Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

451.

Solve : Antivirus Searching?

Answer»

Hi,

I have been using Avast till now, but APPARENTLY is not free anymore.  I am looking for a good, free, antivirus program. SUGGESTIONS?

Thank you.

airreally? its not free anymore? http://www.avast.com/eng/download-avast-home.html

oh well.. AVG? I love avast more though.There's STILL AVAST free. It's not going AWAY anytime SOON. In fact, AVAST 5 is coming out soon. It's in beta right now.Avast! Home Edition (free)

452.

Solve : what is 503 privoxy message??

Answer»

hello,
whenever i browse websites, this message always comes up on the screen:


This is Privoxy 3.0.8 on LOCALHOST (127.0.0.1), port 8118, enabled

Connect failed
Your request for http://... (WEBSITE)... could not be FULFILLED, because the connection to... (website and ip address)... could not be established.

This is often a temporary failure, so you might just try again.

More Privoxy:
Privoxy main page
View & change the current configuration
View the source code version numbers
View the request headers.
Look up which actions apply to a URL and why
Documentation


Support and Service:
The Privoxy TEAM values your feedback. To provide you with the best support, we ask that you:

use the Support Tracker if you need help.
submit ads and configuration related problems with the actions files through the Actionsfile Feedback Tracker.
submit bugs only through the Bug Tracker. Please make sure that the bug has not been submitted yet.
submit feature requests only through the Feature Request Tracker.
read the instructions in the User Manual to make sure your request contains all the information we need.

it is really annoying and it shows almost everytime i click on a link.
please help me about it, what it is and what i should do to fix the problem.
i am not even sure if it is a virus or what.
thanks so much.
jen
Quote from: Karnac on November 16, 2009, 08:02:02 PM

Jenny , go here , post the required LOGS and a specialist will assist you.
453.

Solve : No icons, start menu, only desktop backgound....?

Answer»

I have a HP a712n computer. I am using windows xp and my task manager does work.  I have tried all of the following to try and fix this, but so far, nothing has worked...

1) System restore
2) Last known good configuration
3) defragment and error check
3). I have ran malware and superantispyware and Norton (I do not run them at the same time) have several viruses, and removed them.
4). I can go into regedit and look at my registry, but explorer.exe is not there
5). I type explorer or explorer.exe in the new task and it pops up a box that SAYS "windows cannot access the specified device, path or file.  You may not have the appropriate permission to access the item".
6). I have booted in SAFE mode, safe mode with networking, safe mode with prompts and tried all kinds of things, but nothing works.  Same blank screen in safe mode.
7). I have ran the exehelper that I seen listed in another post on here, and here is what comes up....


exeHelper by Raktor
Build 20091021
Run at 11:57:00 on 10/31/09
Now searching...
Checking for numerical processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Error occurred while processing: exefile.
.exe=exefile
Resetting filetype association for .com
comfile="%1" %*
.com=comfile
Resetting userinit and shell values...
Resetting policies...
--Finished--
 
Press any key to continue . . .

There was nothing new put on computer and we don't keep anything of importance in it. 


Can someone please help me get my desktop back?
1) What happened between the last time everything worked properly and the first time it did not (new hw, sw, virus, error, etc)?

2) Have you done a FULL system scan with BOTH your anti virus utility AND MALWAREBYTES? If not, do so now.Nothing happened.  My son said that everything on computer froze up so he turned it off and rebooted, and no icons, nothing.

I did a full system scan with Norton (found nothing), Superantispyware and Malwarebytes.  There were several adware tracking cookies and a few other trojans and it removed all of it.Okay, well SOMETHING happened - these things don't occur spontaneously. But lets try a couple of things.

1) First, boot to the XP CD and choose the first repair option. That will take you to the recovery console. Once there, run chkdsk /r. It will take a while to complete, let it do so. When it's finished type "exit" and press ENTER to reboot.

2) If still no joy, we can try a repair install.I do not have the XP cd.  You can borrow one for the repair efforts - it's both legal and effective. Try to borrow the same version you currently have in case we have to do the repair install. If you can't borrow one right away, you can download a .iso that will boot you to the recovery console (you have to use a utility to burn the .iso image to cd): http://forums.pcpitstop.com/index.php?showtopic=150212I will see what I can do.  Right now I am not at home, I am on my work computer.  I thought that there was some sort of repair thing in my computer, but I could wrong.  Can  I buy a new xp cd?  I don't know ANYONE that has one.Sure you can. Assuming you intend to keep using XP for the forseeable future you should have one anyway.I am having the EXACT same problem.Only my Background shows up.Task manager works,and I am also having the "windows cannot access the specified device, path or file.  You may not have the appropriate permission to access the item". Please, SOMEONE HELP!


BTW, How did you manage to get the start menu to come up?
Quote from: Blake00 on November 02, 2009, 11:19:49 AM

I am having the EXACT same problem.Only my Background shows up.Task manager works,and I am also having the "windows cannot access the specified device, path or file.  You may not have the appropriate permission to access the item". Please, SOMEONE HELP!


BTW, How did you manage to get the start menu to come up?

You need to either start your own thread or sit quietly and watch this one. This is not your thread. Quote from: Allan on November 02, 2009, 11:36:34 AM
You need to either start your own thread or sit quietly and watch this one. This is not your thread.


umm ya Allan, i started my own.That "patio" guy posted some click here stuff,Which just told me how to get rid of spyware,Malware,Viruses,etc.
Yeah,what great help.
-.-I don't have the start menu.  I access everything through task manager.  The only way I got Malwarebytes and Superantispyware to run was to run exehelper and then hurry up and run the scan.Okay. If I were you I'd download a boot time av scanner, burn it to a cd, boot to it and run a full virus scan at boot. Quote from: Allan on November 02, 2009, 11:58:27 AM
Okay. If I were you I'd download a boot time av scanner, burn it to a cd, boot to it and run a full virus scan at boot.


Not sure if you are talking to me or not.I know it's not my post,but not getting much help from anyone else.
What should i download?
I have tried:
Advance System Care
O.S. Pro
Superanti spyware
Spyhunter
Panda Security
AVG 8.0
Norton
Spyware Removal pro.
etc.I am NOT talking to you in this thread. Please, this is not your thread - you are only confusing things here.
454.

Solve : Yahoo-Google Virus Help Please?

Answer»

I believe I have a Search Engine Virus.  Can anyone please help me?

I READ online to run Combo-fix.  I did, and I'm not sure it worked.  I tried doing a Yahoo search, but that does not work.  Yahoo comes up with a screen that says "Sorry, Unable to process REQUEST at this time -- error 999."  Yahoo says it is probably because of Spyware or a Virus.  I had this problem before I used ComboFix.  I am scared to use Google, because that would always redirect me to another site.  I am scared that it might give me even more viruses if I tried that. 

Before ComboFix, I used Spyware Doctor.  That did not help.  It would find the problem, but it could not fix it.  Here is the results of my ComboFix scan (Thank you for any help):

ComboFix 09-11-11.02 - Owner 11/11/2009 21:14.1.1 - NTFSx86
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
.
ADS - system32: deleted 284 bytes in 2 streams.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-4050954835-1151102444-3722852121-1003
D:\Autorun.inf

.
(((((((((((((((((((((((((   Files Created from 2009-10-12 to 2009-11-12  )))))))))))))))))))))))))))))))
.

2009-11-12 01:58 . 2009-11-12 02:02   --------   d-----w-   C:\Combo-Fix
2009-11-12 00:55 . 2009-11-12 01:13   --------   d-----w-   c:\program files\Registry Easy
2009-11-11 00:06 . 2009-11-11 00:06   --------   d-sh--w-   c:\documents and settings\Owner\PrivacIE
2009-11-08 20:26 . 2009-11-08 20:26   --------   d-sh--w-   c:\documents and settings\NetworkService\IETldCache
2009-11-08 20:05 . 2009-11-08 20:05   --------   d-sh--w-   c:\documents and settings\Owner\IETldCache
2009-11-08 19:24 . 2009-10-02 04:44   92160   -c----w-   c:\windows\system32\dllcache\iecompat.dll
2009-11-08 19:21 . 2009-11-09 08:07   --------   d-----w-   c:\windows\ie8updates
2009-11-08 19:15 . 2009-08-29 08:08   12800   -c----w-   c:\windows\system32\dllcache\xpshims.dll
2009-11-08 19:15 . 2009-08-29 08:08   594432   -c----w-   c:\windows\system32\dllcache\msfeeds.dll
2009-11-08 19:15 . 2009-08-29 08:08   55296   -c----w-   c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-08 19:15 . 2009-08-29 08:08   1985536   -c----w-   c:\windows\system32\dllcache\iertutil.dll
2009-11-08 19:15 . 2009-08-29 08:08   246272   -c----w-   c:\windows\system32\dllcache\ieproxy.dll
2009-11-08 19:15 . 2009-08-29 08:08   11069440   -c----w-   c:\windows\system32\dllcache\ieframe.dll
2009-11-08 19:03 . 2009-11-08 19:13   --------   dc-h--w-   c:\windows\ie8
2009-11-07 18:59 . 2009-11-12 01:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\PC Tools
2009-11-07 18:57 . 2009-11-12 01:22   --------   d---a-w-   c:\documents and settings\All Users\Application Data\TEMP
2009-11-04 04:54 . 2009-11-04 05:03   4045527   ----a-w-   c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-04 04:48 . 2009-11-04 04:48   --------   d-----w-   c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-04 04:48 . 2009-09-10 19:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-11-04 04:48 . 2009-09-10 19:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-04 04:47 . 2009-11-04 04:47   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-04 04:47 . 2009-11-04 05:06   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-12 02:50 . 2008-10-23 07:36   --------   d-----w-   c:\documents and settings\Owner\Application Data\DNA
2009-11-12 01:51 . 2006-10-10 14:43   --------   d-----w-   c:\documents and settings\Owner\Application Data\OpenOffice.org2
2009-11-12 01:50 . 2008-10-23 07:36   --------   d-----w-   c:\program files\DNA
2009-11-11 15:34 . 2006-08-15 18:24   --------   d-----w-   c:\documents and settings\Owner\Application Data\BitTorrent
2009-10-21 23:05 . 2006-04-24 17:30   17552   -c--a-w-   c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-09-11 14:18 . 2004-08-26 16:12   136192   ----a-w-   c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-26 16:12   58880   ----a-w-   c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-26 16:12   916480   ----a-w-   c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-26 16:12   247326   ----a-w-   c:\windows\system32\strmdll.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-07 323392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-25 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 258118]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-07 267064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-20 148888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\BigFix.exe [2006-2-17 1742384]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-1-24 127488]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\cygwin\\usr\\X11R6\\bin\\XWin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\quake\\quake2.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 pctplsg;pctplsg;\??\c:\windows\system32\drivers\pctplsg.sys --> c:\windows\system32\drivers\pctplsg.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 2:49 AM 242712]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.netscape.com/
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\st2579gc.default\
FF - prefs.js: browser.search.selectedEngine - IMDb
FF - prefs.js: browser.startup.homepage - hxxp://www.netscape.com/
FF - PLUGIN: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-winupdate86.exe - c:\windows\system32\winupdate86.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
AddRemove-Money2005b - c:\program files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-11 21:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
COMPLETION time: 2009-11-12 22:10
ComboFix-quarantined-files.txt  2009-11-12 03:10

Pre-Run: 12,612,567,040 bytes free
Post-Run: 13,028,724,736 bytes free

- - END Of File - - FEBDC8922D6667B277348C6FD8DE0264
ComboFix Attachment

[Saving space, attachment deleted by admin]I might have found something under C:\Windows\System32\Drivers\etc\hosts

127.0.0.1 localhost
89.149.210.61 www.google.com
89.149.210.61 www.google.de
89.149.210.61 www.google.fr
89.149.210.61 www.google.co.uk
89.149.210.61 www.google.com.br
89.149.210.61 www.google.it
89.149.210.61 www.google.es
89.149.210.61 www.google.co.jp
89.149.210.61 www.google.com.mx
89.149.210.61 www.google.ca
89.149.210.61 www.google.com.au
89.149.210.61 www.google.nl
89.149.210.61 www.google.co.za
89.149.210.61 www.google.be
89.149.210.61 www.google.gr
89.149.210.61 www.google.at
89.149.210.61 www.google.se
89.149.210.61 www.google.ch
89.149.210.61 www.google.pt
89.149.210.61 www.google.dk
89.149.210.61 www.google.fi
89.149.210.61 www.google.ie
89.149.210.61 www.google.no
89.149.210.61 search.yahoo.com
89.149.210.61 us.search.yahoo.com
89.149.210.61 uk.search.yahoo.com

If I just delete the google and yahoo lines, would that fix things?
Hello Piechuck. Instead of trying to fix things yourself why not go to this link and follow the instructions. Once you post the required logs, one of the experts in this forum will jump in and help you.

455.

Solve : Blue Screen Issues - Infection Suspected?

Answer»

I am running Windows XP, SP3 and I noticed several issues:
  1) The system was getting slower and slower
  2) I run Computer Associates AntiVirus & AntiSpyware and the realtime protection was stopping on a regular basis
  3) Started getting blue screens with the following message:
      STOP: c000021a {Fatal System Error}
      The Windows Logon Process system process terminated unexpectedly with a status of
      0x80000007 (0x00000000 0x00000000)
      The system has been shut down

I followed the steps as requested; however, there was an issue with SUPERAntiSpyware - I ran it several times but it was never able to successfully remove the issues because the system blue screened.  The logs are attached.

Also - thanks in advance for your help!



[Saving space, attachment deleted by admin]I've worked on the system over the past week or so and now know that I have some issues that I cannot resolve.  Whenever I run through the suggested process, SuperAntiSpyware ends up not being able to rid the system of three pests: Adware.Vundo/Variant_MSFake, Adware.Vundo/Variant_BigCatch, and Trojan.Downloader-CREW.  The program consistently identifies these three issues and then it has problems removing them.  Whenever it tries to remove these issues, it states it is cleaning them and then, after about 30-seconds or so, the system blue screens with the message shown in the original post.

Also, MBAM finds multiple instances of Trojan.Vundo.H.  It tries to remove them all but, even after requested reboots, there are infected DLLs.  I suspect this is because SuperAntiSpyware cannot clean Vundo from the system.

I've tried cleaning the system in Safe Mode, but the results are the same.

Is it going to be possible to remove Vundo and CREW from the system?

Thanks.

[Saving space, attachment deleted by admin]Hello oldschoolcoder. Sorry for the delay.

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

* ViewMgr.exe - Useless
* Viewpoint to Plunge Into Adware

It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

* Viewpoint
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
* Viewpoint Experience Technology

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.Thanks for the response.

Removed Viewpoint Manager and Viewpoint Media Player.

The logs are below:

DDS Log:

DDS (Ver_09-10-26.01) - NTFSx86 
Run by Richard at 16:56:01.51 on Thu 11/12/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.346 [GMT -5:00]

AV: CA Anti-Virus *On-access scanning enabled* (Updated)   {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\VetMsg.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\CAVRID.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLHostManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Richard\Local Settings\Temporary Internet

Files\Content.IE5\GALAQ0YA\dds[1].pif
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = about:blank
uDefault_Page_URL = hxxp://business.dellnet.com/
uSearch Bar = about:blank
mSearch Bar =
uSearchURL,(Default) = about:blank
mSearchAssistant = about:blank
mCustomizeSearch = hxxp://ie.search.msn.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat

5.0\reader\activex\AcroIEHelper.ocx
BHO: Yahoo! Companion BHO: {13f537f0-af09-11d6-9029-0002b31f9e59} - c:\program

files\yahoo!\common\ycomp5,0,2,0.dll
BHO: : {2a7edee4-0a75-473e-bb5c-1689fcc69bfe} - c:\windows\system32\pjdfmqz.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} -

c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar

2.0\aoltb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program

files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program

files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson

web-to-page\EPSON Web-To-Page.dll
BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program

files\yahoo!\common\ycomp5,0,2,0.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson

web-to-page\EPSON Web-To-Page.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program

files\yahoo!\messenger\yhexbmes0819.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus Photo 1400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibua.exe /fu

"c:\docume~1\richard\locals~1\temp\E_S1C0.tmp" /EF "HKCU"
mRun: [Auto EPSON Stylus CX4800 Series on XPS] c:\windows\system32\spool\drivers\w32x86\3\e_fatiada.exe

/p38 "auto epson stylus cx4800 series on xps" /o13 "\\xps\Printer" /M "Stylus CX4800"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [UpdReg] c:\windows\Updreg.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SM1BG] c:\windows\SM1BG.EXE
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [QOELOADER] "c:\program files\ca\etrust ez armor\etrust ez anti-spam\qsp-5.1.18.0\QOELoader.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MoneyStartUp10.0] "c:\program files\microsoft money\system\Activation.exe"
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [iRiver Updater] c:\program files\iriver\iriver manager\updater\Updater.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HostManager] c:\program files\common files\aol\1137856837\ee\AOLHostManager.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [DellTouch] c:\windows\DELLMMKB.EXE
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\progra~1\ca\etrust~1\etrust~2\CAVRID.exe"
mRun: [AHQInit] c:\program files\creative\sblive\program\AHQInit.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe"

/runcleanupscript
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common

files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america

online 7.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital

imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital

imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft

office\office10\OSA.EXE
uPolicies-explorer: =
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program

files\aol\aol toolbar 2.0\aoltb.dll
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program

files\yahoo!\messenger\yhexbmes0819.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} -

c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} -

c:\progra~1\spybot~1\SDHelper.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program

files\microsoft money\system\mnyviewer.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/games/hamsterball/en/raptisoftgameloader.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -

hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} -

hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/installs/yinst.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -

hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221779908000
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -

hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} -

hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -

hxxp://install.wildtangent.com/bgn/partners/shockwave/virtualwarfare/install.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -

hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program

files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: bnwpnphf - pjdfmqz.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} -

c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program

files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli orecac.dll

============= SERVICES / DRIVERS ===============

R1 Ndcprtns;Ndcprtns;c:\windows\system32\drivers\NDCPRTNS.sys [2001-1-1 9328]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements

3.0\PhotoshopElementsFileAgent.exe [2004-10-20 98304]
R2 guzykphi;Microsoft USB Generic Parent Helper;c:\windows\system32\svchost.exe -k netsvcs [2001-8-18

14336]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [1980-1-1 28672]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop

elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-20 118784]
R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-4-24 6942]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe

[2007-5-24 189704]
S2 MSSQL$VPINSTANCE;SQL Server (VPINSTANCE);c:\program files\microsoft sql

server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 CW10;Belkin 11Mbps Wireless Win2K Driver;c:\windows\system32\drivers\CW10.sys [2001-6-3 46036]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6

Driver;c:\windows\system32\drivers\netusbxp.sys [2006-11-24 72576]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql

server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql

server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]

=============== Created Last 30 ================

2009-11-11 22:24:03   0   d-----w-   c:\docume~1\richard\applic~1\jkaildqf
2009-11-11 20:59:18   54156   ---ha-w-   c:\windows\QTFont.qfn
2009-11-11 20:59:18   1409   ----a-w-   c:\windows\QTFont.for
2009-10-27 20:44:26   0   d-----w-   c:\program files\Trend Micro
2009-10-27 20:34:17   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2009-10-27 20:34:17   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-10-27 19:44:21   0   d-----w-   c:\docume~1\richard\applic~1\Malwarebytes
2009-10-27 19:44:08   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-27 19:44:06   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-10-27 19:44:06   0   d-----w-   c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-27 19:44:05   0   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-10-15 21:55:42   0   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-10-15 21:55:24   0   d-----w-   c:\program files\SUPERAntiSpyware
2009-10-15 21:55:23   0   d-----w-   c:\docume~1\richard\applic~1\SUPERAntiSpyware.com
2009-10-15 21:54:30   0   d-----w-   c:\program files\common files\Wise Installation Wizard
2009-10-15 21:48:46   0   d-----w-   c:\program files\CCleaner
2009-10-14 13:29:00   0   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-10-14 13:21:23   0   d-----w-   c:\windows\SQL9_KB970892_ENU

