The computer has a screen that pops up every 45 seconds or so for less than a second. Any help is appreciated. Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:35:36 PM, on 7/15/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.ex
e
C:\Windows\system32\tasken
g.exe
C:\Windows\Explorer.EXE
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\Intel\IntelDH\CCU\CC
U_TrayIcon
.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Su
pport\Inte
lHCTAgent.
exe
C:\Windows\System32\rundll
32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\Movielink\MovielinkM
anager\Mov
ielink User.exe
C:\Program Files\McAfee.com\Agent\mca
gent.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\DellSupport\DSAgnt.e
xe
C:\Windows\ehome\ehtray.ex
e
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\ehome\ehmsas.ex
e
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Intel\IntelDH\CCU\CC
U_Engine.e
xe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\PROGRA~1\mcafee\msc\mcu
imgr.exe
G:\utilities\HiJackThis.ex
e
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
A578C2EBDC
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lperShim.d
ll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F
45BD3D40CF
4} - c:\PROGRA~1\mcafee\msk\mca
pbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - c:\Program Files\Java\jre1.6.0\bin\ss
v.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan\scr
iptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
07C3DB8F77
7} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.
dll,nvsvcS
tart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CC
U_TrayIcon
.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Su
pport\Inte
lHCTAgent.
exe" /startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALaunc
her.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTA
L~1\UPDATE
~1\ISUSPM.
exe -startup
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [LoadMSvcmm] "C:\Program Files\Movielink\MovielinkM
anager\Mov
ielink User.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mca
gent.exe /runkey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsc
a.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.e
xe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.ex
e
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - c:\Program Files\Java\jre1.6.0\bin\np
jpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - c:\Program Files\Java\jre1.6.0\bin\np
jpi160.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\Offic
e12\REFIEB
AR.DLL
O13 - Gopher Prefix:
O16 - DPF: {87587503-20F0-4FF5-8DA3-0
107C4C03FD
C} (vmLaunch Class) -
http://downloads.comcast.net/videomail/vmLauncher.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-0
4C2F616BCA
7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cabO20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
1\GOEC62~1
.DLL
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\Al
ertService
.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxco
ms.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\Ad
pPlugins\D
QLWinServi
ce.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_Help
erSvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceAT
L.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.e
xe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcods.ex
e
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
e\mcproxy\
mcproxy.ex
e
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
O23 - Service: Movielink Core Service - Movielink LLC - C:\PROGRA~1\MOVIEL~1\MOVIE
L~1\MOVIEL
~1.EXE
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.ex
e
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.
exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter
) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVER
S\xaudio.e
xe
--
End of file - 9673 bytes
ComboFix 08-07-13.6 - Chuck 2008-07-15 21:36:45.2 - NTFSx86
Microsoft® Windows Vista" Home Premium 6.0.6000.0.1252.1.1033.18.
356 [GMT -4:00]
Running from: G:\utilities\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 ))))))))))))))))))))))))))
)))))
.
2008-07-15 07:07 . 2008-07-15 07:07 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-15 07:04 . 2008-07-15 07:06 <DIR> d-------- C:\Users\All Users\Adobe
2008-07-15 07:04 . 2008-07-15 07:04 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-14 08:04 . 2008-07-15 07:01 <DIR> d-------- C:\Users\All Users\NOS
2008-07-14 08:04 . 2008-07-15 07:01 <DIR> d-------- C:\ProgramData\NOS
2008-07-14 08:04 . 2008-07-14 08:04 <DIR> d-------- C:\Program Files\NOS
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2008-06-28 00:46 --------- d-----w C:\Program Files\McAfee
2008-05-31 01:37 --------- d-----w C:\ProgramData\Roxio
2008-05-31 01:37 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-05-22 02:35 --------- d-----w C:\Program Files\iTunes
2008-05-22 02:35 --------- d-----w C:\Program Files\iPod
2008-05-22 02:33 --------- d-----w C:\Program Files\QuickTime
2008-05-22 02:27 --------- d-----w C:\Program Files\Apple Software Update
2007-08-29 07:10 174 --sha-w C:\Program Files\desktop.ini
2007-11-22 19:12 16,384 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\Mi
crosoft\Wi
ndows\Hist
ory\Histor
y.IE5\inde
x.dat
2007-11-22 19:12 32,768 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\Mi
crosoft\Wi
ndows\Temp
orary Internet Files\Content.IE5\index.da
t
2007-11-22 19:12 16,384 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Roaming\
Microsoft\
Windows\Co
okies\inde
x.dat
.
