1.

Solve : Problems with pop ups--Hijack this posted last entry of thread?

Answer»

To answer all questions, everything is fine. We will take care of the IMGRogue-WiniFighter_Small[1].gif. before we are done.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

RegLockDel::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeEvilfantasy, I had problems. I did what you asked and I received response that it had not been initialized properly. I attempted to use print screen button to "save" the messages to paste in paint and I received the reply that Paint was a key marked for deletion. Also, Combofix wanted to delete Avast key, Internet Explorer and Foxfire as well.  I thought I closed everything again or maybe I did things too soon. It did reboot to give the log---. After that I rebooted to safe mode and choose last known good restore point...Not sure of the terminology and I don't know much about restore points.  Also the magnifier which usually starts up on boot up or restart appeared and it has not been a problem until now....unless you count scattering the icons on desktop a problem. It is usually the bottom row and rightmost 2-3 columns that get moved or a random single one. The google sidebar reappeared; just prior to Combofix it wasn't there---just the google destop and I don't know how I had ended up with both! Also Combofix moved from bottom of my screen to top of screen and more towards the right.

In case it matters, Internet Explorer does not have a "run as administrator" selection while Foxfire does; Internet Explorer is the default browser.... Foxfire when originally put on this computer by a friend was the default; I changed it back to IE long ago.
Log follows:

ComboFix 09-08-28.01 - Susan M 08/28/2009 23:45.4.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.1982.1072 [GMT -4:00]
Running from: c:\users\Susan M\Desktop\ComboFix.exe
Command switches used :: c:\users\Susan M\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((   Files Created from 2009-07-28 to 2009-08-29  )))))))))))))))))))))))))))))))
.