==================== Find3M  ====================

2009-11-03 01:42:06   195456   ------w-   c:\windows\system32\MpSigStub.exe
2009-10-22 09:19:04   5939712   ----a-w-   c:\windows\system32\dllcache\mshtml.dll
2009-10-13 17:29:19   739752   ----a-w-   c:\windows\system32\drivers\vetefile.sys
2009-10-13 17:29:19   133576   ----a-w-   c:\windows\system32\drivers\veteboot.sys
2009-09-11 14:18:39   136192   ----a-w-   c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39   136192   ------w-   c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 21:03:36   58880   ----a-w-   c:\windows\system32\msasn1.dll
2009-09-04 21:03:36   58880   ------w-   c:\windows\system32\dllcache\msasn1.dll
2009-08-28 10:35:52   173056   ----a-w-   c:\windows\system32\dllcache\ie4uinit.exe
2009-08-26 08:00:21   247326   ----a-w-   c:\windows\system32\strmdll.dll
2009-08-26 08:00:21   247326   ------w-   c:\windows\system32\dllcache\strmdll.dll
2009-08-20 19:09:06   1193832   ----a-w-   c:\windows\system32\FM20.DLL
2003-08-27 19:19:18   36963   ----a-r-   c:\program files\common files\SM1updtr.dll
2008-09-18 23:11:55   32768   --sha-w-   c:\windows\system32\config\systemprofile\local

settings\history\history.ie5\mshist012008091820080919\index.dat

============= FINISH: 16:58:31.15 ===============


Attach Log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-10-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 4/27/2002 4:52:13 PM
System Uptime: 11/12/2009 2:23:34 PM (2 hours ago)

Motherboard: Intel Corporation               |  | D845PT     

                   
Processor:               Intel(R) Pentium(R) 4 CPU 1.70GHz |

J1E1 | 1694/100mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 9.399 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 112 GiB total, 20.68 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: Microsoft PS/2 Port Mouse (IntelliPoint)
Device ID: ACPI\PNP0F03\4&268D196D&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Port Mouse (IntelliPoint)
PNP Device ID: ACPI\PNP0F03\4&268D196D&0
Service: i8042prt

==== System Restore Points ===================

RP7: 11/12/2009 4:11:24 PM - System Checkpoint

==== Installed Programs ======================

7300
7300_Help
7300Trb
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Acrobat Reader 3.01
Adobe Flash Player 10 ActiveX
Adobe Photoshop Elements 3.0
Adobe Shockwave Player
AiO_Scan
AiOSoftware
AOL Coach Version 1.0(Build:20011028.1)
AOL Explorer
AOL Toolbar 2.0
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoImpression 5
AutoCAD 2008 - English
Autodesk DWF Viewer 7
BufferChm
CA Anti-Spam
CA Anti-Spyware
CA Anti-Virus
CA Internet Security Suite
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner
Compatibility Pack for the 2007 Office system
Conexant HSF V92 56K RTAD Speakerphone PCI Modem
Copy
CRB PowerSystem for VantagePoint 8.0
CreativeProjects
CreativeProjectsTemplates
Critical Update for Windows Media Player 11 (KB959772)
CueTour
CyberX 2.0
Cypress USB Mass Storage Driver Installation
D-Link DFE-530TX+
D-Link PCI Fast Ethernet Adapter
Dell Picture Studio - Image Expert 2000
Dell ResourceCD
Dell Solution Center
DellTouch
Destinations
Diamond Mine 1.5y
Director
DocProc
DocumentViewer
Edmark Zap! (Remove only)
EPSON Print CD
EPSON Printer Software
EPSON SP1400 Reference Guide
EPSON Web-To-Page
eSignal
Fax
FXCM Trading Station II
GdiplusUpgrade
GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)
GDR 4053 for SQL Server Tools and Workstation Components 2005

ENU (KB970892)
H4 Trading Charts 1.0
Help and Support Customization
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1

- ENU (KB945282)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1

- ENU (KB946040)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1

- ENU (KB946308)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1

- ENU (KB947540)
Hotfix for Microsoft Visual C# 2008 Express Edition with SP1

- ENU (KB947789)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Diagnostic Assistant
HP Image Zone 4.2
HP Photosmart Essential
HP PSC & OfficeJet 4.2
HP Software Update
HPSystemDiagnostics
IE2K
Instant Wireless USB Adapter
InstantShare
Intel Application Accelerator
InterActual Player
Interbank FX Trader 4.00
iRiver Manager
iRiver Updater
iTunes
Java(TM) 6 Update 16
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft IntelliPoint 6.1
Microsoft Interactive Training
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Media Content
Microsoft Office XP Professional
Microsoft Publisher 2002
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (VPINSTANCE)
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser
Microsoft SQL Server 2008 Common Files
Microsoft SQL Server 2008 Database Engine Services
Microsoft SQL Server 2008 Database Engine Shared
Microsoft SQL Server 2008 Management Objects
Microsoft SQL Server 2008 Native Client
Microsoft SQL Server 2008 RsFx Driver
Microsoft SQL Server 2008 Setup Support Files (English)
Microsoft SQL Server Compact 3.5 SP1 Design Tools English
Microsoft SQL Server Compact 3.5 SP1 English
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C# 2008 Express Edition with SP1 - ENU
Microsoft Visual C++ 2008 ATL Update kb973924 - x86

9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Windows SDK for Visual Studio 2008 SP1 Express

Tools for .NET Framework - enu
Microsoft Windows SDK for Visual Studio 2008 SP1 Express

Tools for Win32
Modem Helper
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
MusicMatch Jukebox
Network Play System (Patching)
NVIDIA Windows 2000/XP Display Drivers
Overland
PCFriendly
PhoneTools
PhotoGallery
PowerDVD 5.1
PrintScreen
ProductContext
QFolder
QuickProjects
QuickTime
QuickTime 3.0
Readme
RealPlayer Basic
RockSim 8.0.1 Demo
RTC Client API v1.2
Scan
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training

(KB898458)
Security Update for Step By Step Interactive Training

(KB923723)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shockwave Player
SkinsHP1
Sonic DLA
Sonic RecordNow! Plus
Sonic Update Manager
Sound Blaster Live! Value
Spybot - Search & Destroy
Sql Server Customer Experience Improvement Program
SQL Server System CLR Types
SUPERAntiSpyware Free Edition
TAL Trading Tools
TrayApp
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
USB Storage Adapter FX (SM1)
VantagePoint Intermarket Analysis Software
VBA (2627.01)
Wealth Charts
WebFldrs XP
WebReg
Windows Defender
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinMX
Yahoo! Companion
Yahoo! Internet Mail
Yahoo! Messenger Explorer Bar

==== Event Viewer Messages From Past Week ========

11/9/2009 4:14:55 PM, error: Print [19]  - Sharing printer

failed + 1722, Printer HP DeskJet 660Cse share name Printer.
11/7/2009 1:06:43 PM, error: DCOM [10005]  - DCOM got error

"%1084" attempting to start the service netman with arguments

"" in order to run the server:

{BA126AE5-2166-11D1-B1D0-00805FC1270E}
11/7/2009 1:06:38 PM, error: DCOM [10005]  - DCOM got error

"%1084" attempting to start the service EventSystem with

arguments "" in order to run the server:

{1BE1F766-5536-11D1-B726-00C04FB926AF}
11/11/2009 5:15:20 PM, error: DCOM [10009]  - DCOM was unable

to communicate with the computer CJR using any of the

configured protocols.
11/10/2009 1:53:51 PM, error: DCOM [10005]  - DCOM got error

"%1053" attempting to start the service PPCtlPriv with

arguments "" in order to run the server:

{F974178A-A284-440A-BEFC-5B0D11BCDB68}
11/10/2009 1:53:18 PM, error: DCOM [10005]  - DCOM got error

"%1053" attempting to start the service iPod Service with

arguments "" in order to run the server:

{063D34A4-BF84-4B8D-B699-E8CA06504DDE}

==== End Of File ===========================
Open Notepad. Start > type in notepad.exe then click OK.

In Notepad go to Format > then click Word Wrap. Close Notepad.

Now run DDS again and post the log. The last one is messed up so is hard to read and setting Word Wrap will fix it.Here are the logs:

DDS (Ver_09-10-26.01) - NTFSx86 
Run by Richard at 17:25:19.54 on Thu 11/12/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.339 [GMT -5:00]

AV: CA Anti-Virus *On-access scanning enabled* (Updated)   {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\VetMsg.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\CAVRID.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLHostManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Richard\Local Settings\Temporary Internet Files\Content.IE5\GALAQ0YA\dds[1].pif
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = about:blank
uDefault_Page_URL = hxxp://business.dellnet.com/
uSearch Bar = about:blank
mSearch Bar =
uSearchURL,(Default) = about:blank
mSearchAssistant = about:blank
mCustomizeSearch = hxxp://ie.search.msn.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: Yahoo! Companion BHO: {13f537f0-af09-11d6-9029-0002b31f9e59} - c:\program files\yahoo!\common\ycomp5,0,2,0.dll
BHO: : {2a7edee4-0a75-473e-bb5c-1689fcc69bfe} - c:\windows\system32\pjdfmqz.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\common\ycomp5,0,2,0.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes0819.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus Photo 1400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibua.exe /fu "c:\docume~1\richard\locals~1\temp\E_S1C0.tmp" /EF "HKCU"
mRun: [Auto EPSON Stylus CX4800 Series on XPS] c:\windows\system32\spool\drivers\w32x86\3\e_fatiada.exe /p38 "auto epson stylus cx4800 series on xps" /o13 "\\xps\Printer" /M "Stylus CX4800"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [UpdReg] c:\windows\Updreg.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SM1BG] c:\windows\SM1BG.EXE
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [QOELOADER] "c:\program files\ca\etrust ez armor\etrust ez anti-spam\qsp-5.1.18.0\QOELoader.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MoneyStartUp10.0] "c:\program files\microsoft money\system\Activation.exe"
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [iRiver Updater] c:\program files\iriver\iriver manager\updater\Updater.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HostManager] c:\program files\common files\aol\1137856837\ee\AOLHostManager.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [DellTouch] c:\windows\DELLMMKB.EXE
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\progra~1\ca\etrust~1\etrust~2\CAVRID.exe"
mRun: [AHQInit] c:\program files\creative\sblive\program\AHQInit.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 7.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-explorer: =
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0819.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/games/hamsterball/en/raptisoftgameloader.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/installs/yinst.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221779908000
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - hxxp://install.wildtangent.com/bgn/partners/shockwave/virtualwarfare/install.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: bnwpnphf - pjdfmqz.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli orecac.dll

============= SERVICES / DRIVERS ===============

R1 Ndcprtns;Ndcprtns;c:\windows\system32\drivers\NDCPRTNS.sys [2001-1-1 9328]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-20 98304]
R2 guzykphi;Microsoft USB Generic Parent Helper;c:\windows\system32\svchost.exe -k netsvcs [2001-8-18 14336]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [1980-1-1 28672]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-20 118784]
R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-4-24 6942]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2007-5-24 189704]
S2 MSSQL$VPINSTANCE;SQL Server (VPINSTANCE);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 CW10;Belkin 11Mbps Wireless Win2K Driver;c:\windows\system32\drivers\CW10.sys [2001-6-3 46036]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [2006-11-24 72576]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]

=============== Created Last 30 ================

2009-11-11 22:24:03   0   d-----w-   c:\docume~1\richard\applic~1\jkaildqf
2009-11-11 20:59:18   54156   ---ha-w-   c:\windows\QTFont.qfn
2009-11-11 20:59:18   1409   ----a-w-   c:\windows\QTFont.for
2009-10-27 20:44:26   0   d-----w-   c:\program files\Trend Micro
2009-10-27 20:34:17   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2009-10-27 20:34:17   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-10-27 19:44:21   0   d-----w-   c:\docume~1\richard\applic~1\Malwarebytes
2009-10-27 19:44:08   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-27 19:44:06   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-10-27 19:44:06   0   d-----w-   c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-27 19:44:05   0   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-10-15 21:55:42   0   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-10-15 21:55:24   0   d-----w-   c:\program files\SUPERAntiSpyware
2009-10-15 21:55:23   0   d-----w-   c:\docume~1\richard\applic~1\SUPERAntiSpyware.com
2009-10-15 21:54:30   0   d-----w-   c:\program files\common files\Wise Installation Wizard
2009-10-15 21:48:46   0   d-----w-   c:\program files\CCleaner
2009-10-14 13:29:00   0   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-10-14 13:21:23   0   d-----w-   c:\windows\SQL9_KB970892_ENU

==================== Find3M  ====================

2009-11-03 01:42:06   195456   ------w-   c:\windows\system32\MpSigStub.exe
2009-10-22 09:19:04   5939712   ----a-w-   c:\windows\system32\dllcache\mshtml.dll
2009-10-13 17:29:19   739752   ----a-w-   c:\windows\system32\drivers\vetefile.sys
2009-10-13 17:29:19   133576   ----a-w-   c:\windows\system32\drivers\veteboot.sys
2009-09-11 14:18:39   136192   ----a-w-   c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39   136192   ------w-   c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 21:03:36   58880   ----a-w-   c:\windows\system32\msasn1.dll
2009-09-04 21:03:36   58880   ------w-   c:\windows\system32\dllcache\msasn1.dll
2009-08-28 10:35:52   173056   ----a-w-   c:\windows\system32\dllcache\ie4uinit.exe
2009-08-26 08:00:21   247326   ----a-w-   c:\windows\system32\strmdll.dll
2009-08-26 08:00:21   247326   ------w-   c:\windows\system32\dllcache\strmdll.dll
2009-08-20 19:09:06   1193832   ----a-w-   c:\windows\system32\FM20.DLL
2003-08-27 19:19:18   36963   ----a-r-   c:\program files\common files\SM1updtr.dll
2008-09-18 23:11:55   32768   --sha-w-   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091820080919\index.dat

============= FINISH: 17:26:59.29 ===============



DDS (Ver_09-10-26.01) - NTFSx86 
Run by Richard at 17:25:19.54 on Thu 11/12/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.339 [GMT -5:00]

AV: CA Anti-Virus *On-access scanning enabled* (Updated)   {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\VetMsg.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\CAVRID.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLHostManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1137856837\ee\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Richard\Local Settings\Temporary Internet Files\Content.IE5\GALAQ0YA\dds[1].pif
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = about:blank
uDefault_Page_URL = hxxp://business.dellnet.com/
uSearch Bar = about:blank
mSearch Bar =
uSearchURL,(Default) = about:blank
mSearchAssistant = about:blank
mCustomizeSearch = hxxp://ie.search.msn.com
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: Yahoo! Companion BHO: {13f537f0-af09-11d6-9029-0002b31f9e59} - c:\program files\yahoo!\common\ycomp5,0,2,0.dll
BHO: : {2a7edee4-0a75-473e-bb5c-1689fcc69bfe} - c:\windows\system32\pjdfmqz.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\common\ycomp5,0,2,0.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes0819.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus Photo 1400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatibua.exe /fu "c:\docume~1\richard\locals~1\temp\E_S1C0.tmp" /EF "HKCU"
mRun: [Auto EPSON Stylus CX4800 Series on XPS] c:\windows\system32\spool\drivers\w32x86\3\e_fatiada.exe /p38 "auto epson stylus cx4800 series on xps" /o13 "\\xps\Printer" /M "Stylus CX4800"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [UpdReg] c:\windows\Updreg.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SM1BG] c:\windows\SM1BG.EXE
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [QOELOADER] "c:\program files\ca\etrust ez armor\etrust ez anti-spam\qsp-5.1.18.0\QOELoader.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MoneyStartUp10.0] "c:\program files\microsoft money\system\Activation.exe"
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [iRiver Updater] c:\program files\iriver\iriver manager\updater\Updater.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HostManager] c:\program files\common files\aol\1137856837\ee\AOLHostManager.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [DellTouch] c:\windows\DELLMMKB.EXE
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\progra~1\ca\etrust~1\etrust~2\CAVRID.exe"
mRun: [AHQInit] c:\program files\creative\sblive\program\AHQInit.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 7.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-explorer: =
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0819.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/games/hamsterball/en/raptisoftgameloader.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/installs/yinst.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1221779908000
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - hxxp://install.wildtangent.com/bgn/partners/shockwave/virtualwarfare/install.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: bnwpnphf - pjdfmqz.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli orecac.dll

============= SERVICES / DRIVERS ===============

R1 Ndcprtns;Ndcprtns;c:\windows\system32\drivers\NDCPRTNS.sys [2001-1-1 9328]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-20 98304]
R2 guzykphi;Microsoft USB Generic Parent Helper;c:\windows\system32\svchost.exe -k netsvcs [2001-8-18 14336]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [1980-1-1 28672]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-20 118784]
R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [2002-4-24 6942]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2007-5-24 189704]
S2 MSSQL$VPINSTANCE;SQL Server (VPINSTANCE);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 CW10;Belkin 11Mbps Wireless Win2K Driver;c:\windows\system32\drivers\CW10.sys [2001-6-3 46036]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [2006-11-24 72576]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]

=============== Created Last 30 ================

2009-11-11 22:24:03   0   d-----w-   c:\docume~1\richard\applic~1\jkaildqf
2009-11-11 20:59:18   54156   ---ha-w-   c:\windows\QTFont.qfn
2009-11-11 20:59:18   1409   ----a-w-   c:\windows\QTFont.for
2009-10-27 20:44:26   0   d-----w-   c:\program files\Trend Micro
2009-10-27 20:34:17   73728   ----a-w-   c:\windows\system32\javacpl.cpl
2009-10-27 20:34:17   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-10-27 19:44:21   0   d-----w-   c:\docume~1\richard\applic~1\Malwarebytes
2009-10-27 19:44:08   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-27 19:44:06   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-10-27 19:44:06   0   d-----w-   c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-27 19:44:05   0   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-10-15 21:55:42   0   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-10-15 21:55:24   0   d-----w-   c:\program files\SUPERAntiSpyware
2009-10-15 21:55:23   0   d-----w-   c:\docume~1\richard\applic~1\SUPERAntiSpyware.com
2009-10-15 21:54:30   0   d-----w-   c:\program files\common files\Wise Installation Wizard
2009-10-15 21:48:46   0   d-----w-   c:\program files\CCleaner
2009-10-14 13:29:00   0   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-10-14 13:21:23   0   d-----w-   c:\windows\SQL9_KB970892_ENU

==================== Find3M  ====================

2009-11-03 01:42:06   195456   ------w-   c:\windows\system32\MpSigStub.exe
2009-10-22 09:19:04   5939712   ----a-w-   c:\windows\system32\dllcache\mshtml.dll
2009-10-13 17:29:19   739752   ----a-w-   c:\windows\system32\drivers\vetefile.sys
2009-10-13 17:29:19   133576   ----a-w-   c:\windows\system32\drivers\veteboot.sys
2009-09-11 14:18:39   136192   ----a-w-   c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39   136192   ------w-   c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 21:03:36   58880   ----a-w-   c:\windows\system32\msasn1.dll
2009-09-04 21:03:36   58880   ------w-   c:\windows\system32\dllcache\msasn1.dll
2009-08-28 10:35:52   173056   ----a-w-   c:\windows\system32\dllcache\ie4uinit.exe
2009-08-26 08:00:21   247326   ----a-w-   c:\windows\system32\strmdll.dll
2009-08-26 08:00:21   247326   ------w-   c:\windows\system32\dllcache\strmdll.dll
2009-08-20 19:09:06   1193832   ----a-w-   c:\windows\system32\FM20.DLL
2003-08-27 19:19:18   36963   ----a-r-   c:\program files\common files\SM1updtr.dll
2008-09-18 23:11:55   32768   --sha-w-   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091820080919\index.dat

============= FINISH: 17:26:59.29 ===============
Much better.

