Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: ipconfig.exe box just appears a fraction of a second  (Read 30438 times)

0 Members and 1 Guest are viewing this topic.

Peterwolfe

    Topic Starter


    Hopeful
    ipconfig.exe box just appears a fraction of a second
    « on: May 10, 2010, 01:52:41 AM »
    when doing the "run"...C:\WINDOWS\system32\ipconfig.exe and disappears right away??!!! :P
    all other stuff via Run goes as usual...regedit is quite ok... :)
    system is clean according to my "defences"... ;D
    if its a rootinfection, what software would catch it? ::)
    Have Superantispyware, Spybot, AVG 9.0, Malwarebyte on my XP ??? and they say...nothing found..

    here's my HiJackThis of today:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:10:43, on 10.05.2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\D-Link\AirPlus G DWL-G510\AirGCFG.exe
    C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\RapidShareManager_0_1_0_248\RapidShareManager_0_1_0_248\RapidShareManager.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [D-Link AirPlus G DWL-G510] C:\Program Files\D-Link\AirPlus G DWL-G510\AirGCFG.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\Windows Live\Messenger\usnsvc.exe (file missing)
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

    --
    End of file - 6381 bytes
    « Last Edit: May 10, 2010, 02:11:07 AM by Peterwolfe »

    Peterwolfe

      Topic Starter


      Hopeful
      Re: ipconfig.exe box just appears a fraction of a second
      « Reply #1 on: May 10, 2010, 04:49:55 AM »
      Unhack me cant find any rootprblems... ::) :P

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: ipconfig.exe box just appears a fraction of a second
      « Reply #2 on: May 11, 2010, 06:38:16 PM »
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      SUPERAntiSpyware

      If you already have SUPERAntiSpyware be sure to remove it!


      Download SuperAntispyware Free Edition (SAS)
      * Double-click the icon on your desktop to run the installer.
      * When asked to Update the program definitions, click Yes
      * If you encounter any problems while downloading the updates, manually download and unzip them from here
      * Next click the Preferences button.

      •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
      * Click the Scanning Control tab.
      * Under Scanner Options make sure only the following are checked:

      •Close browsers before scanning
      •Scan for tracking cookies
      •Terminate memory threats before quarantining
      Please leave the others unchecked

      •Click the Close button to leave the control center screen.

      * On the main screen click Scan your computer
      * On the left check the box for the drive you are scanning.
      * On the right choose Perform Complete Scan
      * Click Next to start the scan. Please be patient while it scans your computer.
      * After the scan is complete a summary box will appear. Click OK
      * Make sure everything in the white box has a check next to it, then click Next
      * It will quarantine what it found and if it asks if you want to reboot, click Yes

      •To retrieve the removal information please do the following:
      •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
      •Click Preferences. Click the Statistics/Logs tab.

      •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

      •It will open in your default text editor (preferably Notepad).
      •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

      * Save the log somewhere you can easily find it. (normally the desktop)
      * Click close and close again to exit the program.
      *Copy and Paste the log in your post
      ======================================
      Please download Malwarebytes Anti-Malware from here.

      Double Click mbam-setup.exe to install the application.
      • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select "Perform Full Scan", then click Scan.
      • The scan may take some time to finish,so please be patient.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Make sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
      • Please save the log to a location you will remember.
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and paste the entire report in your next reply.
      Extra Note:

      If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
      ===========================================
      Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

      Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

      Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

      Exit out of MessengerDisable then delete the two files that were put on the desktop.
      ==========================================

      P2P - I see you have P2P software installed on your machine. (uTorrent)We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

      Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

      I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
      ==============================================
      Please go to Jotti's malware scan
      (If more than one file needs scanned they must be done separately and logs posted for each one)

      * Copy the file path in the below Code box:

      Code: [Select]
      C:\RapidShareManager_0_1_0_248\RapidShareManager_0_1_0_248\RapidShareManager.exe
      * At the upload site, click once inside the window next to Browse.
      * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
      * Next click Submit file
      * Your file will possibly be entered into a queue which normally takes less than a minute to clear.
      * This will perform a scan across multiple different virus scanning engines.
      * Important: Wait for all of the scanning engines to complete.
      * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
      ==============================================