((((((((((((((((((((((((((
((( snapshot@2008-07-15_21.22.
22.62 ))))))))))))))))))))))))))
))))))))))
)))))
.
- 2008-07-16 00:52:58 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-07-16 01:26:05 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-07-16 00:52:59 2,048 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\la
stalive0.d
at
+ 2008-07-16 01:26:06 2,048 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\la
stalive0.d
at
- 2008-07-16 00:52:59 2,048 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\la
stalive1.d
at
+ 2008-07-16 01:26:06 2,048 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\AppDat
a\Local\la
stalive1.d
at
- 2008-07-16 00:54:35 262,144 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\NTUSER
.DAT
+ 2008-07-16 01:27:00 262,144 --sha-w C:\Windows\ServiceProfiles
\LocalServ
ice\NTUSER
.DAT
- 2008-07-16 00:54:30 262,144 --sha-w C:\Windows\ServiceProfiles
\NetworkSe
rvice\NTUS
ER.DAT
+ 2008-07-16 01:26:55 262,144 --sha-w C:\Windows\ServiceProfiles
\NetworkSe
rvice\NTUS
ER.DAT
- 2008-07-16 00:53:13 16,384 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Local\M
icrosoft\W
indows\His
tory\Histo
ry.IE5\ind
ex.dat
+ 2008-07-16 01:26:18 16,384 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Local\M
icrosoft\W
indows\His
tory\Histo
ry.IE5\ind
ex.dat
- 2008-07-16 00:53:13 32,768 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Local\M
icrosoft\W
indows\Tem
porary Internet Files\Content.IE5\index.da
t
+ 2008-07-16 01:26:18 32,768 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Local\M
icrosoft\W
indows\Tem
porary Internet Files\Content.IE5\index.da
t
- 2008-07-16 00:53:13 32,768 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Roaming
\Microsoft
\Windows\C
ookies\ind
ex.dat
+ 2008-07-16 01:26:18 32,768 --sha-w C:\Windows\System32\config
\systempro
file\AppDa
ta\Roaming
\Microsoft
\Windows\C
ookies\ind
ex.dat
- 2008-07-16 00:55:30 8,064 ----a-w C:\Windows\System32\WDI\{8
6432a0b-3c
7d-4ddf-a8
9c-172faa9
0485d}\S-1
-5-21-4573
97336-2862
001262-642
535030-100
1_UserData
.bin
+ 2008-07-16 01:28:12 8,064 ----a-w C:\Windows\System32\WDI\{8
6432a0b-3c
7d-4ddf-a8
9c-172faa9
0485d}\S-1
-5-21-4573
97336-2862
001262-642
535030-100
1_UserData
.bin
- 2008-07-16 00:55:30 60,118 ----a-w C:\Windows\System32\WDI\Bo
otPerforma
nceDiagnos
tics_Syste
mData.bin
+ 2008-07-16 01:28:11 60,204 ----a-w C:\Windows\System32\WDI\Bo
otPerforma
nceDiagnos
tics_Syste
mData.bin
- 2008-07-05 13:06:07 42,260 ----a-w C:\Windows\System32\WDI\Sh
utdownPerf
ormanceDia
gnostics_S
ystemData.
bin
+ 2008-07-16 01:28:06 42,422 ----a-w C:\Windows\System32\WDI\Sh
utdownPerf
ormanceDia
gnostics_S
ystemData.
bin
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.e
xe" [2006-11-12 02:19 446976]
"ehTray.exe"="C:\Windows\e
home\ehTra
y.exe" [2006-11-02 08:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 08:36 201728]
"DellSupportCenter"="C:\Pr
ogram Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"NvSvc"="C:\Windows\system
32\nvsvc.d
ll" [2006-12-19 18:12 90191]
"NvCplDaemon"="C:\Windows\
system32\N
vCpl.dll" [2006-12-19 18:11 7766016]
"NvMediaCenter"="C:\Window
s\system32
\NvMcTray.