Go to Add or Remove Programs and uninstall:

-LiveReg (Symantec Corporation)
-LiveUpdate 1.80 (Symantec Corporation)


----------

If you already have ComboFix be SURE to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below LINKS. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
guzykphi

DDS::
uSearch Page = about:blank
uSearch Bar = about:blank
mSearch Bar =
uSearchURL,(Default) = about:blank
mSearchAssistant = about:blank
BHO: : {2a7edee4-0a75-473e-bb5c-1689fcc69bfe} - c:\windows\system32\pjdfmqz.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
uPolicies-explorer: <NO NAME> =
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: bnwpnphf - pjdfmqz.dll

Folder::
c:\docume~1\richard\applic~1\jkaildqf


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeHere is the ComboFix log:

ComboFix 09-11-13.04 - Richard 11/12/2009 19:31.1.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.395 [GMT -5:00]
Running from: c:\documents and settings\Richard\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Richard\Desktop\CFScript.txt
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\richard\applic~1\jkaildqf
c:\docume~1\richard\applic~1\jkaildqf\profiles.ini
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\cert8.db
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\compatibility.ini
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\compreg.dat
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\cookies.sqlite
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\formhistory.sqlite
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\key3.db
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\localstore.rdf
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\permissions.sqlite
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\places.sqlite-journal
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\places.sqlite
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\pluginreg.dat
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\prefs.js
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\secmod.db
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\webappsstore.sqlite
c:\docume~1\richard\applic~1\jkaildqf\Profiles\i5x1ghrd.default\xpti.dat
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}\chrome.manifest
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}\chrome\content\_cfg.js
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}\chrome\content\c.js
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}\chrome\content\overlay.xul
c:\documents and settings\Richard\Local Settings\Application Data\{858063C5-0C44-460C-8CA1-E35399E01831}\install.rdf
c:\documents and settings\Richard\My Documents\ZbThumbnail.info
c:\program files\malwarebytes' anti-malware\mbam.exe
c:\program files\messenger\msmsgs.exe
c:\windows\Downloaded Program Files\Install.inf
c:\windows\system32\pjdfmqz.dll
c:\windows\system32\pwxzqcpz.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_GUZYKPHI
-------\Legacy_ZESOFT
-------\Service_guzykphi


(((((((((((((((((((((((((   Files Created from 2009-10-13 to 2009-11-13  )))))))))))))))))))))))))))))))
.

2009-11-12 23:22 . 2009-11-12 23:22   --------   d-----w-   c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf
2009-11-06 19:36 . 2009-11-06 19:36   --------   d-----w-   c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf
2009-11-06 19:36 . 2009-11-06 19:36   --------   d-----w-   c:\documents and settings\NetworkService\Application Data\jkaildqf
2009-10-27 20:44 . 2009-10-27 20:44   --------   d-----w-   c:\program files\Trend Micro
2009-10-27 20:34 . 2009-10-27 20:33   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-10-27 20:33 . 2009-10-27 20:33   --------   d-----w-   c:\program files\Java
2009-10-27 20:32 . 2009-10-27 20:32   152576   ----a-w-   c:\documents and settings\Richard\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-27 19:44 . 2009-10-27 19:44   --------   d-----w-   c:\documents and settings\Richard\Application Data\Malwarebytes
2009-10-27 19:44 . 2009-09-10 18:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-27 19:44 . 2009-10-27 19:44   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-27 19:44 . 2009-09-10 18:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-10-27 19:44 . 2009-11-13 00:41   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-10-15 21:56 . 2009-11-11 22:22   117760   ----a-w-   c:\documents and settings\Richard\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-15 21:55 . 2009-10-15 21:55   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-15 21:55 . 2009-10-15 21:55   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-10-15 21:55 . 2009-10-15 21:55   --------   d-----w-   c:\documents and settings\Richard\Application Data\SUPERAntiSpyware.com
2009-10-15 21:54 . 2009-10-15 21:54   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-10-15 21:48 . 2009-10-15 21:48   --------   d-----w-   c:\program files\CCleaner
2009-10-14 13:29 . 2009-10-14 13:29   --------   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-10-14 13:21 . 2009-10-14 13:21   --------   d-----w-   c:\windows\SQL9_KB970892_ENU

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-12 21:52 . 2005-03-19 15:38   --------   d-----w-   c:\documents and settings\All Users\Application Data\Viewpoint
2009-11-12 21:52 . 2002-04-24 06:21   --------   d-----w-   c:\program files\Viewpoint
2009-11-03 01:42 . 2009-10-03 18:04   195456   ------w-   c:\windows\system32\MpSigStub.exe
2009-10-15 21:51 . 2009-04-09 13:54   --------   d-----w-   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-14 13:29 . 2008-09-19 17:43   --------   d-----w-   c:\program files\Microsoft SQL Server
2009-10-13 17:29 . 2009-10-13 17:29   739752   ----a-w-   c:\windows\system32\drivers\vetefile.sys
2009-10-13 17:29 . 2009-10-13 17:29   133576   ----a-w-   c:\windows\system32\drivers\veteboot.sys
2009-10-08 18:25 . 2009-07-05 22:05   --------   d-----w-   c:\documents and settings\All Users\Application Data\Skype
2009-10-08 12:28 . 2009-04-09 13:54   --------   d-----w-   c:\program files\Spybot - Search & Destroy
2009-09-11 14:18 . 2001-08-18 12:00   136192   ----a-w-   c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2001-08-18 12:00   58880   ----a-w-   c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2006-06-23 16:33   916480   ----a-w-   c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2003-08-12 17:55   247326   ----a-w-   c:\windows\system32\strmdll.dll
2009-08-20 19:09 . 2009-08-20 19:09   1193832   ----a-w-   c:\windows\system32\FM20.DLL
2003-08-27 19:19 . 2004-11-25 01:23   36963   ----a-r-   c:\program files\Common Files\SM1updtr.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2002-04-24 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"MMTray"="c:\program files\MusicMatch\MusicMatch Jukebox\mm_tray.exe" [2001-06-13 102400]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"iRiver Updater"="c:\program files\iRiver\iRiver Manager\Updater\Updater.exe" [2004-03-10 204800]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HostManager"="c:\program files\Common Files\AOL\1137856837\ee\AOLHostManager.exe" [2005-08-02 159832]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"DellTouch"="c:\windows\DELLMMKB.EXE" [2001-09-23 163840]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-30 177392]
"CAVRID"="c:\progra~1\CA\ETRUST~1\ETRUST~2\CAVRID.exe" [2009-10-14 230664]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-27 149280]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2003-07-28 323584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-20 113664]
America Online 7.0 Tray Icon.lnk - c:\program files\America Online 7.0\aoltray.exe [2002-4-24 32839]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 Ndcprtns;Ndcprtns;c:\windows\SYSTEM32\DRIVERS\NDCPRTNS.sys [1/1/2001 7:52 PM 9328]
R3 Msikbd2k;DellTouch;c:\windows\SYSTEM32\DRIVERS\Msikbd2k.sys [4/24/2002 1:08 AM 6942]
S3 CW10;Belkin 11Mbps Wireless Win2K Driver;c:\windows\SYSTEM32\DRIVERS\CW10.sys [6/3/2001 9:50 PM 46036]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2009-10-04 c:\windows\Tasks\CAAntiSpywareScan_Daily as DANIEL Daniel C at 11 33 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-05-24 09:53]

2002-04-27 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2003-08-12 00:12]

2009-11-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\windows\System32\VetRedir.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/games/hamsterball/en/raptisoftgameloader.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{0663E32A-7AE7-4652-AEB7-3D86555DEB48} - c:\windows\system32\pwxzqcpz.dll
HKLM-Run-Auto EPSON Stylus CX4800 Series on XPS - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-12 19:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'explorer.exe'(2612)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\windows\system32\devldr32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\CA\ETRUST~1\ETRUST~2\ISafe.exe
c:\windows\System32\CTsvcCDA.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\HPZipm12.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\progra~1\CA\ETRUST~1\ETRUST~2\VetMsg.exe
c:\windows\wanmpsvc.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\AOL\1137856837\ee\AOLServiceHost.exe
c:\program files\Netropa\OSD.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-11-12 20:00 - machine was rebooted
ComboFix-quarantined-files.txt  2009-11-13 00:59

Pre-Run: 10,042,122,240 bytes free
Post-Run: 13,049,155,584 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 92F30C5F4129A49FC7E953CA3C16AD1E
Do you know what these are?

Code: [Select]2009-11-12 23:22 . 2009-11-12 23:22   --------   d-----w-   c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf
2009-11-06 19:36 . 2009-11-06 19:36   --------   d-----w-   c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf
2009-11-06 19:36 . 2009-11-06 19:36   --------   d-----w-   c:\documents and settings\NetworkService\Application Data\jkaildqfNo, I don't know what those are.Download OTM by OldTimer to your desktop.

Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

* Save it to your Desktop.
* Double-click OTM.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code: [Select]:Processes
explorer.exe

:files
c:\documents and settings\NetworkService\Application Data\jkaildqf
c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf
c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf

:Commands
[purity]
[emptytemp]
[start explorer]

* Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

* Close OTM

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes.It did a reboot and here is the log that came up afterwards:

All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
========== FILES ==========
c:\documents and settings\NetworkService\Application Data\jkaildqf\Profiles\6l0od2lm.default\extensions folder moved successfully.
c:\documents and settings\NetworkService\Application Data\jkaildqf\Profiles\6l0od2lm.default folder moved successfully.
c:\documents and settings\NetworkService\Application Data\jkaildqf\Profiles folder moved successfully.
c:\documents and settings\NetworkService\Application Data\jkaildqf folder moved successfully.
c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf\Profiles\6l0od2lm.default folder moved successfully.
c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf\Profiles folder moved successfully.
c:\documents and settings\NetworkService\Local Settings\Application Data\jkaildqf folder moved successfully.
c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf\Profiles\i5x1ghrd.default folder moved successfully.
c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf\Profiles folder moved successfully.
c:\documents and settings\Richard\Local Settings\Application Data\jkaildqf folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Administrator.DANIEL
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: All Users
 
User: Daniel C
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 85121 bytes
 
User: Default User
->Temp folder emptied: 2282767 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Gramps
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Jill
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
 
User: NetworkService
->Temp folder emptied: 896 bytes
->Temporary Internet Files folder emptied: 262211 bytes
 
User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Rachel
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Richard
->Temp folder emptied: 1136299 bytes
->Temporary Internet Files folder emptied: 2311194 bytes
->Java cache emptied: 13689500 bytes
 
%SYSTEMDRIVE% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 58371 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 808 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 10006167 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 28.52 mb
 
 
OTM by OldTimer - Version 3.1.1.0 log created on 11122009_203023

Files moved on Reboot...

Registry entries deleted on Reboot...
Thank you.

Let's do some cleanup and then run a scan to make sure we didn't miss anything.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above PROCEDURE will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

1. Double click OTM to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. When finished exit out of OTM.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan LogFirst things first - Thank you for helping me with this issue.  I appreciate your time and patience.

Here is the ESET log:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy2.zip   Win32/Bagle.gen.zip worm   cleaned by DELETING - quarantined
C:\Program Files\MusicMatch\MusicMatch Jukebox\HWUpdateMove.exe   Win32/Adware.HiWire application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP2\A0000207.exe   Win32/Adware.HiWire application   cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\hpqly.bak   a variant of Win32/Kryptik.NJ trojan   cleaned by deleting - quarantined
Looks good. How is the computer running now?

If there are no malware issues remaining we can finish up.

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
456.

Solve : Data Execution Prevent prevents Userinit Logon Application?

Answer»

So today I began to suspect I had some serious viruses/spyware on my computer. Whatever it was, it wasn't allowing me to run any virus scans. So I restarted my computer in safe mode and was able to run a complete scan with SuperAntiSpyware. After removing about 50 THINGS, it asked me to reboot my computer.

Upon rebooting the computer, I RECEIVED a message that Data Execution Prevention had prevented the Userinit Logon APPLICATION, and after I closed that message, I was faced with just a black screen. I wasn't able to find any way to load Windows Explorer or anything else.

I have tried rebooting in both Safe Mode and in DIRECTORY Services Restore mode but in both cases, I'm told that windows failed to start.

With my other computer I downloaded PC Regedit and BURNT it to a CD, and booted my computer from that disc. I was able to check the registry entry for HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit\C:\WINDOWS\system32\userinit.exe, and it appeared to be present and valid.

I don't know what else to do... I've reached the limit of my own knowledge. Please, can someone suggest a fix for this other than reformatting my computer?

457.

Solve : Can't clean computer?

Answer»

My computer was recently infected by Trojans and malware.

A scan with spybot comes up with two things

Win32.Agent.atta
c:\windows\system32\install.txt

Win32.Agent.wiw
c:\windows\system32\wmdtc.exe

Cleaning and a rescan shows the same problems

A scan with MALWAREBYTES also finds 2 Trojan.Agents . The FILE name is USUALLY different but a clean and rescan shows the same results.

HijackThis finds this
AppInit_DLLs: C:\Windows\System32\rdolib.dll
This also comes back after being deleted

There are also a few files in my c:\windows\temp folder that cant be deleted. Even with malwarebytes fileassassin

mta13187.dll
Perflib_Perfdata_11c.dat
tmp1_557571170276.bk.old
x1c99249.dll

I just get a message saying I need to restart my computer in order to delete those files.

Dangerous processes running in task manager
FastNetSrv.exe
opeia.exe
lsm32.sys



Can't update malwarebytes. Get error code 732 (0, 0)
Can't update windows security essentials - Green progress bar stops at about 25%
Can't download anything through internet explorer.
Can't access any virus scan website - browser is slow
Can download things through windows live messengerhi please try to scan your computer in kaspersky online scanner and remove the virousGo HERE, you will need to follow the DIRECTIONS EXACTLY, a specialist will be with you.do as quantos said , but if you have logs from hjt , mbam and spybot post them HEREI got as far as installing avast. It scanned my computer at boot and found a bunch of stuff. Then as I went to gather the text files a bunch of warning from avast came up. Logs are also missing. A lot of my stuff is infected with Win32 Vitro 

Crap!Win32 Vitro  , i think your in trouble DO NOT do anything until an expert gets in touch with you

458.

Solve : Runtime paced fsg?

Answer»

I was running a scan using Malwarebyte's Anti-Malware and halfway, I got an alert from AVG regarding a Runtime packed FSG threat and it's DIRECTED at Malwarebyte's Anti-Malware. I've INCLUDED a screenshot of the alert.



Should I remove it or just leave it?i WOULD ignore it , if you got mbam here its SAFE

459.

Solve : Blue Screen Of Death! Pro Please Help Me!?

Answer»

Below Is The HIjackThis Log

_______________________________________ _________________________
Logfile of HijackThis v1.99.1
Scan saved at 1:29:01 PM, on 11/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\StormII\stormliv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX20.375\BlueScreenView.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\HijackThis_v1.99.1.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Thunder] C:\Program Files\Thunder Network\Thunder\Program\Thunder.exe -s
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFD64621-70D8-4B14-9D5D-3807C846F71A}: NameServer = 202.188.0.133 202.188.1.5
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Contrl Center of Storm MEDIA (ccosm) - - C:\Program Files\StormII\stormliv.exe
_______________________________________ _____________________________


Its Usually Stop With The Code 0x0000008E, Tcpip.sys(Sometime Afd.sys)
when i Connected to Gaming Platform,Downloading With Download Manager,
Reconnect To Internet And LAN.

Sometime It Stop at 0x00000050 when i TURN on computer in safe mode Or
I shut down computer.

Please help me Cause I not very PRO In solving Computer problem.Welcome to the CH forums.

HJT logs should not be posted in any forum other than the Computer Viruses and Spyware forum.  If you believe your problem is caused by malware please go to this post and follow the advice given.   A CH Authorized Malware Removal Specialist will advise you further.

However here are some probable causes for the Bsod Quote

0x0000008E KERNEL_MODE_EXCEPTION_NOT_HANDLED
   This is a very common bug check. To interpret it, you must identify which exception was GENERATED. May also be reported as 0x1000008E.

Possible causes:

    * Hard disk damage or failure
    * Configuration problems with the BIOS, memory, hard disk, or other devices
    * Incompatible device driver
    * Incompatible software

Further info here.. but you have not posted the ENTIRE displayed error message.

Please read this advice and respond accordingly.

460.

Solve : WinXP will not boot, so I can't get rid of malware...help please?

Answer»

Hello Staff,
My desktop computer was running sluggish,so I looked in task manager and found that SEVERAL processes were taking lots of memory.They include:   msa.exe, b.exe,B.exe and msb.exe.There were several SCVHOST (sp)  taking CPU and memory.

I immediately tried to run my virus scan and spyware removal,neither would open. I borrowed a laptop and searched online for a solution.I found that WinXP had a new safety feature called DEP (Data execution Prevention)that could be preventing my utilities from working. They advised that I temporarily disable the DEP,which I did in  DOS (/noexecute=AlwaysOff).

When I went  to reboot, I had several errors.I think they were rundll errors. When the computer tried to restart,it went to black screen with safe mode,last known good configuration,start windows normally,etc. None of which will work. I burned 2 different boot/rescue cds from the internet. Each of these give a boot failure error MESSAGE (isoLinux: Disk error 80, AX=424D, drive 9F Boot failed: press a key to retry. ...)

So now  I have no idea what  to do. My hope is that I can save my pictures and important documents. Windows XP came installed on the computer (emachine) when I bought it new several years ago, so I have no cds for recovery and it does not have a floppy drive.

Thanks in advance for any help, it is greatly appreciated.The first thing I would do is pull the hard drive out / attach to another computer via external USB case / scan the drive from there for spyware/viruses / once done get your pictures and stuff off.  Now you can start doing recovery operations.

Contact emachines   http://www.emachines.com/corporate/contacts.html   and see if you can get CD's for your machine. 

Hope this helps.

Alan <><  gamblersgirl, I am going to ADVISE you to go HERE and follow the directions EXACTLY.
Thanks Quantos for your response ...read all the posts on the page  that you sent  me to,  but everything required downloads or Windows. My computer will not boot past the black option  screen( safe mode, last known good configuration, start Windows normally,etc). None  of the options  work, the computer just keeps  looping back to the option screen.

So how can I get rid of the viruses and malware on an unbootable computer???

Once again, thanks very much, I do appreciate your help.Follow the directions EXACTLY, a specialist will assist you though.Hello gamblersgirl. I think at this point your main concern is to save your data. The best way to do this is to slave your HDD (harddrive) to another computer as Ale52 suggested in Reply#1.  You can find out how to do that in this link. Once you are able to look at your HDD you will be able to save all your important data to CD's of DVD's. The other PROBLEM with DEP will probably require an OS CD to do the repair.

461.

Solve : Antivirus System Pro = evil?

Answer»

I could use some help getting rid of this and what ever else the logs show.

[Saving space, attachment deleted by admin]1) Have "HijackThis" fix the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and close"HijackThis".Please close any open programs before doing this fix.


Quote

O1 - Hosts: 91.212.127.227 winwarepro.microsoft.com
O1 - Hosts: 91.212.127.227 winwarepro.com
O1 - Hosts: 91.212.127.227 www.winwarepro.com
O2 - BHO: (no name) - {a826543a-f73f-4a65-9989-40f3c0463448} - sivotumo.dll (FILE missing)
O2 - BHO: BHO - {B6D223F6-C185-49a2-BA7E-A03E84744702} - C:\WINDOWS\system32\iehelper.dll
O4 - HKLM\..\Run: [readericon] "C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [tvhsguni] "C:\Documents and Settings\Owner.BKNY.000\Local Settings\Application Data\otedle\uimksysguard.exe"
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [tvhsguni] "C:\Documents and Settings\Owner.BKNY.000\Local Settings\Application Data\otedle\uimksysguard.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: vufagavaw - {52f0b50b-f3c9-44f4-8f81-0f77fc1e836d} - c:\windows\system32\hesowuza.dll (file missing)
O21 - SSODL: momekijow - {c465c337-baef-4ef5-8443-27c34996e5c1} - c:\windows\system32\hesowuza.dll (file missing)
O21 - SSODL: widosedaw - {a94785d7-e1b1-42b9-a011-c632aa77edf2} - c:\windows\system32\hesowuza.dll (file missing)
O21 - SSODL: wokisemim - {6934f180-454b-4c9a-bb21-75b5332e9547} - c:\windows\system32\hesowuza.dll (file missing)
O21 - SSODL: sumumumal - {0de47eed-8590-4834-878d-53af0351440d} - c:\windows\system32\hesowuza.dll (file missing)
O21 - SSODL: goveguwev - {c73abe6a-2696-4c0f-9fb5-ebb6d25f7e52} - c:\windows\system32\wikufalu.dll (file missing)
O21 - SSODL: pibiyalad - {0aa43c82-e118-4d41-a4a8-76e03633cebc} - c:\windows\system32\wikufalu.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {52f0b50b-f3c9-44f4-8f81-0f77fc1e836d} - c:\windows\system32\hesowuza.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {c465c337-baef-4ef5-8443-27c34996e5c1} - c:\windows\system32\hesowuza.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {a94785d7-e1b1-42b9-a011-c632aa77edf2} - c:\windows\system32\hesowuza.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {6934f180-454b-4c9a-bb21-75b5332e9547} - c:\windows\system32\hesowuza.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {0de47eed-8590-4834-878d-53af0351440d} - c:\windows\system32\hesowuza.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {c73abe6a-2696-4c0f-9fb5-ebb6d25f7e52} - c:\windows\system32\wikufalu.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {0aa43c82-e118-4d41-a4a8-76e03633cebc} - c:\windows\system32\wikufalu.dll (file missing)




2) Please download the program HostsXpert

Unzip HostsXpert.zip

It will create a folder named HostsXpert in whatever folder you EXTRACT it to.
Run HostsXpert.exe by double clicking on it.
Click the Make Writeable? button.
Click Restore Microsoft's Hosts File and then click OK.
Click the X to exit the program

Please copy and paste a new Hijackthis log taken after running HostsXpert in your reply




3) Next download RootRepeal.rar and unzip it to your Desktop. You'll NEED WinRAR to extract it

    * Double click RootRepeal.exe to start the program
    * Click on the Report tab at the bottom of the program window
    * Click the Scan button
    * In the Select Scan dialog, check:
          o Drivers
          o Files
          o Processes
          o SSDT
          o Stealth Objects
          o Hidden Services
    * Click the OK button
    * In the next dialog, select all drives showing
    * Click OK to start the scan
 

The scan can take some time. DO NOT run any other programs while the scan is running
*  When the scan is complete, the SAVE Report button will become available
 * Click this and save the report to your Desktop as RootRepeal.txt
 * Go to File, then Exit to close the program
*Attach this log in your next  post.