2009-08-29 03:50 . 2009-08-29 03:52   --------   d-----w-   c:\users\Susan M\AppData\Local\temp
2009-08-29 03:50 . 2009-08-29 03:50   --------   d-----w-   c:\users\Public\AppData\Local\temp
2009-08-29 03:50 . 2009-08-29 03:50   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-08-27 21:46 . 2009-08-27 22:44   --------   d-----w-   c:\programdata\Spybot - Search & Destroy
2009-08-27 21:46 . 2009-08-27 21:49   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-08-27 12:44 . 2009-08-27 12:44   --------   d-----w-   c:\programdata\Office Genuine Advantage
2009-08-26 18:01 . 2009-06-22 10:09   2048   ----a-w-   c:\windows\system32\tzres.dll
2009-08-26 12:56 . 2009-06-05 09:40   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2009-08-26 12:56 . 2009-06-05 09:53   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-25 21:47 . 2009-08-28 13:03   --------   d-----w-   c:\program files\SpywareBlaster
2009-08-22 22:17 . 2009-08-22 22:17   --------   d-----w-   c:\program files\Trend Micro
2009-08-12 00:25 . 2009-06-04 12:07   2066432   ----a-w-   c:\windows\system32\mstscax.dll
2009-08-11 05:05 . 2009-08-17 16:04   51376   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
2009-08-11 05:05 . 2009-08-17 16:04   23152   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2009-08-11 05:05 . 2009-08-17 16:02   97480   ----a-w-   c:\windows\system32\AvastSS.scr
2009-08-11 05:05 . 2009-08-17 16:05   114768   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2009-08-11 05:05 . 2009-08-17 16:05   20560   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
2009-08-11 05:05 . 2009-08-17 16:10   1279456   ----a-w-   c:\windows\system32\aswBoot.exe
2009-08-11 05:05 . 2009-08-17 16:05   53328   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2009-08-11 05:05 . 2009-08-11 05:05   --------   d-----w-   c:\program files\Alwil Software
2009-08-03 19:07 . 2009-08-03 19:07   403816   ----a-w-   c:\windows\system32\OGACheckControl.dll
2009-08-03 19:07 . 2009-08-03 19:07   322928   ----a-w-   c:\windows\system32\OGAAddin.dll
2009-08-03 19:07 . 2009-08-03 19:07   230768   ----a-w-   c:\windows\system32\OGAEXEC.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 03:52 . 2007-12-30 18:45   --------   d-----w-   c:\program files\Dl_cats
2009-08-29 03:51 . 2007-12-21 20:23   12   ----a-w-   c:\windows\bthservsdp.dat
2009-08-29 03:39 . 2009-06-23 01:32   117760   ----a-w-   c:\users\Susan M\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-19 01:40 . 2009-02-24 00:46   --------   d-----w-   c:\program files\Java
2009-08-12 00:27 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-08-11 02:38 . 2009-06-23 01:32   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-08-11 02:28 . 2009-07-11 23:51   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-08-11 01:38 . 2009-07-16 04:53   3942048   ----a-w-   c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-09 01:09 . 2007-12-31 22:49   9720   ----a-w-   c:\users\Susan M\AppData\Roaming\wklnhst.dat
2009-08-08 23:04 . 2009-04-02 01:38   --------   d-----w-   c:\program files\Microsoft Silverlight
2009-08-03 17:36 . 2009-07-11 23:51   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 17:36 . 2009-07-11 23:51   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-07-29 12:51 . 2008-09-10 13:08   --------   d-----w-   c:\program files\Dell DataSafe Online
2009-07-29 12:50 . 2008-11-23 05:05   8270752   ----a-w-   c:\users\Susan M\AppData\Roaming\DataSafeDotNet.exe
2009-07-29 12:50 . 2008-11-23 05:05   8270752   ----a-w-   c:\users\Susan M\AppData\Roaming\DataSafeDotNet.exe
2009-07-25 09:23 . 2009-02-24 00:46   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-07-25 04:13 . 2009-07-25 04:13   713992   ----a-w-   c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-07-21 21:52 . 2009-07-30 05:01   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-30 05:01   109056   ----a-w-   c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-30 05:01   71680   ----a-w-   c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-30 05:01   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 00:24   71680   ----a-w-   c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 00:24   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 00:24   313344   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 00:24   4096   ----a-w-   c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 00:24   7680   ----a-w-   c:\windows\system32\spwmp.dll
2009-06-27 20:47 . 2009-06-27 20:47   709566   ----a-w-   c:\programdata\SPL736E.tmp
2009-06-15 23:15 . 2009-08-12 00:24   439864   ----a-w-   c:\windows\system32\drivers\ksecdd.sys
2009-06-15 14:54 . 2009-08-12 00:24   175104   ----a-w-   c:\windows\system32\wdigest.dll
2009-06-15 14:53 . 2009-07-15 12:37   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-06-15 14:53 . 2009-08-12 00:24   72704   ----a-w-   c:\windows\system32\secur32.dll
2009-06-15 14:53 . 2009-08-12 00:24   270848   ----a-w-   c:\windows\system32\schannel.dll
2009-06-15 14:53 . 2009-08-12 00:24   218624   ----a-w-   c:\windows\system32\msv1_0.dll
2009-06-15 14:52 . 2009-08-12 00:24   1259008   ----a-w-   c:\windows\system32\lsasrv.dll
2009-06-15 14:52 . 2009-07-15 12:37   23552   ----a-w-   c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-08-12 00:24   499712   ----a-w-   c:\windows\system32\kerberos.dll