dll" [2006-12-19 18:12 81920]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 12:39 151552]
"ISUSScheduler"="C:\Progra
m Files\Common Files\InstallShield\Update
Service\is
sch.exe" [2006-10-03 11:37 81920]
"CCUTRAYICON"="C:\Program Files\Intel\IntelDH\CCU\CC
U_TrayIcon
.exe" [2006-11-18 07:01 182744]
"NMSSupport"="C:\Program Files\Common Files\Intel\IntelDH\NMS\Su
pport\Inte
lHCTAgent.
exe" [2006-09-26 10:56 423424]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-26 00:11 1838592]
"ECenter"="c:\dell\E-Cente
r\EULALaun
cher.exe" [2006-11-17 17:19 17920]
"ISUSPM Startup"="C:\PROGRA~1\COMM
ON~1\INSTA
L~1\UPDATE
~1\ISUSPM.
exe" [2006-10-03 11:35 221184]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-11-03 21:04 291720]
"MemoryCardManager"="C:\Pr
ogram Files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 21:04 304008]
"FaxCenterServer"="C:\Prog
ram Files\Dell PC Fax\fm3032.exe" [2006-11-03 21:09 312200]
"LoadMSvcmm"="C:\Program Files\Movielink\MovielinkM
anager\Mov
ielink User.exe" [2006-12-01 18:09 116320]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mca
gent.exe" [2007-08-04 02:33 582992]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsc
a.exe" [2007-11-15 10:24 16384]
"DellSupportCenter"="C:\Pr
ogram Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe
" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program
Files\iTunes\iTunesHelper.
exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SigmatelSysTrayApp"="sttr
ay.exe" [2007-02-08 01:16 303104 C:\Windows\sttray.exe]
C:\ProgramData\Microsoft\W
indows\Sta
rt Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-03-20 19:12:09 45056]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1
\Google\GO
OGLE~1\GOE
C62~1.DLL
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\drivers3
2]
"VIDC.NSVI"= nsvideo.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\McAfeeAn
tiSpyware]
"DisableMonitoring"=dword:
00000001
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\McAfeeAn
tiVirus]
"DisableMonitoring"=dword:
00000001
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\McAfeeFi
rewall]
"DisableMonitoring"=dword:
00000001
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
DomainProf
ile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
FirewallRu
les]
"{4532933B-18A3-4026-8FDF-
CC1AAA7FB3
FD}"= UDP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:S
PCM
"{2D6BED86-2DAA-4CAC-8CF3-
7EB76297C2
A0}"= TCP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:S
PCM
"{DAF529CE-548B-4AC9-A8A5-
7BE686B740
3C}"= UDP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{ABD0B61C-DB1E-4C4A-8837-
BF7CF9669F
DB}"= TCP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{49C54BED-8D72-40A6-BC7C-
1ED429E4F1
8F}"= UDP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
:Intel(R) Viiv(TM) Media Server
"{DDC411F7-33D5-4C9B-B6C3-
8EBE6214D8
F1}"= TCP:Profile=Private|Profil
e=Public:L
ocalSubnet
:LocalSubn
et|C:\Prog
ram Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
:Intel(R) Viiv(TM) Media Server
"{41BE193F-C789-49AA-BFCF-
03F7D05F25
9B}"= TCP:Profile=Private|Profil
e=Public|9
442:127.0.