4) Download DDS by sUBs to your desktop.
Your antivirus software might question the file. If it does, allow it.

    * Double click DDS.scr to run it and wait for the scan to finish
    * When finished DDS.txt will open
    * A small while later, a prompt will open. Answer Yes
    * DDS will continue scanning
    * When done, Attach.txt will open

Copy and paste the DDS.txt and attach Attach.txtHJT Log after HostsXpert was run

[Saving space, attachment deleted by admin]Rootrepeal Log

[Saving space, attachment deleted by admin]Griz, where are the other logs?Please include  DDS.txt and attach.txt as well.
462.

Solve : Sending Logs after following your infection removal instructions?

Answer»

I am copying and pasting the 3 logs created when I followed the directions "Read this before requesting malware removal help."  My problem started with somehow getting ask.com as my browser instead of internet explorer.  A few days later a screen pop-up in red saying Access File is infected" and Trojan Horse Injector.GJ.  It didn't LOOK like my anti-virus program so I didn't do anything about it.  I then tried to get rid of ask.com which I did, but I couldn't get internet explorer back.  My son did some things to it and when I started it back up, I got the exe.bad image messages which led me to search for a resolution which led me to your page.  I followed the instructions exactly and after doing Step 4 (Malwarebytes) scan, the Trojan.vrondo (I didn't write it down at the time) was found and after that was removed the exe. bad image messages stopped.  The computer seems to be working properly now--maybe a little slower.

FOLLOWING are the logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/07/2009 at 09:45 PM

Application Version : 4.29.1004

Core Rules Database Version : 4245
Trace Rules Database Version: 2138

Scan type       : COMPLETE Scan
Total Scan Time : 02:24:14

Memory items scanned      : 518
Memory threats detected   : 0
Registry items scanned    : 6120
Registry threats detected : 2
File items scanned        : 107293
File threats detected     : 5

Adware.Gamevance
   HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}
   HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}

Adware.Tracking Cookie
   C:\Documents and Settings\Candy King\Cookies\[email protected][2].txt
   C:\Documents and Settings\Guest\Cookies\[email protected][1].txt
   C:\Documents and Settings\Guest\Cookies\[email protected][1].txt
   C:\Documents and Settings\Guest\Cookies\[email protected][1].txt
   C:\Documents and Settings\Guest\Cookies\[email protected][2].txt


Malwarebytes' Anti-Malware 1.41
Database version: 3120
Windows 5.1.2600 Service Pack 3

11/7/2009 10:10:46 PM
mbam-log-2009-11-07 (22-10-46).txt

Scan type: Quick Scan
Objects scanned: 108077
Time elapsed: 7 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\vusunifo.dll (Trojan.Vundo) -> Quarantined and deleted sucogfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:42 PM, on 11/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\1205755840\ee\AOLSoftware.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\program files\common files\aol\1205755840\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1205755840\ee\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
c:\program files\common files\aol\1205755840\ee\anotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{631ac2d4-57b3-42b0-a148-da33b462c1a3} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Absolutist Games Toolbar - {631ac2d4-57b3-42b0-a148-da33b462c1a3} - C:\Program Files\Absolutist_Games\tbAbso.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Absolutist Games Toolbar - {631ac2d4-57b3-42b0-a148-da33b462c1a3} - C:\Program Files\Absolutist_Games\tbAbso.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1205755840\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [USRobotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257127350203
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: vusunifo.dll 
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c9f53779ddd44) (gupdate1c9f53779ddd44) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 11493 bytes
cessfully.


you SEEM to have 2 anti-virus installed you should have only one , there could be issues , but wait for an expert

463.

Solve : Help please! Malwarebytes won't run. SAS and HJT Logs included...?

Answer»

Hi there,
So I managed to catch myself a lovely virus (Vundo among others, it would appear).  I first noticed it when I started getting various fake "security" warnings, and then discovered that it has disabled Malwarebytes.  I tried various methods recommended by the folks at Malwarebytes to get it running again but to no avail.  Since then, I have followed all of the procedures listed in the "Read this before requesting malware removal help".  I was, of course, unable to run Malwarebytes but I did everything else (properly I hope!).  Everytime I try to do anything with mbam, I get an error code 2 message and the prgoram won't open.  I'm fresh out of ideas so I'm hoping and praying that you guys might be able to help.  If you would please give me a hand I'd be much obliged.  My logs are attached so please let me know if I can provide any further info.  Thanks in advance!
- Cayti     

[Saving space, attachment deleted by admin]you do not seem to have any anti-virus installed or other security can you NAME what you have Hello.  I have Symantec Anti Virus/Anti spyware, but even though it is updated it didn't find anything yesterday during its weekly full scan.  Even now it is saying "Your computer is protected, no problems detected".  Beats me!  Any ideas?  sorry i'm not an expert , but can you start malware in safe mode , or did you try to rename it


sorry i miss that symantec  No problem!  I have already tried the renaming thing, but that definitely doesn't work.  I will try to run it in safe mode and update with results ASAP. No luck in safe mode unfortunately.  It doesn't seem to even register that I opened it.  No error this time, just nothing!<Removed>

Please don't send users away. EFHello caytidid.

Please DOWNLOAD and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
 
There are 4 different versions. If ONE of them won't run then download and try to run the other one.
 
Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run then try to immediately run the following.
 
Now download and Run exeHelper.

* Please download exeHelper from Raktor to your desktop.
* Double-click on exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the log.txt file to your next message.[/list]

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix

----------

Next post please add:

  • exeHelper log
  • ComboFix log
Hi evilfantasy,
Thanks for the reply and sorry for the delay, I had some trouble disabling all aspects of my antivirus software.  Everything seemed to run fine after that.  I have attached both of the requested logs.  I don't know if this is worth noting or not, but after I ran Combofix and the computer restarted, I got the RUNDLL errors for both hafimiw.dll and c:\windows\system32\rosogobu11.  I'm guessing those are remnants of malware that have been deleted.  Didn't know if it was relevant but I figured full disclosure was best.  Thanks for you help on this!

[Saving space, attachment deleted by admin] Quote from: caytidid on November 07, 2009, 05:29:20 PM
Thanks for you help on this!

Your welcome.

Quote from: caytidid on November 07, 2009, 05:29:20 PM
after I ran Combofix and the computer restarted, I got the RUNDLL errors for both hafimiw.dll and c:\windows\system32\rosogobu11.  I'm guessing those are remnants of malware that have been deleted.  Didn't know if it was relevant but I figured full disclosure was best.

Yes and we will take care of that.


Did you create these folders and files?

Quote
2009-11-07 21:24 . 2009-11-07 21:30   --------   d-----w-   c:\program files\Attempt 6 SM
2009-11-07 18:52 . 2009-11-07 18:53   --------   d-----w-   c:\program files\Attempt 5
2009-11-07 18:24 . 2009-11-07 18:28   --------   d-----w-   c:\program files\Attempt 4
2009-11-07 18:20 . 2009-11-07 18:20   --------   d-----w-   c:\program files\Attempt 3
2009-11-07 14:33 . 2009-11-07 14:33   --------   d-----w-   c:\program files\please work
2009-11-07 05:20 . 2009-11-07 05:20   4045528   ----a-w-   c:\program files\xxxx.exe
2009-11-07 05:12 . 2009-11-07 14:41   --------   d-----w-   c:\program files\MF
2009-11-07 05:07 . 2009-11-07 05:10   --------   d-----w-   c:\program files\MW-upfucker
2009-11-07 05:06 . 2009-11-07 05:06   4045528   ----a-w-   c:\program files\mw-upfucker.exe
2009-10-22 18:12 . 2009-10-22 19:04   --------   d-----w-   c:\program files\lmxiyi
I created all of them while attempting to re-download mbam, except for the last one "lmxiyi".  I don't recognize that one at all and noticed it was created on a different day than the rest.  My apologies for the, ummm, colorful file names.  It was a frustrating day. *blushing*  I can delete them now if you would like me to since they didn't work anyway.    Quote
My apologies for the, ummm, colorful file names.

I'V eseen worse... 

Quote
I can delete them now if you would like me to since they didn't work anyway.

We can do it with ComboFix since we need to run it again anyway.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
c:\program files\xxxx.exe
c:\program files\mw-upfucker.exe

Folder::
c:\program files\Attempt 6 SM
c:\program files\Attempt 5
c:\program files\Attempt 4
c:\program files\Attempt 3
c:\program files\please work
c:\program files\MF
c:\program files\MW-upfucker
c:\program files\lmxiyi

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.

----------

Next post please add:

ComboFix log
Both DDS logs
Done and done!  I attached the Combofix, DDS, and Attach logs rather than copy and pasting them since they are apparently too large to add to the message body.  I hope that's alright.   



[Saving space, attachment deleted by admin]Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the desktop

----------

Go to Add or Remove Programs and uninstall:

- Viewpoint Manager (Remove Only)
- Viewpoint Media Player


----------

We need to use ComboFix again.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -

Folder::
C:\Program Files\Viewpoint
c:\program files\Malwarebytes' Anti-Malware Attempt 2

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

I think we deleted Malwarebytes in that last fix. If it is still installed then update it and run a scan.

Post the log it creates.

If you need to download it again be sure to update it before the scan. Malwarebytes' Anti-Malware (MBAM)



Also let me know how the computer is running now.Good Morning!

I have attached the most recent combofix log as well as the mbam log.  While I was running combofix, i got the following notification "PEV.cfxxe has encountered a problem and needs to close...".  I left it alone because combofix seemed to be running ok.  As far as I can tell, everything seems to be running normally now    Yay! (hopefully that's not a premature celebration)  Let me know if you need anything else and thanks!

 - Cayti

[Saving space, attachment deleted by admin]
464.

Solve : chkdsk /r under recovery...????

Answer»

When I type in chksk /r, do I type in 1?  1 is for D, 3 is for C, which is my MAIN drive.  Which one do I choose?Which one do you WANT to check?I don't know.  In my other POST, Allan told me to put in the number 1 because I cannot get my desktop back.  He said I might have to get the windows XP cd and install it again.  I have no icons taskbars.  I have to access everything through the task manager.If your operating system is installed on the C:\ drive then that's the one you want to check.  I'm not SURE why your configuration isn't typical though.I don't know why it is like that.  This was my son's computer and it has the recovery installed in it. I am going to try it and type in 3 for my C drive.  Is there anything else that I need to know before doing this?Okay, I did the chkdsk /r on my c drive and it didn't help.  Back to square one I don't know what the problem is.  I'm not a specialist for this anyway.

I suggest going to this link, doing exactly what it says and then be patient.  A specialist will be with you.Thank you.  I will try anything.  I don't have the windows xp cd to install it back in.Yes, type 1

465.

Solve : can't get my computer to go into safe mode?

Answer» HELLO i can't run my computer in safe mode  it is  running as good EVER so i don't UNDERSTAND why it wouldn't go into safe mode when
i restart my computer then F8 to go into safe mode it will say
 


multi (0) disk (0) disk (0)ruisk (0) partition (0)\windows\ fonts\vgaoem.fon
multi (0) disk (0) disk (0)ruisk (0) partition (0)\windows\ appatch\ drivai.sdl

it will show like 30 like this one below with alot of short 3 4 and 5 letter words after driver
multi (0) disk (0) disk (0)ruisk (0) partition (0)\windows\ system32\ drivers


About ten minutes LATER it will go threw but not in safemode but it doesn't make that noise like it's shutting of and turning back on no beep are nothing it will quitly go right to were my computer begins  like i just turn it on

i ment to say F8have you tried tapping F8 at start up instead of Ctrl8.
466.

Solve : google redirect..?

Answer»

Quote from: evilfantasy on SEPTEMBER 02, 2009, 08:02:23 PM

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.
i dont mean to question you ef
but why?ComboFix 09-09-02.02 - Customer 09/02/2009 21:18.1.4 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3326.2928 [GMT -5:00]
Running from: c:\documents and settings\Customer\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\driver
c:\windows\Installer\99310b7.msp
c:\windows\Installer\99310c8.msp
c:\windows\system32\BReWErS.dll
c:\windows\system32\drivers\SKYNETrvlsotna.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\SKYNETdlvcctpi.dll
c:\windows\system32\SKYNETkkjdxmqh.dat
c:\windows\system32\SKYNEToybfmoxj.dll
c:\windows\system32\SKYNETxduyvymr.dat


c:\windows\system32\proquota.exe . . . is missing!!

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETpkrobqtl
-------\Legacy_SKYNETpkrobqtl
-------\Legacy_TDSSSERV.SYS
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV


(((((((((((((((((((((((((   Files Created from 2009-08-03 to 2009-09-03  )))))))))))))))))))))))))))))))
.

2009-09-03 01:50 . 2009-09-03 01:50   --------   d-----w-   C:\_OTL
2009-09-02 23:16 . 2009-07-28 21:33   55656   ----a-w-   c:\windows\system32\drivers\avgntflt.sys
2009-09-02 23:16 . 2009-03-30 15:33   96104   ----a-w-   c:\windows\system32\drivers\avipbb.sys
2009-09-02 23:16 . 2009-02-13 17:29   22360   ----a-w-   c:\windows\system32\drivers\avgntmgr.sys
2009-09-02 23:16 . 2009-02-13 17:17   45416   ----a-w-   c:\windows\system32\drivers\avgntdd.sys
2009-09-02 23:16 . 2009-09-02 23:16   --------   d-----w-   c:\program files\Avira
2009-09-02 23:16 . 2009-09-02 23:16   --------   d-----w-   c:\documents and settings\All Users\Application Data\Avira
2009-08-30 16:20 . 2009-08-30 16:20   --------   d-----w-   c:\documents and settings\Customer\Application Data\Software Defender
2009-08-30 16:08 . 2009-08-30 20:20   --------   d-----w-   C:\GameCommanderPro
2009-08-30 16:08 . 2009-08-30 16:08   --------   d-----w-   c:\program files\GameCommanderPro
2009-08-30 06:07 . 2009-08-30 06:07   272   ----a-w-   c:\windows\system32\drivers\sfi.dat
2009-08-30 06:04 . 2009-08-30 06:38   --------   d-----w-   c:\program files\COMODO
2009-08-29 02:46 . 2009-08-29 02:46   --------   d-----w-   c:\program files\ERUNT
2009-08-28 22:21 . 2009-08-28 22:21   120   ----a-w-   c:\documents and settings\Guest\Local Settings\Application Data\Qyinag.dat
2009-08-28 22:15 . 2009-08-28 22:15   --------   d-----w-   c:\documents and settings\Guest\Local Settings\Application Data\{24CA42D1-2CBF-4A3B-BDC8-8C983CEBC299}
2009-08-28 20:57 . 2009-08-29 02:07   120   ----a-w-   c:\windows\Qyinag.dat
2009-08-26 22:29 . 2009-08-26 22:29   --------   d-----w-   c:\program files\Electronic Arts
2009-08-26 21:16 . 2009-08-30 06:05   --------   d-----w-   c:\program files\Lavasoft
2009-08-26 21:16 . 2009-08-26 21:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-20 01:57 . 2009-08-20 01:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-18 22:15 . 2009-08-18 22:21   --------   d-----w-   c:\program files\IDoser v4
2009-08-15 07:12 . 2009-08-15 07:12   --------   d-----w-   c:\program files\JAP
2009-08-14 01:04 . 2009-08-15 05:37   45344   ----a-w-   c:\windows\system32\drivers\tnpfb81.sys
2009-08-14 01:04 . 2009-08-14 01:04   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 10:49 . 2009-06-12 12:31   80896   ------w-   c:\windows\system32\dllcache\tlntsess.exe
2009-08-12 10:49 . 2009-06-12 12:31   76288   ------w-   c:\windows\system32\dllcache\telnet.exe
2009-08-12 10:49 . 2009-06-10 06:14   132096   ------w-   c:\windows\system32\dllcache\wkssvc.dll
2009-08-12 10:48 . 2009-06-10 14:13   84992   ------w-   c:\windows\system32\dllcache\avifil32.dll
2009-08-12 10:48 . 2009-07-17 19:01   58880   ------w-   c:\windows\system32\dllcache\atl.dll
2009-08-12 10:48 . 2009-08-05 09:01   204800   ------w-   c:\windows\system32\dllcache\mswebdvd.dll
2009-08-12 10:38 . 2009-07-10 13:27   1315328   ------w-   c:\windows\system32\dllcache\msoe.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 20:28 . 2009-03-21 20:51   --------   d-----w-   c:\documents and settings\All Users\Application Data\Google Updater
2009-09-01 02:03 . 2008-11-21 22:54   --------   d-----w-   c:\documents and settings\Customer\Application Data\LimeWire
2009-08-31 20:35 . 2008-05-03 00:28   --------   d-----w-   c:\documents and settings\Customer\Application Data\uTorrent
2009-08-31 20:35 . 2009-04-29 01:03   --------   d-----w-   c:\program files\World of Warcraft
2009-08-31 04:20 . 2008-11-20 05:05   --------   d-----w-   c:\program files\Defraggler
2009-08-29 02:33 . 2009-05-15 18:52   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-08-18 22:33 . 2008-04-04 04:22   --------   d-----w-   c:\program files\LimeWire
2009-08-15 07:09 . 2009-06-09 22:13   --------   d-----w-   c:\documents and settings\Customer\Application Data\Mumble
2009-08-14 01:07 . 2008-11-20 04:15   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-08-05 09:01 . 2004-08-12 06:00   204800   ----a-w-   c:\windows\system32\mswebdvd.dll
2009-08-03 23:41 . 2009-08-03 05:47   --------   d-----w-   c:\documents and settings\All Users\Application Data\NOS
2009-08-03 18:36 . 2008-11-20 04:15   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2008-11-20 04:15   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-08-03 06:57 . 2009-08-03 05:53   --------   d-----w-   c:\documents and settings\Customer\Application Data\Music Editor Free
2009-08-03 06:39 . 2009-08-03 05:47   --------   d-----w-   c:\program files\NOS
2009-08-03 05:53 . 2009-08-03 05:53   --------   d-----w-   c:\program files\Music Editor Free
2009-08-03 01:22 . 2009-08-03 01:22   --------   d-----w-   c:\documents and settings\Customer\Application Data\Nero
2009-08-03 01:21 . 2009-08-03 01:21   --------   d-----w-   c:\program files\Common Files\Nero
2009-08-03 01:21 . 2009-03-06 23:21   --------   d-----w-   c:\program files\Nero
2009-08-03 01:21 . 2009-08-03 01:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\Nero
2009-07-31 08:46 . 2009-07-31 08:46   --------   d-----w-   c:\documents and settings\Guest\Application Data\SteelSeries
2009-07-31 02:04 . 2009-07-30 22:13   25   ----a-w-   c:\windows\popcinfot.dat
2009-07-30 22:12 . 2009-07-30 22:12   --------   d-----w-   c:\documents and settings\All Users\Application Data\PopCap Games
2009-07-30 22:12 . 2009-07-30 08:04   --------   d-----w-   c:\program files\PopCap Games
2009-07-30 06:54 . 2009-07-30 06:54   --------   d-----w-   c:\program files\iTunes
2009-07-30 06:54 . 2009-07-30 06:54   --------   d-----w-   c:\program files\iPod
2009-07-30 06:54 . 2008-04-03 23:32   --------   d-----w-   c:\program files\Common Files\Apple
2009-07-30 06:19 . 2009-07-30 06:19   --------   d-----w-   c:\documents and settings\Customer\Application Data\SteelSeries
2009-07-30 06:19 . 2009-07-30 06:19   --------   d-----w-   c:\program files\SteelSeries
2009-07-30 06:19 . 2008-04-02 19:19   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-07-19 20:03 . 2009-07-19 20:03   --------   d-----w-   c:\program files\EVGA Precision
2009-07-19 10:20 . 2009-07-19 10:20   --------   d-----w-   c:\documents and settings\All Users\Application Data\PassMark
2009-07-19 09:44 . 2008-04-04 06:42   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-07-19 09:08 . 2009-05-01 22:52   --------   d-----w-   c:\program files\Pando Networks
2009-07-19 02:32 . 2009-07-19 02:32   --------   d-----w-   c:\program files\Alex Feinman
2009-07-17 19:01 . 2004-08-12 06:00   58880   ----a-w-   c:\windows\system32\atl.dll
2009-07-16 09:32 . 2009-05-21 06:07   --------   d---a-w-   c:\documents and settings\All Users\Application Data\TEMP
2009-07-13 15:08 . 2004-08-12 06:00   286720   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-12 20:59 . 2009-06-17 20:23   1324   ----a-w-   c:\windows\system32\d3d9caps.dat
2009-07-10 21:21 . 2009-07-09 19:20   --------   d-----w-   c:\program files\World of Warcraft Public Test
2009-07-09 19:40 . 2009-05-01 22:54   --------   d-----w-   c:\program files\Common Files\Blizzard Entertainment
2009-07-03 17:09 . 2007-04-24 19:05   915456   ----a-w-   c:\windows\system32\wininet.dll
2009-06-21 13:46 . 2008-04-02 19:11   485920   ----a-w-   c:\windows\system32\NVUNINST.EXE
2009-06-16 14:36 . 2007-04-24 19:05   119808   ----a-w-   c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2007-04-24 19:03   81920   ----a-w-   c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-12 06:00   80896   ----a-w-   c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-05-10 17:51   76288   ----a-w-   c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2008-04-03 08:56   2066432   ----a-w-   c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-12 06:00   84992   ----a-w-   c:\windows\system32\avifil32.dll
2009-06-10 13:28 . 2009-06-10 13:28   3510272   ----a-w-   c:\windows\system32\nvgames.dll
2009-06-10 13:28 . 2009-06-10 13:28   4022272   ----a-w-   c:\windows\system32\nvdisps.dll
2009-06-10 13:28 . 2009-06-10 13:28   86016   ----a-w-   c:\windows\system32\nvmctray.dll
2009-06-10 13:28 . 2009-06-10 13:28   168004   ----a-w-   c:\windows\system32\nvsvc32.exe
2009-06-10 13:28 . 2009-06-10 13:28   143360   ----a-w-   c:\windows\system32\nvcolor.exe
2009-06-10 13:28 . 2009-06-10 13:28   13758464   ----a-w-   c:\windows\system32\nvcpl.dll
2009-06-10 13:28 . 2009-06-10 13:28   229376   ----a-w-   c:\windows\system32\nvmccs.dll
2009-06-10 11:03 . 2009-06-10 11:03   1580550   ----a-w-   c:\windows\system32\nvdata.bin
2009-06-10 11:03 . 2009-06-10 11:03   1310720   ----a-w-   c:\windows\system32\nvcuvenc.dll
2009-06-10 11:03 . 2009-03-27 15:03   671744   ----a-w-   c:\windows\system32\nvcuvid.dll
2009-06-10 11:03 . 2008-12-25 16:08   9998336   ----a-w-   c:\windows\system32\nvoglnt.dll
2009-06-10 11:03 . 2008-12-25 16:08   815104   ----a-w-   c:\windows\system32\nvapi.dll
2009-06-10 11:03 . 2008-12-25 16:08   1720320   ----a-w-   c:\windows\system32\nvcuda.dll
2009-06-10 11:03 . 2008-12-25 16:08   151552   ----a-w-   c:\windows\system32\nvcodins.dll
2009-06-10 11:03 . 2008-12-25 16:08   151552   ----a-w-   c:\windows\system32\nvcod.dll
2009-06-10 11:03 . 2008-04-02 19:45   457248   ----a-w-   c:\windows\system32\nvudisp.exe
2009-06-10 11:03 . 2007-12-07 05:51   8087712   ----a-w-   c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 11:03 . 2007-12-07 05:51   5908608   ----a-w-   c:\windows\system32\nv4_disp.dll
2009-06-10 06:14 . 2007-04-24 19:05   132096   ----a-w-   c:\windows\system32\wkssvc.dll
2009-06-05 16:42 . 2009-03-14 19:00   2060288   ----a-w-   c:\windows\system32\usbaaplrc.dll
2009-06-05 16:42 . 2008-10-25 19:48   39424   ----a-w-   c:\windows\system32\drivers\usbaapl.sys
2004-08-12 06:00 . 2008-07-18 07:52   73728   --sha-w-   c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.

