Karl`s PC Help Forums Last active: Never
Not logged in [Login ]
Go To Bottom

In memory of Karl Davis, founder of this board, who made his final journey 12th June 2007

Printable Version | Subscribe | Add to Favourites   Post new thread Poll:
Author: Subject: Homepage Taken Over
Mick Johnson
Custom User Title
*******




Posts: 698
Registered: 3-12-2003
Location: Staffordshire
Theme: KF Blue
Member Is Offline

Mood: No Mood

[*] Post 311242 posted on 7-12-2007 at 14:24 Reply With Quote
Homepage Taken Over



Yes my homepage has been taken over by a Viagra selling site so before I am tempted to order some can someone tell me how to get rid of it.

I have a HJT log and think I see what it is...is it

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

and.......

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

If it is then I have 'fixed it' but it's still there, unless I should of re-booted.

Logfile of HijackThis v1.99.1
Scan saved at 14:15:54, on 07/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O6 "USB001" /M "Stylus C62"
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB002" /M "Stylus Photo R1800"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ColorVisionStartup.lnk = C:\Program Files\ColorVision\Utility\ColorVisionStartup.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194734114390
O17 - HKLM\System\CCS\Services\Tcpip\..\{7821B753-6BD5-4342-A973-57A764C586A2}: NameServer = 212.139.132.37,212.139.132.36
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
View User's Profile View All Posts By User
Mick Johnson
Custom User Title
*******




Posts: 698
Registered: 3-12-2003
Location: Staffordshire
Theme: KF Blue
Member Is Offline

Mood: No Mood

[*] Post 311243 posted on 7-12-2007 at 15:44 Reply With Quote


I have also done a Combo log just in case 'Pancake' appears.

*note to Pancake*
See Dreamweaver post below for "unscrolling text"


ComboFix 07-12-07.3 - Mick 2007-12-07 14:57:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1457 [GMT 0:00]
Running from: C:\Documents and Settings\Mick\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.