2009-06-15 14:52 . 2009-07-15 12:37   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-15 12:37   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-06-15 12:48 . 2009-08-12 00:24   9728   ----a-w-   c:\windows\system32\lsass.exe
2009-06-15 12:42 . 2009-07-15 12:37   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-06-13 04:04 . 2006-11-02 10:25   665600   ----a-w-   c:\windows\inf\drvindex.dat
2009-06-10 11:42 . 2009-08-12 00:24   160256   ----a-w-   c:\windows\system32\wkssvc.dll
2009-06-10 11:38 . 2009-08-12 00:24   91136   ----a-w-   c:\windows\system32\avifil32.dll
2007-12-22 04:05 . 2007-12-22 03:55   8192   --sha-w-   c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((   [email protected]_00.00.47   )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-30 18:29 . 2009-08-28 23:23   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   32768              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-30 18:29 . 2009-08-28 23:23   32768              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-30 18:29 . 2009-08-29 03:52   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-30 18:29 . 2009-08-28 23:23   16384              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-29 21:26 . 2009-08-29 03:52   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-04-29 21:26 . 2009-08-28 23:23   245760              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-26 29744]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-17 4907008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):91,33,f5,30,dd,eb,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3588662981-376592854-2214661680-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F7822FD6-F6D0-4F27-91A7-C0AD1B1CE73A}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{BBF1B85C-9643-4C02-BD3C-FA25A6F9BE88}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{44FD6BC8-7F41-43A1-9F58-D5CDCA6A9105}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{90BC60DF-E730-4E61-8553-2B8C95354F7D}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{5141C4D6-F916-4E5F-BBCD-E5F3FC805E18}"= UDP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{555B5C3C-690B-4093-9958-548FD832EF6E}"= TCP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{09F02723-E8DC-45BC-B597-CED5202C2053}"= Disabled:UDP:135:TCP Port 135
"{E4E2D9D1-38EB-458A-853C-5E570C668A6A}"= Disabled:UDP:5000:TCP Port 5000
"{8930DE8D-6342-40F7-B226-E2D29B3749E2}"= Disabled:UDP:5001:TCP Port 5001
"{B68E5541-B4A1-49C4-8541-1CA11A153574}"= Disabled:UDP:5002:TCP Port 5002
"{9383E65A-FB56-4452-9170-8AF1145134E5}"= Disabled:UDP:5003:TCP Port 5003
"{9AD3CFDB-563C-423D-AF13-6139D94A7BE8}"= Disabled:UDP:5004:TCP Port 5004
"{FB2775F1-A7D2-47D3-B44F-BD45DD501FA5}"= Disabled:UDP:5005:TCP Port 5005
"{9C9104CA-5C33-42DB-9EC6-4B913D1C9387}"= Disabled:UDP:5006:TCP Port 5006
"{9BA2B06B-3350-40CE-82CE-A6A24181BB60}"= Disabled:UDP:5007:TCP Port 5007
"{BCA0B46D-96C8-4591-9B76-C092D1FEDFB3}"= Disabled:UDP:5008:TCP Port 5008
"{F62C0116-57CF-4E62-9B29-581269121CF4}"= Disabled:UDP:5009:TCP Port 5009
"{83F76203-F020-46D3-8632-B19A04E36EE6}"= Disabled:UDP:5010:TCP Port 5010
"{E5EC9F2D-D603-4C5D-90F4-89DE21F04C3F}"= Disabled:UDP:5011:TCP Port 5011
"{64B4E585-7F91-4F66-AB9B-52B3D5F87E4C}"= Disabled:UDP:5012:TCP Port 5012
"{0B64EFC9-3170-4C27-8B4E-CD72F1D271D8}"= Disabled:UDP:5013:TCP Port 5013
"{F18631F7-456F-493A-8015-F92EEF249626}"= Disabled:UDP:5014:TCP Port 5014
"{EC80A2F9-608E-4565-84A6-6C09F23935FA}"= Disabled:UDP:5015:TCP Port 5015
"{A7CE6CE9-35EF-4F90-AF9A-07BA5015B253}"= Disabled:UDP:5016:TCP Port 5016
"{85536E9B-0CA0-4BDF-9688-18363CB7C91B}"= Disabled:UDP:5017:TCP Port 5017
"{C8111B12-510B-4B77-BBA5-AC98074626F4}"= Disabled:UDP:5018:TCP Port 5018
"{0FE1E5F5-682B-4063-B281-29D250911D38}"= Disabled:UDP:5019:TCP Port 5019
"{7F7A26C4-ED89-4A15-93CB-B4CB9F633419}"= Disabled:UDP:5020:TCP Port 5020
"{A0309D64-84C6-4595-9D74-C8ED3AD93864}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3BF97467-1B54-46DA-986F-132DFD17D223}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{080DC243-A175-4EA0-AF2F-D65824C4F48C}c:\\program files\\popcap games\\alchemy deluxe\\winalch.exe"= UDP:c:\program files\popcap games\alchemy deluxe\winalch.exe:WinAlch
"UDP Query User{2DB51784-3EEF-4CC0-A4BC-0CC3A5C6465F}c:\\program files\\popcap games\\alchemy deluxe\\winalch.exe"= TCP:c:\program files\popcap games\alchemy deluxe\winalch.exe:WinAlch
"{B5A4A89A-5F98-4D80-BBCE-8250779AC25C}"= UDP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{94FA2DBB-D677-420C-A5B5-5A2FDC57060C}"= TCP:c:\windows\System32\dlcxcoms.exe:Lexmark Communications System
"{9DF1615C-182A-4560-9A61-A341AD56A4F2}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{C8AA90C9-F508-43F6-ACC4-5F19FA0CC2A6}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{BD893CB9-D840-4005-8523-71F1CF74607F}"= UDP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{A28901B6-CBA9-48AD-A979-4FD5AB4054BD}"= TCP:c:\program files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{9BDDD5D0-5870-4717-A362-A803560E1604}"= UDP:c:\users\Susan M\Desktop\HouseCall.exe:HouseCall.exe
"{F43BC75E-E07C-41BF-A1FD-51839A4312FB}"= TCP:c:\users\Susan M\Desktop\HouseCall.exe:HouseCall.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