------- Sigcheck -------

[7] 2004-08-12 06:00   502272   01C3346C241652F43AED8E2149881BFE   c:\windows\$NtServicePackUninstall$\winlogon.exe
[7] 2008-04-14 00:12   507904   ED0EF0A136DEC83DF69F04118870003E   c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-11-18 00:50   507904   3969440BA384D35317DBBDEEAAE641CE   c:\windows\system32\winlogon.exe

[-] 2007-04-24 19:05   295424   C29A5286E64D97385178452D5F307B98   c:\windows\$NtServicePackUninstall$\termsrv.dll
[7] 2008-04-14 00:12   295424   FF3477C03BE7201C294C35F684B3479F   c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-11-18 00:50   295424   63999D0ABD8DABFD76A9C07F6E104868   c:\windows\system32\termsrv.dll


c:\windows\system32\drivers\beep.sys ... is missing !!
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-30 1935360]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2009-04-28 298000]
"SteelSeries World of Warcraft MMO Gaming Mouse"="c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2009-05-13 414720]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\joelonion\\counter-strike\\hl.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\joelonion\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.3.9183-to-3.0.8.9464-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.2.0.10048-to-0.2.0.10072-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.2.0.10072-to-0.2.0.10083-enUS-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 2:22 PM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/2/2009 6:16 PM 108289]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [7/30/2009 1:19 AM 11136]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [4/3/2008 5:39 PM 45440]
S0 tnpfb81;tnpfb81;\SystemRoot\\SystemRoot\System32\drivers\tnpfb81.sys --> \SystemRoot\\SystemRoot\System32\drivers\tnpfb81.sys [?]
S1 4180b6ce.sys;4180b6ce.sys;\??\c:\windows\System32\drivers\4180b6ce.sys --> c:\windows\System32\drivers\4180b6ce.sys [?]
S2 gupdate1c9aa6717e65336;Google Update Service (gupdate1c9aa6717e65336);c:\program files\Google\Update\GoogleUpdate.exe [3/21/2009 3:53 PM 133104]
S3 JmtFltr;n52te;c:\windows\system32\Drivers\JmtFltr.sys --> c:\windows\system32\Drivers\JmtFltr.sys [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [12/4/2008 10:36 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]
S3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [4/3/2008 5:33 PM 19020]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;

S3 vhack;vhack;\??\c:\docume~1\Customer\LOCALS~1\Temp\Rar$EX25.2579\vhack.sys --> c:\docume~1\Customer\LOCALS~1\Temp\Rar$EX25.2579\vhack.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - RTCORE32
*Deregistered* - RTCore32

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]

2009-09-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-21 20:51]

2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 20:53]

2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 20:53]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-PlayNC Launcher - (no file)
MSConfigStartUp-TrueImageMonitor - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.curse.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} - hxxp://webserver.dyyno.com/tng/dyyno-client/DyynoCAB.CAB
DPF: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - hxxp://www.octoshape.com/files/octosetupGotFrag.cab
DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} - hxxp://www.srtest.com/srl_bin/sysreqlab_test.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\lx4hbh99.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 21:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-484763869-1202660629-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-484763869-1202660629-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:4c,77,61,19,2a,84,09,02,a9,ac,0b,91,31,61,c5,0a,60,69,6b,57,8a,
   4e,74,6a,08,10,98,6e,44,f3,19,27,49,2a,d6,87,55,12,92,35,8d,00,ed,63,fe,74,\
"rkeysecu"=hex:6f,c1,8d,4f,4c,7c,a4,72,e4,e6,0b,91,d2,83,44,ef

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
Denied: (A 2) (Everyone)
="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(732)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3152)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
.
**************************************************************************
.
Completion time: 2009-09-03 21:35 - machine was rebooted
ComboFix-quarantined-files.txt  2009-09-03 02:35

Pre-Run: 127,226,544,128 bytes free
Post-Run: 127,111,868,416 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /PAE

353   --- E O F ---   2009-09-02 20:28




Sorry it took so long, i went as fast as i could. Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
tnpfb81
4180b6ce.sys

FCopy::
C:\WINDOWS\ServicePackFiles\i386\proquota.exe | c:\windows\system32\proquota.exe
C:\WINDOWS\ServicePackFiles\i386\beep.sys | c:\windows\system32\drivers\beep.sys


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the SCREENSHOT below. Important: PERFORM this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 09-09-02.02 - Customer 09/02/2009 21:55.2.4 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3326.2878 [GMT -5:00]
Running from: c:\documents and settings\Customer\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Customer\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.


.
--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\proquota.exe --> c:\windows\system32\proquota.exe
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_4180b6ce.sys
-------\Service_tnpfb81


(((((((((((((((((((((((((   Files Created from 2009-08-03 to 2009-09-03  )))))))))))))))))))))))))))))))
.

2009-09-03 02:55 . 2008-04-14 00:12   50176   ----a-w-   c:\windows\system32\proquota.exe
2009-09-03 02:55 . 2008-04-14 00:12   50176   ----a-w-   c:\windows\system32\dllcache\proquota.exe
2009-09-03 01:50 . 2009-09-03 01:50   --------   d-----w-   C:\_OTL
2009-09-02 23:16 . 2009-07-28 21:33   55656   ----a-w-   c:\windows\system32\drivers\avgntflt.sys
2009-09-02 23:16 . 2009-03-30 15:33   96104   ----a-w-   c:\windows\system32\drivers\avipbb.sys
2009-09-02 23:16 . 2009-02-13 17:29   22360   ----a-w-   c:\windows\system32\drivers\avgntmgr.sys
2009-09-02 23:16 . 2009-02-13 17:17   45416   ----a-w-   c:\windows\system32\drivers\avgntdd.sys
2009-09-02 23:16 . 2009-09-02 23:16   --------   d-----w-   c:\program files\Avira
2009-09-02 23:16 . 2009-09-02 23:16   --------   d-----w-   c:\documents and settings\All Users\Application Data\Avira
2009-08-30 16:20 . 2009-08-30 16:20   --------   d-----w-   c:\documents and settings\Customer\Application Data\Software Defender
2009-08-30 16:08 . 2009-08-30 20:20   --------   d-----w-   C:\GameCommanderPro
2009-08-30 16:08 . 2009-08-30 16:08   --------   d-----w-   c:\program files\GameCommanderPro
2009-08-30 06:07 . 2009-08-30 06:07   272   ----a-w-   c:\windows\system32\drivers\sfi.dat
2009-08-30 06:04 . 2009-08-30 06:38   --------   d-----w-   c:\program files\COMODO
2009-08-29 02:46 . 2009-08-29 02:46   --------   d-----w-   c:\program files\ERUNT
2009-08-28 22:21 . 2009-08-28 22:21   120   ----a-w-   c:\documents and settings\Guest\Local Settings\Application Data\Qyinag.dat
2009-08-28 22:15 . 2009-08-28 22:15   --------   d-----w-   c:\documents and settings\Guest\Local Settings\Application Data\{24CA42D1-2CBF-4A3B-BDC8-8C983CEBC299}
2009-08-28 20:57 . 2009-08-29 02:07   120   ----a-w-   c:\windows\Qyinag.dat
2009-08-26 22:29 . 2009-08-26 22:29   --------   d-----w-   c:\program files\Electronic Arts
2009-08-26 21:16 . 2009-08-30 06:05   --------   d-----w-   c:\program files\Lavasoft
2009-08-26 21:16 . 2009-08-26 21:29   --------   d-----w-   c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-20 01:57 . 2009-08-20 01:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-18 22:15 . 2009-08-18 22:21   --------   d-----w-   c:\program files\IDoser v4
2009-08-15 07:12 . 2009-08-15 07:12   --------   d-----w-   c:\program files\JAP
2009-08-14 01:04 . 2009-08-15 05:37   45344   ----a-w-   c:\windows\system32\drivers\tnpfb81.sys
2009-08-14 01:04 . 2009-08-14 01:04   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 10:49 . 2009-06-12 12:31   80896   ------w-   c:\windows\system32\dllcache\tlntsess.exe
2009-08-12 10:49 . 2009-06-12 12:31   76288   ------w-   c:\windows\system32\dllcache\telnet.exe
2009-08-12 10:49 . 2009-06-10 06:14   132096   ------w-   c:\windows\system32\dllcache\wkssvc.dll
2009-08-12 10:48 . 2009-06-10 14:13   84992   ------w-   c:\windows\system32\dllcache\avifil32.dll
2009-08-12 10:48 . 2009-07-17 19:01   58880   ------w-   c:\windows\system32\dllcache\atl.dll
2009-08-12 10:48 . 2009-08-05 09:01   204800   ------w-   c:\windows\system32\dllcache\mswebdvd.dll
2009-08-12 10:38 . 2009-07-10 13:27   1315328   ------w-   c:\windows\system32\dllcache\msoe.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 20:28 . 2009-03-21 20:51   --------   d-----w-   c:\documents and settings\All Users\Application Data\Google Updater
2009-09-01 02:03 . 2008-11-21 22:54   --------   d-----w-   c:\documents and settings\Customer\Application Data\LimeWire
2009-08-31 20:35 . 2008-05-03 00:28   --------   d-----w-   c:\documents and settings\Customer\Application Data\uTorrent
2009-08-31 20:35 . 2009-04-29 01:03   --------   d-----w-   c:\program files\World of Warcraft
2009-08-31 04:20 . 2008-11-20 05:05   --------   d-----w-   c:\program files\Defraggler
2009-08-29 02:33 . 2009-05-15 18:52   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-08-18 22:33 . 2008-04-04 04:22   --------   d-----w-   c:\program files\LimeWire
2009-08-15 07:09 . 2009-06-09 22:13   --------   d-----w-   c:\documents and settings\Customer\Application Data\Mumble
2009-08-14 01:07 . 2008-11-20 04:15   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-08-05 09:01 . 2004-08-12 06:00   204800   ----a-w-   c:\windows\system32\mswebdvd.dll
2009-08-03 23:41 . 2009-08-03 05:47   --------   d-----w-   c:\documents and settings\All Users\Application Data\NOS
2009-08-03 18:36 . 2008-11-20 04:15   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2008-11-20 04:15   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-08-03 06:57 . 2009-08-03 05:53   --------   d-----w-   c:\documents and settings\Customer\Application Data\Music Editor Free
2009-08-03 06:39 . 2009-08-03 05:47   --------   d-----w-   c:\program files\NOS
2009-08-03 05:53 . 2009-08-03 05:53   --------   d-----w-   c:\program files\Music Editor Free
2009-08-03 01:22 . 2009-08-03 01:22   --------   d-----w-   c:\documents and settings\Customer\Application Data\Nero
2009-08-03 01:21 . 2009-08-03 01:21   --------   d-----w-   c:\program files\Common Files\Nero
2009-08-03 01:21 . 2009-03-06 23:21   --------   d-----w-   c:\program files\Nero
2009-08-03 01:21 . 2009-08-03 01:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\Nero
2009-07-31 08:46 . 2009-07-31 08:46   --------   d-----w-   c:\documents and settings\Guest\Application Data\SteelSeries
2009-07-31 02:04 . 2009-07-30 22:13   25   ----a-w-   c:\windows\popcinfot.dat
2009-07-30 22:12 . 2009-07-30 22:12   --------   d-----w-   c:\documents and settings\All Users\Application Data\PopCap Games
2009-07-30 22:12 . 2009-07-30 08:04   --------   d-----w-   c:\program files\PopCap Games
2009-07-30 06:54 . 2009-07-30 06:54   --------   d-----w-   c:\program files\iTunes
2009-07-30 06:54 . 2009-07-30 06:54   --------   d-----w-   c:\program files\iPod
2009-07-30 06:54 . 2008-04-03 23:32   --------   d-----w-   c:\program files\Common Files\Apple
2009-07-30 06:19 . 2009-07-30 06:19   --------   d-----w-   c:\documents and settings\Customer\Application Data\SteelSeries
2009-07-30 06:19 . 2009-07-30 06:19   --------   d-----w-   c:\program files\SteelSeries
2009-07-30 06:19 . 2008-04-02 19:19   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-07-19 20:03 . 2009-07-19 20:03   --------   d-----w-   c:\program files\EVGA Precision
2009-07-19 10:20 . 2009-07-19 10:20   --------   d-----w-   c:\documents and settings\All Users\Application Data\PassMark
2009-07-19 09:44 . 2008-04-04 06:42   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-07-19 09:08 . 2009-05-01 22:52   --------   d-----w-   c:\program files\Pando Networks
2009-07-19 02:32 . 2009-07-19 02:32   --------   d-----w-   c:\program files\Alex Feinman
2009-07-17 19:01 . 2004-08-12 06:00   58880   ----a-w-   c:\windows\system32\atl.dll
2009-07-16 09:32 . 2009-05-21 06:07   --------   d---a-w-   c:\documents and settings\All Users\Application Data\TEMP
2009-07-13 15:08 . 2004-08-12 06:00   286720   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-12 20:59 . 2009-06-17 20:23   1324   ----a-w-   c:\windows\system32\d3d9caps.dat
2009-07-10 21:21 . 2009-07-09 19:20   --------   d-----w-   c:\program files\World of Warcraft Public Test
2009-07-09 19:40 . 2009-05-01 22:54   --------   d-----w-   c:\program files\Common Files\Blizzard Entertainment
2009-07-03 17:09 . 2007-04-24 19:05   915456   ------w-   c:\windows\system32\wininet.dll
2009-06-21 13:46 . 2008-04-02 19:11   485920   ----a-w-   c:\windows\system32\NVUNINST.EXE
2009-06-16 14:36 . 2007-04-24 19:05   119808   ----a-w-   c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2007-04-24 19:03   81920   ----a-w-   c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-12 06:00   80896   ----a-w-   c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-05-10 17:51   76288   ----a-w-   c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2008-04-03 08:56   2066432   ----a-w-   c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-12 06:00   84992   ----a-w-   c:\windows\system32\avifil32.dll
2009-06-10 13:28 . 2009-06-10 13:28   3510272   ----a-w-   c:\windows\system32\nvgames.dll
2009-06-10 13:28 . 2009-06-10 13:28   4022272   ----a-w-   c:\windows\system32\nvdisps.dll
2009-06-10 13:28 . 2009-06-10 13:28   86016   ----a-w-   c:\windows\system32\nvmctray.dll
2009-06-10 13:28 . 2009-06-10 13:28   168004   ----a-w-   c:\windows\system32\nvsvc32.exe
2009-06-10 13:28 . 2009-06-10 13:28   143360   ----a-w-   c:\windows\system32\nvcolor.exe
2009-06-10 13:28 . 2009-06-10 13:28   13758464   ----a-w-   c:\windows\system32\nvcpl.dll
2009-06-10 13:28 . 2009-06-10 13:28   229376   ----a-w-   c:\windows\system32\nvmccs.dll
2009-06-10 11:03 . 2009-06-10 11:03   1580550   ----a-w-   c:\windows\system32\nvdata.bin
2009-06-10 11:03 . 2009-06-10 11:03   1310720   ----a-w-   c:\windows\system32\nvcuvenc.dll
2009-06-10 11:03 . 2009-03-27 15:03   671744   ----a-w-   c:\windows\system32\nvcuvid.dll
2009-06-10 11:03 . 2008-12-25 16:08   9998336   ----a-w-   c:\windows\system32\nvoglnt.dll
2009-06-10 11:03 . 2008-12-25 16:08   815104   ----a-w-   c:\windows\system32\nvapi.dll
2009-06-10 11:03 . 2008-12-25 16:08   1720320   ----a-w-   c:\windows\system32\nvcuda.dll
2009-06-10 11:03 . 2008-12-25 16:08   151552   ----a-w-   c:\windows\system32\nvcodins.dll
2009-06-10 11:03 . 2008-12-25 16:08   151552   ----a-w-   c:\windows\system32\nvcod.dll
2009-06-10 11:03 . 2008-04-02 19:45   457248   ----a-w-   c:\windows\system32\nvudisp.exe
2009-06-10 11:03 . 2007-12-07 05:51   8087712   ----a-w-   c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 11:03 . 2007-12-07 05:51   5908608   ----a-w-   c:\windows\system32\nv4_disp.dll
2009-06-10 06:14 . 2007-04-24 19:05   132096   ----a-w-   c:\windows\system32\wkssvc.dll
2009-06-05 16:42 . 2009-03-14 19:00   2060288   ----a-w-   c:\windows\system32\usbaaplrc.dll
2009-06-05 16:42 . 2008-10-25 19:48   39424   ----a-w-   c:\windows\system32\drivers\usbaapl.sys
2004-08-12 06:00 . 2008-07-18 07:52   73728   --sha-w-   c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.