      Open HijackThis and select Do a system scan only

      Place a check mark next to the following entries: (if there)

      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.
      ===============================================

      Windows 8 and Windows 10 dual boot with two SSD's

      BC_Programmer


        Mastermind
      • Typing is no substitute for thinking.
      • Thanked: 1140
        • Yes
        • Yes
        • BC-Programming.com
      • Certifications: List
      • Computer: Specs
      • Experience: Beginner
      • OS: Windows 11
      Re: ipconfig.exe box just appears a fraction of a second
      « Reply #3 on: May 11, 2010, 10:00:36 PM »
      when doing the "run"...C:\WINDOWS\system32\ipconfig.exe and disappears right away??!!! :P
      all other stuff via Run goes as usual...regedit is quite ok... :)

      ipconfig is a command-line program. if you wish to see the output, run "cmd" and then run ipconfig from the prompt.
      I was trying to dereference Null Pointers before it was cool.

      Peterwolfe

        Topic Starter


        Hopeful
        Re: ipconfig.exe box just appears a fraction of a second
        « Reply #4 on: May 12, 2010, 11:20:20 AM »
        Thanks BC Programmer, it was just a clear "understanding" error...cool...acted too quick on something I was sure I knew...lol...

        SuperDave: didn get your answer...was it a general one or was it based on my info? But than ks, my defences are up to date. I am running now as a consequence UnHackMe and it's quite reassuring with a rootkit solution too...but thanks anyway

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: ipconfig.exe box just appears a fraction of a second
        « Reply #5 on: May 12, 2010, 01:30:02 PM »
        If you don't want my help just let me know and I'll lock this thread.
        Windows 8 and Windows 10 dual boot with two SSD's

        Peterwolfe

          Topic Starter


          Hopeful
          Re: ipconfig.exe box just appears a fraction of a second
          « Reply #6 on: May 12, 2010, 10:13:46 PM »
          I am not THAT cocky...lol...done your stuff and now what? Nothing found!

          Have Superantispyware, Spybot, AVG 9.0, Malwarebyte on my XP  and they say...nothing found..

          BC_Programmer


            Mastermind
          • Typing is no substitute for thinking.
          • Thanked: 1140
            • Yes
            • Yes
            • BC-Programming.com
          • Certifications: List
          • Computer: Specs
          • Experience: Beginner
          • OS: Windows 11
          Re: ipconfig.exe box just appears a fraction of a second
          « Reply #7 on: May 12, 2010, 10:16:16 PM »
          I am not THAT cocky...lol...done your stuff and now what?

          Where are the logs?
          I was trying to dereference Null Pointers before it was cool.

          Peterwolfe

            Topic Starter


            Hopeful
            Re: ipconfig.exe box just appears a fraction of a second
            « Reply #8 on: May 12, 2010, 10:24:54 PM »
            ooops, sorry...will get back at you ;D

            Peterwolfe

              Topic Starter


              Hopeful
              Re: ipconfig.exe box just appears a fraction of a second
              « Reply #9 on: May 12, 2010, 10:28:35 PM »
              by the way: I use windows live messenger and have never encountered any problems, so...it's ON on a daily basis...lol
              Jotti says Rapidshare ok; HiJackThis suggestions executed. logs to follow...Live Messenger stays, never encountered any problems with that....

              BC_Programmer


                Mastermind
              • Typing is no substitute for thinking.
              • Thanked: 1140
                • Yes
                • Yes
                • BC-Programming.com
              • Certifications: List
              • Computer: Specs
              • Experience: Beginner
              • OS: Windows 11
              Re: ipconfig.exe box just appears a fraction of a second
              « Reply #10 on: May 12, 2010, 10:30:11 PM »
              by the way: I use windows live messenger and have never encountered any problems, so...it's ON on a daily basis...lol

              Quote
              Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

              you have confused them.  :P
              I was trying to dereference Null Pointers before it was cool.

