007-11-07 14:56:11 C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-04 22:04:01
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 22:05:04
.
--- E O F ---
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:08:58, on 04/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
E:\power iso\PowerISO\PWRISOVM.EXE
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Users\Grumpy\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://uk.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: (no name) - {4B7B69EB-A00F-4FCD-B601-ACCBB86ED528} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] E:\power iso\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Grumpy\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} -
http://rover.ebay.com/rover/1/710-44557-9400-3/4 (file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} -
http://www.amazon.co.uk/exec/obidos/redire...1&site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewido.net/ewidoOnlineScan.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {EF58E341-49C3-4156-A3C4-5FFCA7C1EAB7} (EURAS_Portal.Gateway) -
http://www.euras.com/vista2/euras.CABO17 - HKLM\System\CCS\Services\Tcpip\..\{2A7BE3E8-4D6D-4BE2-AA8E-3C39E31EE1B8}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A7BE3E8-4D6D-4BE2-AA8E-3C39E31EE1B8}: NameServer = 80.58.61.250,80.58.61.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxcg_device - - C:\Windows\system32\lxcgcoms.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
--
End of file - 9990 bytes