------- Sigcheck -------

[7] 2004-08-12 06:00   502272   01C3346C241652F43AED8E2149881BFE   c:\windows\$NtServicePackUninstall$\winlogon.exe
[7] 2008-04-14 00:12   507904   ED0EF0A136DEC83DF69F04118870003E   c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-11-18 00:50   507904   3969440BA384D35317DBBDEEAAE641CE   c:\windows\system32\winlogon.exe

[-] 2007-04-24 19:05   295424   C29A5286E64D97385178452D5F307B98   c:\windows\$NtServicePackUninstall$\termsrv.dll
[7] 2008-04-14 00:12   295424   FF3477C03BE7201C294C35F684B3479F   c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-11-18 00:50   295424   63999D0ABD8DABFD76A9C07F6E104868   c:\windows\system32\termsrv.dll


c:\windows\system32\drivers\beep.sys ... is missing !!
.
(((((((((((((((((((((((((((((   [email protected]_02.33.12   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-03 03:01 . 2009-09-03 03:01   16384              c:\windows\temp\Perflib_Perfdata_750.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-30 1935360]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2009-04-28 298000]
"SteelSeries World of Warcraft MMO Gaming Mouse"="c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2009-05-13 414720]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\joelonion\\counter-strike\\hl.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\joelonion\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.3.9183-to-3.0.8.9464-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.2.0.10048-to-0.2.0.10072-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.2.0.10072-to-0.2.0.10083-enUS-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 2:22 PM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/2/2009 6:16 PM 108289]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [7/30/2009 1:19 AM 11136]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [4/3/2008 5:39 PM 45440]
S2 gupdate1c9aa6717e65336;Google Update Service (gupdate1c9aa6717e65336);c:\program files\Google\Update\GoogleUpdate.exe [3/21/2009 3:53 PM 133104]
S3 JmtFltr;n52te;c:\windows\system32\Drivers\JmtFltr.sys --> c:\windows\system32\Drivers\JmtFltr.sys [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [12/4/2008 10:36 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]
S3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [4/3/2008 5:33 PM 19020]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;

S3 vhack;vhack;\??\c:\docume~1\Customer\LOCALS~1\Temp\Rar$EX25.2579\vhack.sys --> c:\docume~1\Customer\LOCALS~1\Temp\Rar$EX25.2579\vhack.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - RTCORE32
*Deregistered* - RTCore32

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]

2009-09-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-21 20:51]

2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 20:53]

2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 20:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.curse.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} - hxxp://webserver.dyyno.com/tng/dyyno-client/DyynoCAB.CAB
DPF: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - hxxp://www.octoshape.com/files/octosetupGotFrag.cab
DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} - hxxp://www.srtest.com/srl_bin/sysreqlab_test.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\lx4hbh99.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 22:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-484763869-1202660629-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-484763869-1202660629-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:4c,77,61,19,2a,84,09,02,a9,ac,0b,91,31,61,c5,0a,60,69,6b,57,8a,
   4e,74,6a,08,10,98,6e,44,f3,19,27,49,2a,d6,87,55,12,92,35,8d,00,ed,63,fe,74,\
"rkeysecu"=hex:6f,c1,8d,4f,4c,7c,a4,72,e4,e6,0b,91,d2,83,44,ef

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
Denied: (A 2) (Everyone)
="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(732)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1548)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
.
**************************************************************************
.
Completion time: 2009-09-03 22:03 - machine was rebooted
ComboFix-quarantined-files.txt  2009-09-03 03:03
ComboFix2.txt  2009-09-03 02:35

Pre-Run: 127,085,703,168 bytes free
Post-Run: 127,048,708,096 bytes free

312   --- E O F ---   2009-09-02 20:28


There ya go.Save the attached file to your desktop. Unzip it and place the beep.sys file in you Drivers folder.

C:\WINDOWS\system32\drivers <- Place it in this folder.

Let me know how the computer is running now.



[attachment deleted by admin]no more redirects, gonna check safe mode. Safe mode is working, but it's still asking me if i want to load, or press cancel to stop loading SPTD.sys... not sure what that is.
Wep pages are pulling up significantly faster..

Any advice for keeping protected against that stuff in the future?

P.S. i live in oklahoma too, in Shattuck, northwest panhandle Quote from: onion on September 02, 2009, 09:16:46 PM
Safe mode is working, but it's still asking me if i want to load, or press cancel to stop loading SPTD.sys... not sure what that is.

See here: http://www.bleepingcomputer.com/startups/sptd.sys-13477.html

Quote
Any advice for keeping protected against that stuff in the future?

We'll get to that at the end.

Quote
P.S. i live in oklahoma too, in Shattuck, northwest panhandle

Other side of the state...

Let's clean up a little and then check to see if we missed anything.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Double click OTL

* Click the CleanUp! button.
* Select Yes when the "Begin cleanup Process?" prompt appears.
* If you are prompted to Reboot during the cleanup, select Yes
* The tool will delete itself once it finishes.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Kaspersky Lab Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

If needed, this animation will guide you through the process.updating the kaspersky online thing right now, but i got college in the morning at 8:00 so i gotta hit the sack, thanks man. Ill post the scan log tomorrow around 4pm.
again, THANK YOU. No problem. I'll be signing off soon also.Kaspersky didn't find a single thing.Sounds like we nailed it then. Good job!

Time to finish up.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Quote from: evilfantasy on September 02, 2009, 07:13:30 PM
Please don't ask for malicious links to be posted.

onion - Give me a few minutes to look at your logs and I will reply.

im sorry, i just wanted to know what the redirects said. your doin a good job, evilToo many people click first and think second so it's risky. If they are needed to be posted then have them disable the links by adding xx into the http. > hxxp
467.

Solve : Blue screen problem- not what you think?

Answer»

im not GREAT with computers so here it is...
When i turn on my laptop (hp pav vista) it wont load past the microsoft corporation loading bar- i dont reach the logon screen or desktop, instead i get a couple of flickers of black boxes which then disappear completely,
and then all i get is a blank blue screen- its not a blue screen of death- its more of a purpley blue and its got no writing on it at all and all i can see is the mouse.
 It started when my computer apparently blocked a bunch of viruses, trojans and after that it didnt recover. i tried system restore but that didnt work and when i go into safe mode i get a completely black screen except  for 'safe mode' in each corner and microsoft at TOP - no task manager with ctrl ALT delete no start or anything.
 Ive also tried the using settings from an earlier DATE option and system repair and ive restarted my computer a million times, made sure its not low on POWER, but nothing ive done works...plz help  Boot to your AV CD and run a scan at boot

468.

Solve : SUPERAntiSpyware Pro Giveaway?

Answer»

I have one Free SUPERAntiSpyware PROFESSIONAL Edition Lifetime Key to give away.

If you are interested then visit my blog here: SUPERAntiSpyware Pro Giveaway  evilfantasy’s blog

Ends in the after noon of Tuesday September 1st 2009

Be SURE to read the rules for ENTRY carefully. If I don't know your Digg username I can't match you up with the comments on the blog.Winner ANNOUNCED. hydrocarbon000 is the winner.

Thank you to everybody who joined in.

http://evilfantasy.wordpress.com/2009/08/27/superantispyware-pro-giveaway/

469.

Solve : TotalSecure and hijacked desktop?

Answer»

You are most WELCOME.....If you're SURE that your COMPUTER has been cleaned you will need to reset your SYSTEM Restore point to ensure that you don't become re-infected again.

470.

Solve : Hijack this - need a little help?

Answer»

I went through all the processes for removing malware, etc.  The HIJACK this analyzer wanted me to remove the "no value strings" in internet explorer (RO) but when I tried they just stayed there.  I can not log in to any sites.  I can go online and do anything else but when I try to log in to sites I get "internet explorer can not display"...

Thanks for any advise!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:20 PM, on 1/4/2002
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 4182 bytes
you hjt log is clean Thank you.I don't know how to cure an INFECTED computer but I did note your log has an incorrect date and just wander why? Is your system CLOCK correct?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:20 PM, on 1/4/2002maybe sajack reset the cmos Quote from: lectrocrew on September 01, 2009, 06:39:15 PM

Is your system clock correct?
I just corrected the system clock, but I still have all the same "symptoms".wait for an expert to advise furtherI finally managed to CLEAR all the Windows Live add ons in internet explorer and deleted live search and this corrected the problems.  It doesn't make sense to me since some of the problems didn't even require the browser....
471.

Solve : RootKits..?

Answer»

Could it have something to do with the script that smeezekitty posted Here? He asked BC to see what that script does, I thought I'd try too...but I only previewed it there in that topic , nothing happened, I didn't try it here.....I don't think it can be that though Quote from: Ivy on September 01, 2009, 10:05:00 PM

Why did it look LIKE that???

Not sure. You must have a Chinese version of Windows.

But, No rootkits found! is a good thing.

HackTool.BVP - Is this from AVG? If so then it should have been removed unless you denied it from being fixed.I removed HackTool.BVP ALREADY, and No I don't have chinese version of windows lol.....did you read the smeezykitty script.

Hey Evil, thank you for HELPING, you're always awesome, thank you so much!Your welcome. Safe SURFING Queen...
472.

Solve : Computer slowdown with Norton 2009 and SP2?

Answer»

Here's the problem- our only computer that is online is old and slow, but when we installed Norton 2009 that came with our NetZero dial up software, and SP 2, our PC is way slower than it used to be. Specs-
1.2 GHz Celeron
384MB ram
32 GB HDD
XP Home 
Norton requires 256 MB ram and SP2 shouldn't bog it down, right? Like I SAID, since this is our only internet PC, we could really use the help. Thanks in advance!
You need more ram, and how much free space is available on your harddrive?

You could remove Norton and install a free AV that uses less resources.OK, I might be able to find more ram, but it uses PC-133 and I THINK the MOBO's limit is 512 MB, is that enough? We can try another AV. Which one uses less ram than Norton? And we have about 12 GB free space.Try Avira AntiVir  http://www.free-av.com/

GO to http://www.crucial.com/index.aspx to scan your PC for memory capacity.I just downloaded Avira and will try it when we are back at our home computer. Hope this will help.I've got Avira on our PC and it is deffinitely faster than Norton. Thanks to all! You're most welcome.....

473.

Solve : Suspected Virus on Computer 1?

Answer»

This is a new thread so there is no confusion as suggested.

This is what has been done so FAR:
I have been working through the "STEPS to TAKE before asking for virus help". So far there seem to be good results as I can now open the documents I referred to. However, as suggested, I will complete the cleaning process as soon as possible.

Thanks again for your help so far! Be sure and post all the asked for logs when you get finished running the scans. That WAY a specialist can have a look and make sure everything is gone.

474.

Solve : No sound recording on computer 2?

Answer»

This is a NEW THREAD to avoid confusion.

I have been receiving an error 80004005. The MICROPHONE cannot record. The mic is new and WORKS on other systems. The slider for microphone volume is at max and is enabled.

running win XP sp3

475.

Solve : HELP FOR PITIES SAKE HELP?

Answer»

IM GOING OFF THE CHAIN WITH THIS AND I THINK I WILL THROW IT AT A WALL.

sorry for the outburst. Right i own a toshiba laptop and have had it for nearly two year. The norton internet security ran out of the 21st of august 2009 and since then the laptop has went ape sh*t. Its been starting to freeze and just overall nuisance. Every time i turn it on it goes straight into a DISK clean which has never hapened before the 21st. Then after SIGNING in to vista a pop up comes up which says bad image  and says something like symantec/ccErrDsp.dll is either not designed not to run on WINDOWS or has an error.

THE THING IS I TRACED IT BACK TO ITS SOURCE AND ITS FROM NORTON INTERNET SECURITY WHICH CAME WITH THE LAPTOP!!!....so how can it not be made for windows.

after i click ok on the pop up the SYSTEM freezes. I have went into safe mode which i am on now because if i go on normal mode it dies. I have downloaded malwarebytes which is reall good, it wiped all the malware and viruses and the lot straight of my computer which i thought would fix it (by te way there actually wasnt much stuff on there that was bad anyway) but no way it still dies after at most 4 mins. I thought maybe just maybe the hardrive was too packed or muddled up so i did a defrag...to no effect. PLEASE HELP PLEASE!!!!!!!!!!! the pic of the pop up is attached!!!!

[attachment deleted by admin]TRY removing norton with add/remove programs
nortan av isnt that good anyway
get a better av instead

476.

Solve : Total Security?

Answer»

Here's the mbam log:


Malwarebytes' Anti-Malware 1.40
Database version: 2713
Windows 6.0.6002 Service Pack 2

8/31/2009 4:50:50 AM
mbam-log-2009-08-31 (04-50-50).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 256011
Time elapsed: 2 hour(s), 40 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\TSC (Rogue.Total.Security) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\TSC\tsc.exe (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Windows\System32\1251214205.exe (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Computer Scan.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Help.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Registration.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Security Center.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Settings.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Total Security.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\TSC\Update.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
C:\Users\Pinard\Desktop\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
C:\Users\Pinard\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\TSC.lnk (Rogue.Total.Security) -> Quarantined and deleted successfully.
And here is the hjt log. I did this after the mbam log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:55 AM, on 8/31/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows SIDEBAR\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [0207671222653068mcinstcleanup] C:\Users\Pinard\AppData\Local\Temp\020767~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon NOTIFY: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

--
End of file - 8103 bytes
How is your computer running?Karnac,

Seems to be runnibg good.
I have the SAS log. It found a bunch of cookiess. The mbam seems to have gotten rid of that trojan.TDSS as well as Total Security.
Should I run mbam again to make sure? AVG didn't catch that. That worries me. Here's the log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/31/2009 at 10:46 AM

Application Version : 4.27.1002

Core Rules Database Version : 4077
Trace Rules Database Version: 2017

Scan type       : Custom Scan
Total Scan Time : 05:39:14

Memory items scanned      : 695
Memory threats detected   : 0
Registry items scanned    : 6447
Registry threats detected : 0
File items scanned        : 634584
File threats detected     : 177

Adware.Tracking Cookie
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][3].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][3].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Users\Pinard\Cookies\Low\[email protected][2].txt
   C:\Users\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected]la[1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][2].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][3].txt
   C:\Windows.old\Documents and Settings\Pinard\Cookies\Low\[email protected][1].txt
Run Mbam again, just to be sure.

I would consider using Avira AntiVir, it's free, AVG isn't what it used to be.

Install WOT (Web of Trust).....this will protect you when browsing, so you don't go to websites LIKE Spyzooka.
I hope you removed that program in Add/Remove programs as well.Yes, I did remove spyzooka. Thanx so very much for your help. I'll let you know what  a new mbam scan says.


Check it out!

Malwarebytes' Anti-Malware 1.40
Database version: 2722
Windows 6.0.6002 Service Pack 2

8/31/2009 2:16:36 PM
mbam-log-2009-08-31 (14-16-36).txt

Scan type: Quick Scan
Objects scanned: 81640
Time elapsed: 6 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I'll follow your advice and get Avira.Good stuff...It APPEARS that you're not running any Firewall. If that is true, you need to activate the Windows Firewall ASAP. Did you ever have McAfee on that computer? There is still some evidence of it in the log.

477.

Solve : Re: Kaspersky?

Answer»

I use Kaspersky...I can FIND the virus vault in my directory.. But the kaspersky couldn't detect...Annie, what are you trying to tell us?Kaspersky has also a Virus vault but its not ope to all. If Ksapersky can't find the virus other ANTIVIRUS found, let Kaspersky know
Thanks
Mahmud
<link removed>

478.

Solve : parents computer having issues...please help!?

Answer»

My parents computer is a little older, but it is running VERY slowly, and it is doing some bizarre things.  Often times when trying to go to a website (such as the superantispyware site, it re-directs to a completely different site. 

I downloaded Avast! antivirus (they did not have an active anti-virus before), and the computer will not completely boot unless I boot into safe mode (which is what I am in right now).  I also downloaded MALWAREBYTE's Anti-Malware, but it quit a few seconds into the scan.  I also downloaded Hijack-This, and it also quit a few seconds into the scan.  Then, when I tried to reopen HJT, a window popped up saying "Windows cannot access the specified device, path, or FILE.  You may not have the appropriate permissions to access the item. 

When looking at the task manager, there are a COUPLE of weird entries.  helpctr.exe has 2 copies running, as well as a couple copies of something else that I stopped running (it had something about 7PFR something...) but SINCE stopping them they haven't come back up.  Any help would be GREATLY appreciated!Try renaming the programs to something else......sniper.exe or boom.exe Quote from: Karnac on August 30, 2009, 06:12:25 PM

Try renaming the programs to something else......sniper.exe or boom.exe

I tried renaming all of those programs, but no result.create a new user account
and try running the program again
479.

Solve : Lurking problem?

Answer»

Great Keith ....... sorry about the distraction........i think you can SEE here http://www.voip-sol.com/10-skype-alternatives/http://www.voip-sol.com/10-skype-alternatives/
also CHECK sourceforge.net for free alterntives
by the way i am not advertisinguse CCLEANER every week

480.

Solve : Help with suspected virus at work - job under threat?

Answer»

Hi I am a newbie and desperately looking for help!

My DH has been sacked for accessing inappropriate websites at work and is appealing the decision.  We have asked for their evidence and have been sent pages and pages of surf control infor showing websites his computer has visited.  He has not accessed these sites (literally thousands in the space of a couple of days).  All the times are when he has been at work and most seem to be when he was at his desk (obviously he can't recall to the precise minute when he was there).  He is not techy at all but thinks his computer goes into hibernation when he is not using it (he gets a screensaver, then the screen goes blank a short while later) so it seems that whatever is accessing this info is only doing it when the computer is active.

We are just desperately trying to understand what might have happened.  I am guessing he has a local virus, but no idea what the virus might be, why it hasn't spread to other computers or how it could have got there.  He is aware of having received some spam email (he has a published work email address) and some of it has been INNOCENT looking and looked like other work email.  He has occasionally therefore clicked on a link (so in addition to being sacked for attempting to access such sites he has also been sacked for putting the company's systems at risk).  Whatever is doing this is doing it without his knowledge.  He does have IE open all the time at work but has not been aware of this activity at all.

And yes, before you ask, I do believe that he has not been surfing porn at work.

So please help!  He loved that job and we are desperate to come up with an EXPLANATION for what has happened that might persuade them to take him back.

Thanks in advanceHi tvgirl, please read this first before requesting malware removal: Click here.Hi there,

Thanks for your reply.  Unfortunately we are not looking for malware removal as he has already been sacked and no longer have access to the computer.  We are trying to understand how this has happened and what virus etc could be responsible so that he can try to explain to them at his appeal that he is not at fault and persuade them to GIVE him his job back!

CheersWe understand your problem.But we can't simply help you without any information regarding running processes in your computer.So, please follow the prework and  post the required logs in  your next reply. It will  help us to solve your problem more efficiently .Sorry!  Unfortunately we don't have access to the computer so there is no way I can get any more info.  I'm just looking for possible explanations really - and I know I'm grasping at straws a bit..