R3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-26 29744]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-05-26 7408]
S1 aswSP;avast! Self Protection;


S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-11 74480]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-08-17 53328]
S2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe [2006-10-11 532480]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
WindowsMobile   REG_MULTI_SZ      wcescomm rapimgr
LocalServiceRestricted   REG_MULTI_SZ      WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-29 c:\windows\Tasks\User_Feed_Synchronization-{34BB2544-E314-4CD1-A261-BD1AA15CAABB}.job
- c:\windows\system32\msfeedssync.exe [2009-07-30 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/a/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: comcast.net\www
FF - ProfilePath - c:\users\Susan M\AppData\Roaming\Mozilla\Firefox\Profiles\wlpwrnl4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/a/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-28 23:52
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected]??

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-08-29 23:58 - machine was rebooted
ComboFix-quarantined-files.txt  2009-08-29 03:58
ComboFix2.txt  2009-08-29 00:03

Pre-Run: 236,156,841,984 bytes free
Post-Run: 235,897,585,664 bytes free

247   --- E O F ---   2009-08-28 12:30


npersn31Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click ACCEPT.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or SOMETHING similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

If needed, this animation will guide you through the process.I am concerned about what should be on and when as I am afraid stuff will interfer with other stuff, including stuff that appears in the tray, stuff that appears to the right of the Windows 'pearl'(Belarc icon, computer icon, internet explorer icon,Office Note 2007icon,Display Desktop icon,Firefox icon, Windows Media icon,Switch between windows icon,Spybot Search and Destroy icon [Tea timer icon not currently in system tray.]). In system tray upon start up/restart are Dell Support Center,Google Desktop[Desktop currently has both Google gadget icon and Google side bar],the button with options to add google gadgets(hides/shows sidebar),Dell Data Online,Avast, Avast Virus Recovery Database Generator icon,network icon,Realtek HD Audio Manager icon,  and Safely remove hardware icon. What do I need to do about these?

And now for the major questions:
Questions to be answered before I run this:
1) I know where to find Tools on Internet Explorer favorites bar and from there Internet options and on General tab under Browsing History find Delete. I find :preserve favorites website data; temporary internet files;cookies;history;form data;passwords;InPrivate filtering data. Under this there is a delete button and a cancel button. I think that the Disk Cleanup used to have a regularly scheduled time, but when I had McAfee I got rid of that and McAfee's default cleaning as it was messing with D: where shadow copies are causing unauthorized access message in Event Viewer. How do I delete temporary internet files and temporary files?

2)What must be off when I run this Combo /u?  I have turned on everything back on/or options
to have in tray when run (SuperAntiSpyware Free) in order to go onto the internet. Does the firewall need to be off? And when I go back on to run TFC by OldTimer what do I do? 
Do I turn stuff off for the online download, and then, while modem is on standby, turn everything off? Then run TFC.exe?