              Peterwolfe

                Topic Starter


                Hopeful
                Re: ipconfig.exe box just appears a fraction of a second
                « Reply #11 on: May 12, 2010, 10:38:15 PM »
                ok, but then why to remove msn messenger if i dont have it..?

                Jotti says Rapidshare ok; HiJackThis suggestions executed. logs to follow...Live Messenger stays, never encountered any problems with that....

                Use utroorent only for music and movies and they are always checked, because nowadays you cant be sure of anything

                Peterwolfe

                  Topic Starter


                  Hopeful
                  Re: ipconfig.exe box just appears a fraction of a second
                  « Reply #12 on: May 12, 2010, 10:45:43 PM »
                  http://virusscan.jotti.org/en/scanresult/1ba370c2e
                  330fa12f238958ad08d8715b8ad8174/894d1011be
                  c8516aa5aa617c35314b435dc0f4c7
                  « Last Edit: May 15, 2010, 01:12:56 PM by SuperDave »

                  Peterwolfe

                    Topic Starter


                    Hopeful
                    Re: ipconfig.exe box just appears a fraction of a second
                    « Reply #13 on: May 12, 2010, 10:55:11 PM »
                    hm, they are still there...?...did your thing, checked and said fix...
                    answer 1:
                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 06:35:08, on 13.05.2010
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\AVG\AVG9\avgchsvx.exe
                    C:\Program Files\AVG\AVG9\avgrsx.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\AVG\AVG9\avgcsrvx.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\AVG\AVG9\avgwdsvc.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\AVG\AVG9\avgnsx.exe
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\Program Files\D-Link\AirPlus G DWL-G510\AirGCFG.exe
                    C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
                    C:\Program Files\Common Files\Java\Java Update\jusched.exe
                    C:\PROGRA~1\AVG\AVG9\avgtray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\UnHackMe\hackmon.exe
                    C:\Program Files\Opera 10 Beta\opera.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                    O4 - HKLM\..\Run: [D-Link AirPlus G DWL-G510] C:\Program Files\D-Link\AirPlus G DWL-G510\AirGCFG.exe
                    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                    O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\Windows Live\Messenger\usnsvc.exe (file missing)
                    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

                    --
                    End of file - 6318 bytes

                    Peterwolfe

                      Topic Starter


                      Hopeful
                      Re: ipconfig.exe box just appears a fraction of a second
                      « Reply #14 on: May 12, 2010, 11:28:39 PM »
                      SUPERAntiSpyware Scan Log
                      http://www.superantispyware.com

                      Generated 05/13/2010 at 07:29 AM

                      Application Version : 4.31.1000

                      Core Rules Database Version : 4910
                      Trace Rules Database Version: 2722

                      Scan type       : Complete Scan
                      Total Scan Time : 00:51:03

                      Memory items scanned      : 415
                      Memory threats detected   : 0
                      Registry items scanned    : 6360
                      Registry threats detected : 0
                      File items scanned        : 22134
                      Adware.Tracking Cookies found  : 37

                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][5].txt
                         C:\Documents and Settings\Peter\Cookies\peter@tribalfusion[2].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][5].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@toplist[2].txt
                         C:\Documents and Settings\Peter\Cookies\peter@buyalltraffic[2].txt
                         C:\Documents and Settings\Peter\Cookies\peter@atdmt[2].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@tradedoubler[1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][3].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@yadro[1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@trafficholder[1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@partypoker[1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@revsci[1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@toplist[1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][4].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][3].txt
                         C:\Documents and Settings\Peter\Cookies\peter@doubleclick[2].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][3].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@revsci[2].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\peter@atdmt[1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][3].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][2].txt
                         C:\Documents and Settings\Peter\Cookies\peter@statcounter[2].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][1].txt
                         C:\Documents and Settings\Peter\Cookies\[email protected][2].txt