ThanksYour coworker is pretty much euchred........A good lawyer who deals with wrongful dismissal suits will be your best source of information on this topic....they deal with this all the time and will give you a qualified answer as to what your coworkers chances of reinstatement  are.....
It's my husband - and I think you might be right 

Does anyone know of whether a virus would do this, though?  Are there any well known types that do this wort of thing?  I'm afraid I don't really know the difference between a worm or a trojan or a virus, so I am using the word 'virus' to mean anything malicious.  If there is something that can do this, how would it have got onto his computer?  And why wouldn't it have spread to other computers?

Sorry for all the questions...

ThanksIf this is the case, "literally thousands in the space of a couple of days" of websites appeared in surf control then there is a good chance something is amiss with the security on the network..... this is where a lawyer will question the network administrators housekeeping practices and whether the security upkeep has been followed, logs are sometimes kept depending on policy....It all depends on how far you wish to take the suit, how much service your husband has with the company, have they been on his *censored* for another reason and is this a convenient manner to dismiss him?.....lotta questions to be answered.Do you have or can you request a copy of the firewall logs that indicates where your husband has allegedly surfed on their network?

There are several possibilities, but take with a grain of salt until you (or an attorney) can gather more evidence:

1) Your hubby's logon password was something stupidly easy to guess and/or he put on a sticky note with his password around his desk.  Someone gets password, logs into his PC or user account, surfs pr0nz, and profits.  IT departments' logs may go solely by user name basis, RATHER than computer.

2) Same as #1, but add that someone could have logged into his PC remotely.  Windows Remote Desktop locks the host computer while the guest accesses it, and the host's monitor can be in a screen saver or off.

3) Malware can certainly cause deh pronz to appear in firewall logs. Quote from: tvgirl on August 28, 2009, 07:24:24 AM

Does anyone know of whether a virus would do this, though?
Possibly.

Quote from: tvgirl on August 28, 2009, 07:24:24 AM
Are there any well known types that do this wort of thing?  I'm afraid I don't really know the difference between a worm or a trojan or a virus, so I am using the word 'virus' to mean anything malicious.
You can call it malware (malicious software).

Quote from: tvgirl on August 28, 2009, 07:24:24 AM
If there is something that can do this, how would it have got onto his computer?
Many factors. It can be transmitted via network, USB flash drives, dirty websites, download of infected email attachments, download of pirated software, clicking on links to WEB pages, accepting file transfers, etc.
481.

Solve : Infected by extremley nasty malware, can't even run HijackThis, please help?

Answer»

I got infected by a NASTY malware while surfing a news forum. It rebooted my computer (XP sP2). Now my situation is:
1. Even in safe mode, I canot run any anti-spyware software: Malwarebyte's will close in one second after starting SCANNING. SuperAntiSpeware will close after about 10 seconds of scanning. Then the .exe application file will no longer work. When I tried to run them again, it will say "Windows cannot access the specified device, path, or file. You may not have the appropriate premission to access the item." On the first SCAN, SAS did found a few vundo etc spywares before it got closed down. Later, when I copied another SAS.exe from another computer and tried to run, it no longer reports finding anything before it got closed down.  (I did restart computer in between though.)
2. Cannot connect to any website, it always shows trying to connect. (The wireless connection itself shows OK).
3. It removed the system restore tab from system property, and does not run system restore claiming that it is disabled by group policy. I got around and brought back that tab and enabled restore, but the restore point table shows only August and there is no restore points. I can't move to other months.
4. Worst of all, after I downloaded HijackThis using another computer, copied onto the infected desktop, and tried to run, it ended up the same as any anti-spyware software - it closes itself immediately after scanning started and become inaccessible afterwards. So I can't even post the HijiackThis logs.

There could be other symptoms I have yet to discover. Never seen this kind of nasty stuff. Please help!!!
I don't see anywhere in your post that you tried renaming the exe....try rename them anything other than the regular program name.Here is what I would do. In fact, it is what i do.
1. Buy a GOOD but cheap Hard Drive. I found a 160 GB IDE on E bay for $20. Works FINE for my purpose.
2. Do a full install of your system on the replacement drive. Do NOT use software on the infected drive, even device drivers. Don't even have the infected drive connected. for now.
3. Get a real good anti-virus up and running.

Now at this point you can decide how much data from the infected drive you want to import, like documents, music, photos and videos. No EXE or ZIP files or things like that. Later, format your infected drive and copy the new install using q image tool line the one from Run time Software.

http://www.runtime.org/

And next time do backups to an external or removable device.
 
To Karnac:

I did rename HijakcThis to Sniper.


Thanks,

MaxGen

482.

Solve : Are my files gone forever?- was this a virus??

Answer»

an external hard DRIVE containing 76gb of photos has been running on my laptop for two days, i noticed that when i tried to save to it, a popup said it was unable to save to f: drive. so i went to my computer and opened the drive by right click and explore but there is NOTHING in there apart from an autorun folder which i don't recall being there before. I'm obviously shocked at the notion that ten years of work and FAMILY photos are missing but i'm afraid to unplug or power off the system or external hdd in case i do permenant damage, ALSO when in my computer and i richt click on the hdd and select properties, the hard drive has 76gb used space. Please HelpIs there something WRONG with your original topic?

Closed.

483.

Solve : Security Center says anti-virus protection is turned off..?

Answer»

but the AVG icon is in the tray and i'm ACTUALLY running antivirus as we speak. I may have picked up malware last night. Anybody can HELP?
You will need to follow the instructions in this linkOK for some reason the little red SHIELD in the tray turned itself off and the antivirus icon is there so I don't know what to say. I guess all is well. Maybe it was a glitch/bug.

484.

Solve : explorer.exe keeps restarting?

Answer»

Can anyone help please?
Here is my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:24 AM, on 4/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1202671746304
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190779466356
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190779604815
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BOCore - Unknown owner - C:\Program Files\Freeware Folder\Adware+Spyware+Scumware Remover\BOCORE.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

--
End of file - 5828 bytes
you have 2 anti-virus PROGS; installed and you should have ONE , avast is the best

 and i never seen or heard of threatfire , harry Quote

O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE

That's what we like to see! 

Nothing Jumps out at me.

can you run through the steps here, and repost the three logs? (MBAM, Super Anti-Spyware, and a fresh Hijackthis after that).

Ok,
It went away for a couple of days now either I got another virus or It came back!
I'll follow the instructions in your post.
485.

Solve : When putting in my new Norton Internet security 2009?

Answer»

I put my new NORTON in late last night EARLY morning.  I don't remember the exact words but something came up about me not being certified do I want to go on yes or no there was also a spot to CLICK on to find out what this was I did and I click on something which ended up I got Verisign I don't know what this is do I need this and how do I GET rid of this?Verisign is a  trusted provider of Internet infrastructure services

http://www.verisign.com/

I assume they were verifying youDid you pay for the programme??

486.

Solve : Is driveguard.exe actually a virus??

Answer»

Hi..
Recently I noticed a FILE driveguard.exe in my programfiles.When I scanned it for viruses with AVG free,it detected it as a trojan.But ALONG the readme with driveguard.exe,it is POINTED out that driveguard.exe is a software for protection of pen drives when connected to PC.I want an opinion whether i should remove it or not.Pls help me...........
This is the Microsoft Corporation; Flash Drive Protector. Tools like this work in the same way that MALWARE would and are sometimes flagged as malicious. ANTIVIRUS can't tell the difference in "good" and "bad" processes so it's just doing it's job.

http://www.file.net/process/driveguard.exe.html

487.

Solve : HELP! Computer crashed, won't start even in safe modeat?

Answer»

I'm writing from my husband's LAPTOP because my desktop is completely dead.   

We were out of TOWN for several days and when we returned my desktop was running very slow so I attempted to restart it.  It locked up, I pressed/held the power button and when it restarted it attempted to run a disk check.  The disk check locked up and I had to press/hold the power button again.  When it restarted I got a blue screen ~ stop: C0000218 unknown hard error.

Sometimes when I attempt to restart it I get: checking file system on C:
file system = NTFS

When I attempt to restart it in safe mode, safe mode with networking or starting in last known good configuration I get . . .

MULTI(0)disk(0)rdisk(0)partition(2)\windows\appPatch\drvmain.sdb
multi(0)disk(0)rdisk(0)partition(2)\windows\system32\drivers\ . . . (various items)

Now it won't start, not EVEN in safe mode.  Everything I try ~ I just get a black screen.

** I just tried to restart AGAIN and it ran disk scan, said it had completed disk scan and would restart, the screen went black when it attempted to restart and the screen is still black and it won't restart.

What can I do to get my computer BACK?

Any help will be greatly appreciated!you should not post twice , you will not get help any quicker , harryI didn't know I posted twice and certainly did not mean to.  We're also having some trouble with husband's laptop and it must have posted twice when I hit "refresh."  Feel free to delete the duplicate.

Do you have any advice/help for my problem?

488.

Solve : Re: spyware/virus problem. can't access C: drive, can't open certain programs?

Answer»

Had a very similar problem, here the log that I got after running COMBOFIX
Wonder if were downloading same thing.


ComboFix 09-03-15.01 - Stan 2009-03-18 21:22:34.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.1535.1159 [GMT -4:00]
Running from: c:\documents and settings\Stan\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: McAfee VirusScan *On-access scanning disabled* (Outdated)
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\gaopdxaklnqqoroeeiwqmmnaijgvjngukftvxo.sys
c:\windows\system32\drivers\gaopdxrmyvymqskltenbgixudpskjwbpjovutm.sys
c:\windows\system32\drivers\gaopdxyapuxrdlvnrwkpbivaqxdoltfmrqvmph.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxxmumdbjduxdltoirkhfrhpabrnoretfm.dll
Z:\Autorun.inf
z:\recycler\S-1-4-31-100013720-100003350-100027788-1077.com
z:\recycler\S-5-3-59-100026097-100009182-100004493-3868.com
z:\recycler\S-5-5-81-100002894-100007065-100025522-8070.com
z:\recycler\S-9-9-13-100003843-100027127-100021430-4327.com

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys


(((((((((((((((((((((((((   Files Created from 2009-02-19 to 2009-03-19  )))))))))))))))))))))))))))))))
.

2009-03-18 18:49 . 2009-03-18 18:49      d--------   c:\documents and settings\Stan\Application Data\TrojanHunter
2009-03-18 18:14 . 2009-03-18 18:14      d--------   c:\program files\TrojanHunter 5.0
2009-03-17 23:01 . 2009-03-17 23:01      d--------   C:\Mdtcm
2009-03-16 22:10 . 2009-03-16 22:10      d--h-----   C:\$AVG8.VAULT$
2009-03-16 22:01 . 2009-03-16 22:01      d--------   c:\windows\system32\drivers\Avg
2009-03-16 22:01 . 2009-03-16 22:01      d--------   c:\program files\AVG
2009-03-16 22:01 . 2009-03-16 22:01      d--------   c:\documents and settings\Stan\Application Data\AVGTOOLBAR
2009-03-16 22:01 . 2009-03-16 22:01      d--------   c:\documents and settings\All Users\Application Data\avg8
2009-03-16 22:01 . 2009-03-16 22:01   325,640   --a------   c:\windows\system32\drivers\avgldx86.sys
2009-03-16 22:01 . 2009-03-16 22:01   107,912   --a------   c:\windows\system32\drivers\avgtdix.sys
2009-03-16 22:01 . 2009-03-16 22:01   10,520   --a------   c:\windows\system32\avgrsstx.dll
2009-03-16 20:43 . 2009-01-26 15:31   414,552   --a------   c:\windows\system32\123.scr
2009-03-16 20:36 . 2009-03-16 21:21      d--------   c:\program files\Spybot - Search & Destroy
2009-03-16 20:36 . 2009-03-16 21:13      d--------   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-16 20:11 . 2009-03-16 20:11      d--------   c:\documents and settings\Administrator
2009-03-16 20:00 . 2009-03-16 20:01      d--------   c:\program files\Spyware Doctor
2009-03-16 20:00 . 2009-03-16 20:00      d--------   c:\program files\Common Files\PC Tools
2009-03-16 20:00 . 2009-03-16 20:00      d--------   c:\documents and settings\Stan\Application Data\PC Tools
2009-03-16 20:00 . 2009-03-18 19:25      d-a------   c:\documents and settings\All Users\Application Data\TEMP
2009-03-16 20:00 . 2009-03-16 20:00      d--------   c:\documents and settings\All Users\Application Data\PC Tools
2009-03-16 20:00 . 2008-12-11 08:38   159,600   --a------   c:\windows\system32\drivers\pctgntdi.sys
2009-03-16 20:00 . 2009-03-06 16:45   130,424   --a------   c:\windows\system32\drivers\PCTCore.sys
2009-03-16 20:00 . 2008-12-18 12:16   73,840   --a------   c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-16 20:00 . 2008-12-10 12:36   64,392   --a------   c:\windows\system32\drivers\pctplsg.sys
2009-03-16 17:44 . 2003-02-28 18:26   139,536   --a------   c:\windows\system32\javaee.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 01:20   ---------   d-----w   c:\documents and settings\Stan\Application Data\DNA
2009-03-18 23:25   ---------   d-----w   c:\program files\DNA
2009-03-18 23:02   ---------   d-----w   c:\program files\Common Files\Symantec Shared
2009-03-18 22:49   ---------   d-----w   c:\documents and settings\Stan\Application Data\U3
2009-03-16 11:37   ---------   d-----w   c:\program files\Norton Internet Security
2009-03-16 01:29   ---------   d-----w   c:\documents and settings\Stan\Application Data\BitTorrent
2009-02-09 10:19   1,846,272   ----a-w   c:\windows\system32\win32k.sys
2009-01-24 20:36   ---------   d-----w   c:\program files\BitTorrent
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"j2 4.4"="c:\program files\j2 Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-24 342848]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-10-16 868352]
"RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 319488]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-03-23 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-03-23 77824]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2003-08-08 122880]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 71280]
"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2003-10-22 70840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-03 4800512]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2003-08-17 163840]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-16 1932568]
"THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-10-24 1056928]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 54472]

c:\documents and settings\Stan\Start Menu\Programs\Startup\
jConnect 4.4.lnk - c:\program files\j2 Messenger 4.4\J2GTray.exe [2008-10-07 656896]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-06 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-16 22:01 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-16 130424]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-16 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-16 107912]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-16 298264]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [2008-08-22 6016]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [2006-03-24 23296]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-16 348752]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-9-9-13-100003843-100027127-100021430-4327.com c:\
\Shell\Open\command - c:\recycler\S-9-9-13-100003843-100027127-100021430-4327.com c:\

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-9-9-13-100003843-100027127-100021430-4327.com z:\
\Shell\Open\command - z:\recycler\S-9-9-13-100003843-100027127-100021430-4327.com z:\
.
Contents of the 'Scheduled Tasks' folder

2009-03-14 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2003-12-04 18:22]

2009-03-19 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-13 19:38]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-AVG7_RegCleaner - c:\progra~1\Grisoft\AVG7\avgregcl.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ebay.com/
uInternet Connection Wizard,ShellNext = hxxp://estore.sonic.com/upgrades/purchase.asp?srnm=C5HL2KVAEPDSS4JGR⟨=ENU&id=40
uInternet Settings,ProxyServer = 192.168.1.1
uInternet Settings,ProxyOverride =
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Stan\Application Data\Mozilla\Firefox\Profiles\x5uhg4ro.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nphssb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-18 21:26:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-18 21:28:38
ComboFix-quarantined-files.txt  2009-03-19 01:28:32

Pre-Run: 101,167,312,896 bytes free
Post-Run: 101,278,400,512 bytes free

173   --- E O F ---   2009-03-16 21:46:33
i'm not an expert , but why do you have ,  AVG  / norton / mcafee / spyware

WITH antvirus, all on you pc  , harryYou have way TOO MUCH protection on this computer. It actually can offer less protection by running multiple security softwares at once.

Disable Spybot's TeaTimer

While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with our fixes. Please disable TeaTimer.

1. Right click Spybot in the System TRAY (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D RESIDENT
2. Run Spybot S&D
3. Go to the Mode menu, and make sure Advanced Mode is selected.
4. On the left hand side, choose Tools > Resident
uncheck Resident TeaTimer and OK any prompt and Restart your computer.

Note:
If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

If TeaTimer will not turn off then uninstall Spybot until we are done cleaning.

----------

AVG Anti-Virus Free
McAfee VirusScan
Spyware Doctor with AntiVirus


The real-time protection of multiple antivirus programs may conflict with each other and cause the following:

1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

Please uninstall all but ONE antivirus now.

----------

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left MOUSE button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is FOUND, it will download and install the LATEST version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    489.

    Solve : HijackThis.exe not showing up Trend Micro folder so I can rename it to sniper?

    Answer»

    You may recognize the instructions below from your malware preparation bulletin.

    Step 6: HijackThis

    Please run HijackThis only after the above steps have been completed

    Download and rename HijackThis.exe (HJT)

    * Double-click on HJTInstall.
    * Click on the Install button.
    * It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
    * Upon install, HijackThis should open for you.

        * Close HijackThis and rename it.
        * Go to C:\Program Files\Trend Micro\HijackThis.exe
        * Right click on HijackThis.exe and select Rename.
        * Type in sniper.exe and press Enter.
        * Right-click on sniper.exe and select Send To > Desktop (create shortcut)


    I already had HijackThis installed but I re-installed it.  Stilll, inside the Trend Micro folder, there was no HijackThis.exe file, only a Backups folder, hijackthis text document  and a HijackThis icon which opens the program when you double-click it.  I did a search and the HijackThis.exe file did not show up.  Is it necessary to rename this file to sniper.exe (and why do you do that, anyway)?

    I have initiated this malware removal process because I started getting this error when starting up:  "Error loading dll32  The specified module could not be found."  I cannot open my web browser (Firefox) now on my user account.  I'm assuming the error message relates to the browser problem.  So I now have to go into my daughter's user account to get online and begin this process of communicating with you.  By the way, I have given her account administrator rights so I can proceed. I have done all the steps in your prepatory bulletin up to the "HijackThis - rename to sniper" step and now am hitting this snag of not finding the HijackThis.exe file.  What do you propose?

    Quote

    and a HijackThis icon which opens the program when you double-click it.

    That's what you need to rename.OK, I changed the icon name to sniper.exe and put it on the desktop. 

    Once again, currently, the main problem is that I get the following error message when I log on to my user account: "Error Loading dll32   The specified module could not be found". And then I cannot open my Firefox browser. I get this error mesage: "Proxy Server Refused Connection.  Firefox is configured to use a proxy server that is refusing connections."(I'm assuming the dll32 file has something to do with that).  I even tried inserting my Windows XP disc to have that file repaired but it did not seem to work.  I have to switch user accounts so that I can get on the internet.