2007-12-06 23:02 . 2007-12-06 23:11 <DIR> d-------- C:\Program Files\httphotos
2007-12-06 23:02 . 2007-12-06 23:10 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\httphotos
2007-12-06 08:34 . 2007-12-06 08:34 <DIR> d-------- C:\WINDOWS\LastGood
2007-12-06 08:34 . 2004-09-30 05:06 79,686 --a------ C:\WINDOWS\system32\E_FLM9LE.DLL
2007-12-06 08:34 . 2003-05-21 02:27 64,000 --a------ C:\WINDOWS\system32\E_FBCB9LE.DLL
2007-12-06 08:34 . 2004-09-10 20:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2007-12-06 08:34 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\E_FBCH9LE.DLL
2007-12-02 09:49 . 2007-12-02 10:11 <DIR> d-------- C:\Program Files\Bonjour
2007-12-02 09:43 . 2007-12-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-12-02 09:43 . 2007-12-02 10:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-11-29 19:50 . 2007-11-29 19:50 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\EPSON
2007-11-29 17:45 . 2007-11-29 17:45 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-11-28 20:22 . 2007-11-28 20:22 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-11-28 20:22 . 2007-11-28 20:22 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-11-28 20:22 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-11-28 20:22 . 2007-11-28 20:22 376 --a------ C:\WINDOWS\ODBC.INI
2007-11-28 20:14 . 2007-11-28 20:14 <DIR> dr-h----- C:\MSOCache
2007-11-28 14:09 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-11-28 14:09 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-11-28 14:08 . 2005-07-22 00:00 148,992 --a------ C:\WINDOWS\system32\esxuin32.dll
2007-11-28 14:08 . 2005-06-20 00:00 139,264 --a------ C:\WINDOWS\system32\esint32.dll
2007-11-28 14:08 . 2005-07-22 00:00 88,576 --a------ C:\WINDOWS\system32\esxuni.dll
2007-11-28 14:08 . 2005-07-22 00:00 71,680 --a------ C:\WINDOWS\system32\esxuimgd.dll
2007-11-28 14:08 . 2003-06-06 00:00 65,793 --a------ C:\WINDOWS\system32\esfw32.bin
2007-11-28 14:08 . 2005-07-13 00:00 47,104 --a------ C:\WINDOWS\system32\escimgn.dll
2007-11-28 14:08 . 2005-07-22 00:00 39,424 --a------ C:\WINDOWS\system32\esxucmd.dll
2007-11-28 14:08 . 2005-07-13 00:00 32,768 --a------ C:\WINDOWS\system32\eswia32.dll
2007-11-28 14:08 . 2005-07-13 00:00 23,552 --a------ C:\WINDOWS\system32\esccmn.dll
2007-11-28 13:56 . 2007-11-28 13:56 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\AdobeUM
2007-11-18 17:02 . 2007-11-18 17:02 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-11-17 13:43 . 2007-11-17 13:43 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2007-11-17 13:43 . 2007-12-01 15:36 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\AVG7
2007-11-16 19:41 . 2007-11-16 19:41 <DIR> d-------- C:\Program Files\Nero
2007-11-16 19:41 . 2007-11-16 19:41 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-11-13 14:54 . 2007-12-07 13:26 9,662 --a------ C:\WINDOWS\EPISME00.SWB
2007-11-13 14:39 . 2007-11-13 14:39 <DIR> d-------- C:\Program Files\SSC Service Utility
2007-11-13 14:35 . 2007-11-13 14:35 <DIR> d-------- C:\Program Files\Common Files\EPSON
2007-11-13 14:35 . 2001-08-23 01:04 139,264 --a------ C:\WINDOWS\system32\EBAPI2.dll
2007-11-13 14:34 . 2007-12-06 08:36 <DIR> d-------- C:\Program Files\EPSON
2007-11-13 14:34 . 2007-11-28 14:06 <DIR> d-------- C:\EPSON
2007-11-13 14:34 . 2002-09-30 02:33 73,676 --a------ C:\WINDOWS\system32\EBPMON2.DLL
2007-11-13 14:34 . 2002-07-31 02:25 61,440 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2007-11-13 14:34 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2007-11-13 14:34 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-11-13 14:34 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-11-13 14:34 . 2007-12-04 10:12 10,978 --a------ C:\WINDOWS\EPSTPLOG.BAK
2007-11-13 14:34 . 2001-09-04 02:04 182 --a------ C:\WINDOWS\system32\EBPPORT.DAT
2007-11-12 19:30 . 2007-11-12 19:30 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-11-12 19:30 . 2007-11-12 19:30 <DIR> d-------- C:\Intel
2007-11-12 19:16 . 2007-11-12 19:16 <DIR> d-------- C:\Program Files\ASUS
2007-11-11 21:32 . 2007-11-11 21:32 1,156 --a------ C:\WINDOWS\mozver.dat
2007-11-11 20:07 . 2007-11-29 22:43 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\PicturesToExe
2007-11-11 17:39 . 2007-11-11 17:39 <DIR> d-------- C:\Program Files\JAlbum7.2
2007-11-11 12:24 . 2007-11-11 12:24 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\Grisoft
2007-11-11 12:24 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-11 12:06 . 2007-11-13 17:25 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\OpenOffice.org2
2007-11-11 12:04 . 2007-11-28 20:25 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2007-11-11 11:59 . 2007-11-11 11:59 <DIR> d-------- C:\Program Files\ColorVision
2007-11-11 11:59 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-11-11 11:47 . 2007-11-11 11:47 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-11-11 11:47 . 2007-11-11 11:48 <DIR> d-------- C:\Program Files\Macromedia
2007-11-11 11:47 . 2007-11-11 11:48 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2007-11-11 11:34 . 2007-12-01 00:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-11 11:19 . 2007-11-11 11:19 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Program Files\Skype
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-11-11 00:16 . 2007-11-30 20:50 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\Skype
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2007-11-11 00:12 . 2007-11-11 00:12 <DIR> d-------- C:\Program Files\Picasa2
2007-11-11 00:12 . 2006-10-05 02:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-11 00:12 . 2006-10-05 02:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-10 23:54 . 2007-11-10 23:55 <DIR> d-------- C:\Program Files\PicturesToExe
2007-11-10 23:46 . 2007-12-06 08:33 <DIR> d-------- C:\Program Files\SpeedFan
2007-11-10 23:46 . 2007-11-10 23:46 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2007-11-10 23:44 . 2007-12-03 23:14 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-11-10 23:44 . 2004-03-09 01:00 1,081,616 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2007-11-10 23:44 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2007-11-10 23:44 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2007-11-10 23:36 . 2007-11-10 23:36 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\AVG7
2007-11-10 23:36 . 2007-11-10 23:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-10 23:35 . 2007-11-11 12:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-10 23:35 . 2007-11-18 12:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-10 23:35 . 2007-11-10 23:35 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-11-10 23:35 . 2007-11-10 23:35 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-11-10 23:34 . 2007-12-07 14:59 11,057,184 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-10 23:34 . 2007-12-05 23:04 125,912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-10 23:32 . 2007-11-10 23:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 19:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-11 12:37 --------- d-----w C:\Program Files\Google
2007-11-11 11:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-10 22:52 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-11-10 22:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-10 22:30 --------- d-----w C:\Program Files\Realtek
2007-11-10 22:27 --------- d-----w C:\Program Files\Intel
2007-11-10 22:22 --------- d-----w C:\Program Files\Analog Devices
2007-11-10 22:15 --------- d-----w C:\Program Files\microsoft frontpage
2006-06-23 14:48 32,768 ----a-w C:\WINDOWS\inf\UpdateUSB.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 08:06]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2007-04-03 20:55]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-10 23:37]
"RegistryMechanic"=""
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"EPSON Stylus C62 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe" [2002-07-01 03:05]
"EPSON Stylus Photo R1800"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.exe" [2004-09-08 03:00]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-10 23:37]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe

S3 cvspydr2;ColorVision Spyder 2;C:\WINDOWS\system32\DRIVERS\cvspydr2.sys

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 14:59:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-07 14:59:39
.