0.1:Intel(
R) Viiv(TM) Media Server Discovery
"{FEB82D9D-95D9-41D5-807B-
2402AECE7A
B7}"= TCP:Profile=Private|Profil
e=Public|1
900:LocalS
ubnet:Loca
lSubnet:In
tel(R) Viiv(TM) Media Server UPnP Discovery
"{81C3971B-F6B0-4A7B-AAEA-
121F9400FF
E9}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EX
E:Microsof
t Office OneNote
"{78B5170E-93B7-4E72-9E76-
D70373BA40
96}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EX
E:Microsof
t Office OneNote
"{9146C4E6-4937-46ED-BEC3-
A670BADF4A
6B}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.e
xe:McAfee Network Agent
"{72B5C1D7-33DE-4264-A945-
8683629230
39}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.e
xe:McAfee Network Agent
"{6886E048-85F3-4B9D-A134-
0C7968D3DE
DE}"= UDP:C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe:Yaho
o! Messenger
"{C4406090-DDFD-4A83-ACE6-
73D135F9C1
54}"= TCP:C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe:Yaho
o! Messenger
"{5B525DA0-AA3C-4BB6-A267-
D5ED4D2891
99}"= UDP:C:\Program Files\Yahoo!\Messenger\YSe
rver.exe:Y
ahoo! FT Server
"{D6F86E51-01C8-4E09-9C74-
2127CBA543
E1}"= TCP:C:\Program Files\Yahoo!\Messenger\YSe
rver.exe:Y
ahoo! FT Server
"{0E657B4A-B34E-42F7-8251-
B1B70697E6
C3}"= C:\Program Files\MSN Messenger\livecall.exe:Win
dows Live Messenger 8.1 (Phone)
"{E3F5CE7A-F688-41A3-804E-
F770D6BA08
BF}"= UDP:C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{DA91EDA4-12F4-4761-8F7D-
305701FA76
27}"= TCP:C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{684510CB-AF3E-41DD-9E4A-
05B34B2310
19}"= UDP:C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{F3FF8FD5-3D66-4397-82A2-
AFE9843E38
C6}"= TCP:C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{A7AC2E6B-C30B-4106-9CDD-
14E34FC926
BB}"= UDP:C:\Windows\System32\dl
cxcoms.exe
:Lexmark Communications System
"{8261685F-36B4-4DF1-8B91-
7A2EDEE2EE
5F}"= TCP:C:\Windows\System32\dl
cxcoms.exe
:Lexmark Communications System
"{D9C066D6-C3A1-433A-90C7-
9613255A4D
4A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iT
unes
"{AECC1D77-2DD7-49C7-95C6-
88E6D5CBA2
34}"= TCP:C:\Program Files\iTunes\iTunes.exe:iT
unes
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
PublicProf
ile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
Restricted
Services\S
tatic\Syst
em]
"DFSR-1"= RPort=5722|UDP:%SystemRoot
%\system32
\svchost.e
xe|Svc=DFS
R:Allow inbound TCP traffic|
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
StandardPr
ofile]
"EnableFirewall"= 0 (0x0)
R2 dlcx_device;dlcx_device;C:
\Windows\s
ystem32\dl
cxcoms.exe
[2006-11-03 21:07]
R2 DQLWinService;DQLWinServic
e;C:\Progr
am Files\Common Files\Intel\IntelDH\NMS\Ad
pPlugins\D
QLWinServi
ce.exe [2006-10-29 09:03]
R2 nmsgopro;GoProto Protocol Driver for NMS;C:\Windows\system32\DR
IVERS\nmsg
opro.sys [2006-09-27 16:37]
R2 nmsunidr;UniDriver for NMS;C:\Windows\system32\DR
IVERS\nmsu
nidr.sys [2006-10-19 15:49]
R3 IntelDH;IntelDH Driver;C:\Windows\system32
\Drivers\I
ntelDH.sys
[2007-03-20 19:24]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_Help
erSvc.exe [2008-06-26 10:24]
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{05
508f92-526
1-11dd-a0e
5-0019d13d
b85b}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-15 05:31:58 C:\Windows\Tasks\McDefragT
ask.job"
- c:\PROGRA~1\mcafee\mqc\QcC
onsol.exe'
"2008-07-01 05:00:07 C:\Windows\Tasks\McQcTask.
job"
- c:\PROGRA~1\mcafee\mqc\QcC
onsol.exe
"2008-07-15 07:43:13 C:\Windows\Tasks\User_Feed
_Synchroni
zation-{98
395E65-126
7-4413-80B
9-8207F623
232A}.job"
- C:\Windows\system32\msfeed
ssync.exe
.
**************************
**********
**********
**********
**********
********
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-15 21:42:13
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
.
Completion time: 2008-07-15 21:44:26
ComboFix-quarantined-files
.txt 2008-07-16 01:44:13
ComboFix2.txt 2008-07-16 01:23:10
Pre-Run: 219,768,905,728 bytes free
Post-Run: 219,739,410,432 bytes free
166 --- E O F --- 2008-07-16 00:51:14