3)What about that start up magnifier, the Dell Support Center in the tray, and the google gadget button with the google sidebar(on right side of screen)? Also,Dell Data online is in the tray upon start up? Will these interfer with anything?

4)After TfC.exe run: turn Windows firewall on with everything else off to do Kaspersky run? 

5)Will Kaspersky let me choose settings before it starts scan? I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this?

6)What about dds.scr which is still on my desktop?

7)What about the C:\Program Files\Trend Micro\sniper.exe?  The sniper shortcut on desk top and the downloaded sniper2.exe? I had problems with the renaming....

8)Any special instructions for Spyware Blaster and SpyBot Search and Destroy?  Tea time is still off --- I assume so since I have not gone back to Advanced Mode to turn it on.

9)I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you?

Sorry for the list of concerns and questions but I don't want to mess up.  I think the last thing we tried had to do with siv, a program that I uninstalled long ago and tried to get it out of the registry without success. Also a long time ago a computer repair person put a marker in the registry--I think--so someone who knew what they were doing would find it.Did you read my list of questionable programs in an earlier post in this thread? Trying to make sure all the bases get covered! Thanks so much for the help thus far.
npersn31 Quote
How do I delete temporary internet files and temporary files?

You will be doing that by running TFC from my prior instructions.

Quote
What must be off when I run this Combo /u?

Nothing needs to be turned off. Just run Combo /u and then TFC.

Quote
Will Kaspersky let me choose settings before it starts scan?

All of the options should already be set.

Quote
I looked at your automation for Kaspersky and noticed that you need to run Internet Explorer as administrator and I have no such option. What do I do about this?

Right click the Internet Explorer icon in the system tray (bottom left) and choose Runs as Administrator.

Quote
What about dds.scr which is still on my desktop?

Delete it.

Quote
What about the C:\Program Files\Trend Micro\sniper.exe

Leave it for now. When we are done you can uninstall it in Add or Remove Programs.

Quote
Any special instructions for Spyware Blaster and SpyBot Search and Destroy?  Tea time is still off

Leave Tea Timer off. Don't worry about Spywareblaster.

Quote
I don't know if you need to know about PEB Corruption error that showed up in Problem reports in Windows vista(date of entry August 28). Do you?

I have no clue what that is. Just run Kaspersky so we can see if any malware is left. Then we will deal with any remaining issues.







Instructions followed; many files deleted, clicked IE 8 icon near pearl to run as administrator. Still got message that with Windows Vista you must run Kaspersky as administrator. Report follows.  Did remove dds.scr to Recycle Bin and from there deleted it [after Combofix removal.] TFC.exe still on desktop. Npersn31 calling it a night. Reply when convenient and thanks!
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
 Sunday, August 30, 2009
 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Sunday, August 30, 2009 03:34:54
 Records in database: 2718240
--------------------------------------------------------------------------------

Scan settings:
   scan using the following database: extended
   Scan archives: yes
   Scan e-mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\
   F:\

Scan statistics:
   Objects scanned: 110011
   Threats found: 0
   Infected objects found: 0
   Suspicious objects found: 0
   Scan duration: 01:52:19

No threats found. Scanned area is clean.

Selected area has been scanned.
Quote
PEB Corruption error

Are you sure this is spelled right?Evilfantasy: Here is the text taken from the Event viewer-----and you tell me!

Product
PEB_CORRUPTION

Problem
Driver host process disconnect

Date
8/28/2009 11:45 PM

Status
Report Sent

Description
The Windows User-Mode Driver Framework detected that a driver host-process disconnected unexpectedly. 
This report contains information about the process and the drivers running within and will be used to improve the quality of these drivers.

Problem signature
Problem Event Name:   WUDFHostProblem
EventClass:   HostProblem
Problem:   HostDisconnect
DetectedBy:   2
UMDFVersion:   6.0.6001.18000. (longhorn_rtm.080118-1840)
ExitCode:   ffffffffffffffff
Operation:   0
Message:   0
Status:   ffffffff
OS Version:   6.0.6002.2.2.0.768.3
Locale ID:   1033

Extra information about the problem
Bucket ID:   169643709
I have more details about what has been going on ,but don't have the time yet.
npersn31 signing off.That error is most likely not malware related so we can finish up here. Post the information about the error in the Microsoft Windows forum and someone there will help. I deal with malware...