I have also done a Combo log just in case 'Pancake' appears.

ComboFix 07-12-07.3 - Mick 2007-12-07 14:57:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1457 [GMT 0:00]
Running from: C:\Documents and Settings\Mick\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.

2007-12-06 23:02 . 2007-12-06 23:11 <DIR> d-------- C:\Program Files\httphotos
2007-12-06 23:02 . 2007-12-06 23:10 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\httphotos
2007-12-06 08:34 . 2007-12-06 08:34 <DIR> d-------- C:\WINDOWS\LastGood
2007-12-06 08:34 . 2004-09-30 05:06 79,686 --a------ C:\WINDOWS\system32\E_FLM9LE.DLL
2007-12-06 08:34 . 2003-05-21 02:27 64,000 --a------ C:\WINDOWS\system32\E_FBCB9LE.DLL
2007-12-06 08:34 . 2004-09-10 20:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2007-12-06 08:34 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\E_FBCH9LE.DLL
2007-12-02 09:49 . 2007-12-02 10:11 <DIR> d-------- C:\Program Files\Bonjour
2007-12-02 09:43 . 2007-12-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-12-02 09:43 . 2007-12-02 10:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-11-29 19:50 . 2007-11-29 19:50 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\EPSON
2007-11-29 17:45 . 2007-11-29 17:45 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-11-28 20:22 . 2007-11-28 20:22 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-11-28 20:22 . 2007-11-28 20:22 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-11-28 20:22 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-11-28 20:22 . 2007-11-28 20:22 376 --a------ C:\WINDOWS\ODBC.INI
2007-11-28 20:14 . 2007-11-28 20:14 <DIR> dr-h----- C:\MSOCache
2007-11-28 14:09 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-11-28 14:09 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-11-28 14:08 . 2005-07-22 00:00 148,992 --a------ C:\WINDOWS\system32\esxuin32.dll
2007-11-28 14:08 . 2005-06-20 00:00 139,264 --a------ C:\WINDOWS\system32\esint32.dll
2007-11-28 14:08 . 2005-07-22 00:00 88,576 --a------ C:\WINDOWS\system32\esxuni.dll
2007-11-28 14:08 . 2005-07-22 00:00 71,680 --a------ C:\WINDOWS\system32\esxuimgd.dll
2007-11-28 14:08 . 2003-06-06 00:00 65,793 --a------ C:\WINDOWS\system32\esfw32.bin
2007-11-28 14:08 . 2005-07-13 00:00 47,104 --a------ C:\WINDOWS\system32\escimgn.dll
2007-11-28 14:08 . 2005-07-22 00:00 39,424 --a------ C:\WINDOWS\system32\esxucmd.dll
2007-11-28 14:08 . 2005-07-13 00:00 32,768 --a------ C:\WINDOWS\system32\eswia32.dll
2007-11-28 14:08 . 2005-07-13 00:00 23,552 --a------ C:\WINDOWS\system32\esccmn.dll
2007-11-28 13:56 . 2007-11-28 13:56 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\AdobeUM
2007-11-18 17:02 . 2007-11-18 17:02 <DIR> d-------- C:\Program Files\Western Digital Technologies
2007-11-17 13:43 . 2007-11-17 13:43 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2007-11-17 13:43 . 2007-12-01 15:36 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\AVG7
2007-11-16 19:41 . 2007-11-16 19:41 <DIR> d-------- C:\Program Files\Nero
2007-11-16 19:41 . 2007-11-16 19:41 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-11-13 14:54 . 2007-12-07 13:26 9,662 --a------ C:\WINDOWS\EPISME00.SWB
2007-11-13 14:39 . 2007-11-13 14:39 <DIR> d-------- C:\Program Files\SSC Service Utility
2007-11-13 14:35 . 2007-11-13 14:35 <DIR> d-------- C:\Program Files\Common Files\EPSON
2007-11-13 14:35 . 2001-08-23 01:04 139,264 --a------ C:\WINDOWS\system32\EBAPI2.dll
2007-11-13 14:34 . 2007-12-06 08:36 <DIR> d-------- C:\Program Files\EPSON
2007-11-13 14:34 . 2007-11-28 14:06 <DIR> d-------- C:\EPSON
2007-11-13 14:34 . 2002-09-30 02:33 73,676 --a------ C:\WINDOWS\system32\EBPMON2.DLL
2007-11-13 14:34 . 2002-07-31 02:25 61,440 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2007-11-13 14:34 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2007-11-13 14:34 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-11-13 14:34 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-11-13 14:34 . 2007-12-04 10:12 10,978 --a------ C:\WINDOWS\EPSTPLOG.BAK
2007-11-13 14:34 . 2001-09-04 02:04 182 --a------ C:\WINDOWS\system32\EBPPORT.DAT
2007-11-12 19:30 . 2007-11-12 19:30 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-11-12 19:30 . 2007-11-12 19:30 <DIR> d-------- C:\Intel
2007-11-12 19:16 . 2007-11-12 19:16 <DIR> d-------- C:\Program Files\ASUS
2007-11-11 21:32 . 2007-11-11 21:32 1,156 --a------ C:\WINDOWS\mozver.dat
2007-11-11 20:07 . 2007-11-29 22:43 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\PicturesToExe
2007-11-11 17:39 . 2007-11-11 17:39 <DIR> d-------- C:\Program Files\JAlbum7.2
2007-11-11 12:24 . 2007-11-11 12:24 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\Grisoft
2007-11-11 12:24 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-11 12:06 . 2007-11-13 17:25 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\OpenOffice.org2
2007-11-11 12:04 . 2007-11-28 20:25 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3
2007-11-11 11:59 . 2007-11-11 11:59 <DIR> d-------- C:\Program Files\ColorVision
2007-11-11 11:59 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-11-11 11:47 . 2007-11-11 11:47 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-11-11 11:47 . 2007-11-11 11:48 <DIR> d-------- C:\Program Files\Macromedia
2007-11-11 11:47 . 2007-11-11 11:48 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2007-11-11 11:34 . 2007-12-01 00:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-11 11:19 . 2007-11-11 11:19 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Program Files\Skype
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-11-11 00:16 . 2007-11-30 20:50 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\Skype
2007-11-11 00:16 . 2007-11-11 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2007-11-11 00:12 . 2007-11-11 00:12 <DIR> d-------- C:\Program Files\Picasa2
2007-11-11 00:12 . 2006-10-05 02:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-11 00:12 . 2006-10-05 02:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-10 23:54 . 2007-11-10 23:55 <DIR> d-------- C:\Program Files\PicturesToExe
2007-11-10 23:46 . 2007-12-06 08:33 <DIR> d-------- C:\Program Files\SpeedFan
2007-11-10 23:46 . 2007-11-10 23:46 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2007-11-10 23:44 . 2007-12-03 23:14 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-11-10 23:44 . 2004-03-09 01:00 1,081,616 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2007-11-10 23:44 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2007-11-10 23:44 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2007-11-10 23:36 . 2007-11-10 23:36 <DIR> d-------- C:\Documents and Settings\Mick\Application Data\AVG7
2007-11-10 23:36 . 2007-11-10 23:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-10 23:35 . 2007-11-11 12:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-10 23:35 . 2007-11-18 12:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-10 23:35 . 2007-11-10 23:35 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-11-10 23:35 . 2007-11-10 23:35 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-11-10 23:34 . 2007-12-07 14:59 11,057,184 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-10 23:34 . 2007-12-05 23:04 125,912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-10 23:32 . 2007-11-10 23:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 19:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-11 12:37 --------- d-----w C:\Program Files\Google
2007-11-11 11:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-10 22:52 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-11-10 22:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-10 22:30 --------- d-----w C:\Program Files\Realtek
2007-11-10 22:27 --------- d-----w C:\Program Files\Intel
2007-11-10 22:22 --------- d-----w C:\Program Files\Analog Devices
2007-11-10 22:15 --------- d-----w C:\Program Files\microsoft frontpage
2006-06-23 14:48 32,768 ----a-w C:\WINDOWS\inf\UpdateUSB.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 08:06]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2007-04-03 20:55]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-10 23:37]
"RegistryMechanic"=""
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
"EPSON Stylus C62 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe" [2002-07-01 03:05]
"EPSON Stylus Photo R1800"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.exe" [2004-09-08 03:00]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-10 23:37]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 --a------ C:\WINDOWS\s




--- E O F ---
View User's Profile View All Posts By User
Mick Johnson
Custom User Title
*******




Posts: 698
Registered: 3-12-2003
Location: Staffordshire
Theme: KF Blue
Member Is Offline

Mood: No Mood

[*] Post 311258 posted on 7-12-2007 at 19:18 Reply With Quote


Forgot to mention my homepage is my website and I can't get to it.

How do they do that then?
View User's Profile View All Posts By User
Post new thread Poll:

Guest Notice
You are a guest, as a guest you can only see a maximum of 3 posts per thread.

If you want to see the rest, please click here to register.