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Evilfantasy, lots of files were deleted but quarantine in SuperAntiSpyware was not affected.Trace.Known Threat Sources
   C:\Users\Susan M\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZE8Y5QVT\IMGRogue-WiniFighter_Small[1].gif
was still in quarantine and whether it was adviseable to remove,  it has been done.  I also checked to see if anything from McAfee had been forgotten and it had: some logs from McAfee(exported text),some logs from McAfee Virtual TECHNICIAN (html form),McAfee manuals(Adobe Acrobat pdf). I am going to remove these. Last hjt that I ran just to see what it looked like after all this(including reverted to last known good configuration with Combofix problem and not having ever removing/stopping any restore points before running a/v) showed:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: ::1 localhost

Which doesn't take me where I want to go--- most of them.
Im not sure what I am going to do next. The Avast questions, I guess I'll have to ask in Avast forum and ask about Windows firewall elsewhere too. Internet Explorer not having administrative rights is puzzling since when I had attempted to use BitDefender scanner I used administrative rights selection from a shortcut on my desktop instead of the one to the right of the 'pearl'.
npersn31All of the entries in the HJT log are legitimate. You don't have to worry about them or you can fix them with HJT.

What is wrong with Avast and Windows Firewall?Before I forget,I hope you don't take this as a request for instant help---I appreciate the help when it comes. Also I still have the Oldtimer executable on my desktop: what does it take to get this removed?

In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate  but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think?

Also there seems to be a reference to McAfee here:O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab. What about it?

Here is the HJT that I used:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:18 PM, on 9/1/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[email protected]
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: dlcx_device -   - C:\Windows\system32\dlcxcoms.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7140 bytes
npersn31 Quote
Also I still have the Oldtimer executable on my desktop: what does it take to get this removed?

Just delete it.

Quote
In reference to your question about Avast and my firewall, I would refer you to the hjt that I just used the tool to evaluate  but I cannot figure how to get back to the evaluation. This evaluation did not recognize my firewall. As for what is wrong with Avast, I cannot get it to scan my email in my Windows Mail inbox. I do not understand their settings and what they mean by redirected email. I don't think that I used your method to run IE 8 as administrator when installing Avast and am wondering if I need to reinstall it. What do you think?

Your files are scanned automatically. You don't need to do anything.

Quote
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5551/mcfscan.cab

Fix it with HJT.evil fantasy, I ran the Secunia Software Inspector and it ran over an hour, hanging up on D:---or so it seemed to me. I ran it after updating Java 6 update 15 to Java 6 update 16. Backtracking a second, recall that the Internet explorer 8 shortcut as well as the Internet explorer "e" icon on the desktop had no "run as administrator" option available in previous steps of this malware chase, I have used the one in the tray to create a new "launch Internet Explorer" shortcut with the option desired. Using this shortcut and the available "run as administrator" option, I ran the Secunia Inspector in Internet Explorer 8[I do have Foxfire, but not as default browser.] I am logged in as administrator, so I don't know if this was necessary or not---right clicking the option, that is. Just making sure circumstances surrounding the "hanging up" on D: are clearly understood. D: has the "shadow copies" and is not a separate drive from C:. The insecure programs were listed as the process went on and 8 programs were listed as found, 3 were insecure,5 were patched.  I choose to go directly to sites to get the updates. Adobe Flash, Adobe Acrobat Reader,and Mozilla Foxfire were the insecure ones.

I have had second thoughts about those legitimate sites you said I could take out using HJT. I have asked someone about the PEB corruption, and am wondering if my administrative rights questions are too much to ask. I have not posted any internet explorer questions yet.


If you think this is ok, we can end this thread. I wait your reply and thank you so much for your patience and help.
npersn31Yes we can wrap this up now.


Discussion

No Comment Found