    Here are the logs: (I've also included and AVG report at the end to show you what it detected)

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 03/18/2009 at 05:57 PM

    Application Version : 4.25.1014

    Core Rules Database Version : 3803
    Trace Rules Database Version: 1758

    Scan type       : Complete Scan
    Total Scan Time : 02:39:48

    Memory items scanned      : 428
    Memory threats detected   : 0
    Registry items scanned    : 6176
    Registry threats detected : 112
    File items scanned        : 95255
    File threats detected     : 56

    Adware.MyWebSearch
       HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
       HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
       C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL
       HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32
       HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
       C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
       HKU\S-1-5-21-1960408961-448539723-725345543-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
       HKU\S-1-5-21-1960408961-448539723-725345543-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
       HKU\S-1-5-21-1960408961-448539723-725345543-1006\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}

    Adware.MyWebSearch/FunWebProducts
       HKU\S-1-5-21-1960408961-448539723-725345543-1006\SOFTWARE\MyWebSearch
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Control
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus\1
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ProgID
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Programmable
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\TypeLib
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Version
       HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\VersionIndependentProgID
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32#ThreadingModel
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance#CLSID
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag
       HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag#Url
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32#ThreadingModel
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\Programmable
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\TypeLib
       HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
       HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
       HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
       HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32#ThreadingModel
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ProgID
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\Programmable
       HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\VersionIndependentProgID
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS
       HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib
       HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib#Version
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE#NextInstance
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Service
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Legacy
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ConfigFlags
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Class
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ClassGUID
       HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#DeviceDesc
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Type
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Start
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ErrorControl
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ImagePath
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#DisplayName
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ObjectName
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Security
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Security#Security
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#0
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#Count
       HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#NextInstance

    Adware.Tracking Cookie
       www3.addfreestats.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .videoegg.adbureau.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .imrworldwide.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .imrworldwide.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       www.burstbeacon.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       tracker.mediatracker.co.nz [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .roiservice.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .gaiainteractive.112.2o7.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       server.cpmstar.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .stats.adbrite.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .interclick.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .interclick.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .interclick.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .insightexpressai.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .insightexpressai.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .insightexpressai.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .insightexpressai.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .insightexpressai.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .earthlinkfinder.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .specificclick.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .aaotracker.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .aaotracker.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .adlegend.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .adlegend.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .atwola.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       www8.addfreestats.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       www7.addfreestats.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       ads.gamesbannernet.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       ads.gamesbannernet.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .apmebf.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .nextag.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .nextag.com [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .collective-media.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       .collective-media.net [ C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\3ju4bzep.default\cookies.txt ]
       C:\Documents and Settings\David\Cookies\[email protected][1].txt
       C:\Documents and Settings\Leanne\Cookies\[email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][2].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][2].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][2].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][2].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt
       C:\Documents and Settings\user pc\Cookies\user [email protected][1].txt





    Malwarebytes' Anti-Malware 1.34
    Database version: 1866
    Windows 5.1.2600 Service Pack 3

    3/18/2009 6:58:30 PM
    mbam-log-2009-03-18 (18-58-30).txt

    Scan type: Quick Scan
    Objects scanned: 93990
    Time elapsed: 10 minute(s), 3 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 27
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:15:54 PM, on 3/18/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\PROGRA~1\NETWOR~1\MCAFEE~1\FireSvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\system32\WTablet\TabUserW.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\PROGRA~1\NETWOR~1\MCAFEE~1\Firetray.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [McAfeeFireTray] C:\PROGRA~1\NETWOR~1\MCAFEE~1\Firetray.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-21-1960408961-448539723-725345543-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'user pc')
    O4 - HKUS\S-1-5-21-1960408961-448539723-725345543-1003\..\Run: [dll] rundll32 dll32,sm (User 'user pc')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175397160937
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15033/CTPID.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\PROGRA~1\NETWOR~1\MCAFEE~1\FireSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 9028 bytes


    AVG Anti-Virus free edition "scan whole computer" report:

    8.0.238


    "C:\Documents and Settings\user pc\Local Settings\Temp\tt_1237291175.exe";"Trojan horse SHeur2.WHB";"Moved to Virus Vault"
    "C:\Documents and Settings\user pc\Local Settings\Temp\tt_1237294987.exe";"Trojan horse SHeur2.WHB";"Moved to Virus Vault"
    "C:\Documents and Settings\user pc\Local Settings\Temp\wJQs.exe";"Trojan horse SHeur2.QVU";"Moved to Virus Vault"
    "C:\windows\ld02.exe";"Trojan horse SHeur2.WGW";"Moved to Virus Vault"
    "C:\windows\pp03.exe";"Trojan horse SHeur2.WHP";"Moved to Virus Vault"
    "C:\windows\pp03.exe";"Trojan horse SHeur2.WHP";"Moved to Virus Vault"
    "C:\WINDOWS\pp03.exe";"Trojan horse SHeur2.WHP";"Moved to Virus Vault"
    "C:\WINDOWS\pp03.exe (172)";"Trojan horse SHeur2.WHP";"Reboot is required to finish the action"
    "C:\WINDOWS\system32\dll32.dll";"Trojan horse Pakes.CTG";"Moved to Virus Vault"
    "C:\WINDOWS\system32\dll32.dll";"Trojan horse Pakes.CTG";"Infected"
    "C:\WINDOWS\system32\rundll32.exe (208)";"Trojan horse Pakes.CTG";"Reboot is required to finish the action"

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixFor some reason, I am unable to disable the Anti-Virus and Anti-Spyware components of the AVG free edition.  There's nothing to uncheck  Just right click the AVG tray icon and choose to stop or exit. Run ComboFix and if anything tries to stop it from running then just allow it instead of blocking it.ComboFix 09-03-18.01 - Becky 2009-03-19  0:49:11.1 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1535.1182 [GMT -4:00]
    Running from: c:\documents and settings\Becky\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning ENABLED* (Updated)
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Documents\notepad.exe
    c:\documents and settings\Becky\Desktop\notepad.exe
    c:\documents and settings\user pc\Desktop\notepad.exe
    c:\documents and settings\user pc\Desktop\Shared\b.bking\desktop_.ini
    c:\windows\a3kebook.ini
    c:\windows\akebook.ini
    c:\windows\ANS2000.INI
    c:\windows\system32\mdm.exe

    .
    (((((((((((((((((((((((((   Files Created from 2009-02-19 to 2009-03-19  )))))))))))))))))))))))))))))))
    .

    2009-03-18 19:09 . 2009-03-18 19:09   410,984   --a------   c:\windows\system32\deploytk.dll
    2009-03-18 18:42 . 2009-03-18 18:42      d--------   c:\documents and settings\Becky\Application Data\Malwarebytes
    2009-03-18 18:42 . 2009-02-11 10:19   15,504   --a------   c:\windows\system32\drivers\mbam.sys
    2009-03-18 18:41 . 2009-03-18 18:42      d--------   c:\program files\Malwarebytes' Anti-Malware
    2009-03-18 18:41 . 2009-03-18 18:41      d--------   c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-18 18:41 . 2009-02-11 10:19   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\SUPERAntiSpyware
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\Common Files\Wise Installation Wizard
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\documents and settings\Becky\Application Data\SUPERAntiSpyware.com
    2009-03-18 15:04 . 2009-03-18 15:04      d--------   c:\program files\CCleaner
    2009-03-17 16:44 . 2009-03-17 16:44      d--hs----   C:\found.000
    2009-03-17 15:50 . 2008-04-13 20:12   116,224   --a--c---   c:\windows\system32\dllcache\xrxwiadr.dll
    2009-03-17 15:50 . 2001-08-17 22:37   99,865   --a--c---   c:\windows\system32\dllcache\xlog.exe
    2009-03-17 15:50 . 2001-08-17 22:37   27,648   --a--c---   c:\windows\system32\dllcache\xrxftplt.exe
    2009-03-17 15:50 . 2001-08-17 22:36   23,040   --a--c---   c:\windows\system32\dllcache\xrxwbtmp.dll
    2009-03-17 15:50 . 2004-08-03 22:29   19,455   --a--c---   c:\windows\system32\dllcache\wvchntxx.sys
    2009-03-17 15:50 . 2008-04-13 20:12   18,944   --a--c---   c:\windows\system32\dllcache\xrxscnui.dll
    2009-03-17 15:50 . 2001-08-17 12:11   16,970   --a--c---   c:\windows\system32\dllcache\xem336n5.sys
    2009-03-17 15:50 . 2004-08-03 22:29   12,063   --a--c---   c:\windows\system32\dllcache\wsiintxx.sys
    2009-03-17 15:50 . 2008-04-13 14:36   8,832   --a--c---   c:\windows\system32\dllcache\wmiacpi.sys
    2009-03-17 15:50 . 2008-04-13 20:12   8,192   --a--c---   c:\windows\system32\dllcache\wshirda.dll
    2009-03-17 15:50 . 2001-08-17 22:37   4,608   --a--c---   c:\windows\system32\dllcache\xrxflnch.exe
    2009-03-17 15:48 . 2001-08-17 22:36   525,568   --a--c---   c:\windows\system32\dllcache\tridxp.dll
    2009-03-17 15:47 . 2001-08-17 22:36   495,616   --a--c---   c:\windows\system32\dllcache\sblfx.dll
    2009-03-17 15:46 . 2001-08-17 13:28   899,146   --a--c---   c:\windows\system32\dllcache\r2mdkxga.sys
    2009-03-17 15:45 . 2001-08-17 12:50   198,144   --a--c---   c:\windows\system32\dllcache\nv3.sys
    2009-03-17 15:44 . 2001-08-17 13:28   802,683   --a--c---   c:\windows\system32\dllcache\ltsm.sys
    2009-03-17 15:43 . 2008-04-13 20:11   702,845   --a--c---   c:\windows\system32\dllcache\i81xdnt5.dll
    2009-03-17 15:42 . 2001-08-17 14:56   1,733,120   --a--c---   c:\windows\system32\dllcache\g400d.dll
    2009-03-17 15:41 . 2001-08-17 12:14   952,007   --a--c---   c:\windows\system32\dllcache\diwan.sys
    2009-03-17 15:40 . 2001-08-17 12:13   980,034   --a--c---   c:\windows\system32\dllcache\cicap.sys
    2009-03-17 15:33 . 2001-08-17 13:28   871,388   --a--c---   c:\windows\system32\dllcache\bcmdm.sys
    2009-03-17 15:32 . 2001-08-17 14:55   382,592   --a--c---   c:\windows\system32\dllcache\atidrab.dll
    2009-03-17 15:31 . 2001-08-17 12:19   747,392   --a--c---   c:\windows\system32\dllcache\adm8830.sys
    2009-03-17 15:30 . 2001-08-17 13:28   762,780   --a--c---   c:\windows\system32\dllcache\3cwmcru.sys
    2009-03-17 15:30 . 2001-08-17 14:55   689,216   --a--c---   c:\windows\system32\dllcache\3dfxvs.dll
    2009-03-17 15:30 . 2001-08-17 14:56   66,048   --a--c---   c:\windows\system32\dllcache\s3legacy.dll
    2009-03-17 15:30 . 2008-04-13 14:46   53,376   --a--c---   c:\windows\system32\dllcache\1394bus.sys
    2009-03-17 15:30 . 2001-08-17 14:06   11,264   --a--c---   c:\windows\system32\dllcache\1394vdbg.sys
    2009-03-17 00:05 . 2009-03-17 00:05   0   --a------   c:\windows\system32\nfr.gpref
    2009-03-17 00:05 . 2009-03-17 00:05   0   --a------   c:\windows\system32\nfr.assembly
    2009-03-16 23:50 . 2009-03-16 23:50   1   --a------   c:\windows\9g234sdfdfgjf23
    2009-03-16 22:24 . 2009-03-16 22:24   2   ---h-----   c:\windows\t55ft2807f44.dat
    2009-03-11 21:16 . 2009-03-11 21:16      d--------   c:\documents and settings\David\Application Data\AVGTOOLBAR

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-19 04:11   ---------   d-----w   c:\documents and settings\user pc\Application Data\WTablet
    2009-03-18 23:12   ---------   d-----w   c:\program files\Java
    2009-03-18 19:00   ---------   d-----w   c:\program files\Lavasoft
    2009-03-18 19:00   ---------   d-----w   c:\documents and settings\All Users\Application Data\Lavasoft
    2009-03-17 16:21   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
    2009-03-17 09:26   ---------   d-----w   c:\documents and settings\user pc\Application Data\uTorrent
    2009-03-15 21:35   138,624   ----a-w   c:\windows\system32\drivers\PnkBstrK.sys
    2009-03-15 21:34   202,352   ----a-w   c:\windows\system32\PnkBstrB.exe
    2009-03-15 04:15   ---------   d-----w   c:\documents and settings\user pc\Application Data\DVD Flick
    2009-03-15 01:38   ---------   d-----w   c:\documents and settings\user pc\Application Data\dvdcss
    2009-03-07 17:20   ---------   d-----w   c:\program files\Ahead
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\ZoomBrowser EX
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\CameraWindowDC
    2009-02-25 15:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\AVGTOOLBAR
    2009-02-12 16:12   ---------   d-----w   c:\program files\Google
    2009-02-11 02:24   34   ----a-w   c:\documents and settings\user pc\jagex_runescape_preferences.dat
    2009-02-10 04:35   ---------   d-----w   c:\documents and settings\Leanne\Application Data\AVGTOOLBAR
    2009-02-10 04:19   ---------   d-----w   c:\documents and settings\Leanne\Application Data\vlc
    2009-02-09 11:13   1,846,784   ----a-w   c:\windows\system32\win32k.sys
    2009-02-09 03:08   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Apple Computer
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\WTablet
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Network Associates
    2009-02-09 02:42   ---------   d-----w   c:\documents and settings\Becky\Application Data\AVGTOOLBAR
    2009-02-09 02:38   ---------   d-----w   c:\documents and settings\Becky\Application Data\vlc
    2009-02-05 18:37   ---------   d-----w   c:\documents and settings\user pc\Application Data\vlc
    2009-02-05 18:16   ---------   d-----w   c:\program files\VideoLAN
    2009-02-03 19:16   ---------   d-----w   c:\program files\Improvisation
    2009-01-27 15:56   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
    2009-01-27 15:56   10,520   ----a-w   c:\windows\system32\avgrsstx.dll
    2009-01-27 15:55   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
    2009-01-25 05:54   ---------   d-----w   c:\documents and settings\user pc\Application Data\Any VIDEO Converter
    2009-01-24 22:06   ---------   d-----w   c:\program files\AVG
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
    2009-01-24 20:56   ---------   d-----w   c:\documents and settings\All Users\Application Data\nView_Profiles
    2008-09-27 02:22   24   ----a-w   c:\documents and settings\David\jagex_runescape_preferences.dat
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-31 180269]
    "McAfeeFireTray"="c:\progra~1\NETWOR~1\MCAFEE~1\Firetray.exe" [2005-04-12 655420]
    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
    "NvMediaCenter"="NvMCTray.dll" [2008-05-03 c:\windows\system32\nvmctray.dll]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-01-27 11:56 10520 c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
    backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Personal Coach.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Personal Coach.lnk
    backup=c:\windows\pss\Personal Coach.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTZDetec.exe]
    --a------ 2007-12-18 15:20 401408 c:\documents and settings\user pc\Desktop\David\Creative Media Lite\CTZDetec.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-03-28 23:37 413696 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-04-04 19:00 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    --a------ 2008-05-03 06:46 1630208 c:\windows\system32\nwiz.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "80:TCP"= 80:TCP:dll32
    "7171:TCP"= 7171:TCP:dll32

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-24 325128]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-24 107272]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-24 903960]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-24 298264]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

    2009-03-17 c:\windows\Tasks\Uniblue SpyEraser Nag.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []

    2007-09-04 c:\windows\Tasks\Uniblue SpyEraser.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
    MSConfigStartUp-DT Task - c:\program files\Gateway\EzTune\DTHtml.exe
    MSConfigStartUp-My Web Search Bar - c:\progra~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
    MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
    MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_07\bin\jusched.exe
    MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe


    .
    ------- Supplementary Scan -------
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Becky\Application Data\Mozilla\Firefox\Profiles\v0zlm1jn.default\
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-19 00:52:35
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\SrchAstt\\1.bin\\MWSSRCAS.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\MWSBAR.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Control]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\MWSBAR.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus]
    DACL=(02 0000)
    ="0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ProgID]
    DACL=(02 0000)
    ="MyWebSearchToolBar.SettingsPlugin.1"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\TypeLib]
    DACL=(02 0000)
    ="{07B18EA0-A523-4961-B6BB-170DE4475CCA}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Version]
    DACL=(02 0000)
    ="1.0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\VersionIndependentProgID]
    DACL=(02 0000)
    ="MyWebSearchToolBar.SettingsPlugin"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32]
    DACL=(02 0000)
    ="c:\\WINDOWS\\system32\\shdocvw.dll"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance]
    DACL=(02 0000)
    "CLSID"="{4D5C8C2A-D075-11d0-B416-00C04FB90376}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\MWSBAR.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID]
    DACL=(02 0000)
    ="MyWebSearchToolBar.ToolbarPlugin.1"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\TypeLib]
    DACL=(02 0000)
    ="{07B18EA0-A523-4961-B6BB-170DE4475CCA}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID]
    DACL=(02 0000)
    ="MyWebSearchToolBar.ToolbarPlugin"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\M3SKIN.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]
    DACL=(02 0000)
    ="0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]
    DACL=(02 0000)
    ="{7473D290-B7BB-4f24-AE82-7E2CE94BB6A9}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]
    DACL=(02 0000)
    ="1.0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\M3SKIN.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]
    DACL=(02 0000)
    ="0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID]
    DACL=(02 0000)
    ="MyWebSearch.PseudoTransparentPlugin.1"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]
    DACL=(02 0000)
    ="{7473D290-B7BB-4f24-AE82-7E2CE94BB6A9}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]
    DACL=(02 0000)
    ="1.0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID]
    DACL=(02 0000)
    ="MyWebSearch.PseudoTransparentPlugin"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\M3SKIN.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]
    DACL=(02 0000)
    ="0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]
    DACL=(02 0000)
    ="{7473D290-B7BB-4f24-AE82-7E2CE94BB6A9}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]
    DACL=(02 0000)
    ="1.0"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs]
    DACL=(02 0000)
    ="{A9571378-68A1-443d-B082-284F960C6D17}"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\M3OUTLCN.DLL"
    "ThreadingModel"="Apartment"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ProgID]
    DACL=(02 0000)
    ="MyWebSearch.OutlookAddin.1"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\Programmable]
    DACL=(02 0000)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\VersionIndependentProgID]
    DACL=(02 0000)
    ="MyWebSearch.OutlookAddin"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid]
    DACL=(02 0000)
    ="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32]
    DACL=(02 0000)
    ="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib]
    DACL=(02 0000)
    ="{D518921A-4A03-425E-9873-B9A71756821E}"
    "Version"="1.0"

    [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0]
    DACL=(02 0000)
    ="HtmldocPlugin 1.0 Type Library"

    [HKEY_LOCAL_MACHINE\software\PortraitDisplays\DisplayTune\MGJ74D0C06550]
    DACL=(02 0000)
    "Analog 0.700,0.300Caps"="vcp(02 04 05 06 08 0E 10 12 14(01 05 08 0B) 16 18 1A 1E 20 30 3E 52 60(01 03) 68 AC AE B2 B6 C0 C6 C8 C9 CA D6(01 04) DF FA FB FC FD FE AA(01 04)) vcp_p2(37 38 39 3B) type(LCD) mccs_ver(2.0) asset_eep(64) mpu(0.04)"

    [HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\HID\Vid_045e&Pid_00f9&MI_01&Col02\7&36e0efb9&0&0001\LogConf]
    DACL=(02 0000)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(644)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    Completion time: 2009-03-19  0:54:11
    ComboFix-quarantined-files.txt  2009-03-19 04:54:07

    Pre-Run: 31,787,245,568 bytes free
    Post-Run: 32,360,882,176 bytes free

    CURRENT=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
    376   --- E O F ---   2009-03-13 22:12:01
    I just did a search about the original error I received: "error loading dll32".  I saw somebody's response to their browser not being able to access the internet (like my problem).  Apparently changed the proxy settings (which I had no idea what that was, but Googled and found how to change them on firefox). I looked at the proxy settings on an uncorrupted user account and saw how they were set "No Proxy".  My corrupted user account was set for manual with a particular port.  When I changed it to "No Proxy", voila, internet access.
    Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    RegLock::
    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Control]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\TypeLib]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Version]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\VersionIndependentProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\TypeLib]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Control]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Version]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\Programmable]

    [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\VersionIndependentProgID]

    [-HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid]

    [-HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32]

    [-HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib]

    Folder::
    C:\found.000
    c:\windows\system32\nfr.gpref
    c:\windows\system32\nfr.assembly
    c:\windows\9g234sdfdfgjf23

    File::
    c:\windows\system32\nfr.assembly
    C:\found.000
    c:\windows\t55ft2807f44.dat

    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "80:TCP"=-
    "7171:TCP"=-

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze


    ComboFix 09-03-18.01 - Becky 2009-03-19 11:37:10.2 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1535.1092 [GMT -4:00]
    Running from: c:\documents and settings\Becky\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Becky\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
     * Created a new restore point

    FILE ::
    C:\found.000
    c:\windows\system32\nfr.assembly
    c:\windows\t55ft2807f44.dat
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Becky\Desktop\notepad.exe
    C:\found.000
    c:\found.000\file0000.chk
    c:\windows\9g234sdfdfgjf23\
    c:\windows\system32\nfr.assembly
    c:\windows\system32\nfr.gpref\
    c:\windows\t55ft2807f44.dat

    .
    (((((((((((((((((((((((((   Files Created from 2009-02-19 to 2009-03-19  )))))))))))))))))))))))))))))))
    .

    2009-03-18 19:09 . 2009-03-18 19:09   410,984   --a------   c:\windows\system32\deploytk.dll
    2009-03-18 18:42 . 2009-03-18 18:42      d--------   c:\documents and settings\Becky\Application Data\Malwarebytes
    2009-03-18 18:42 . 2009-02-11 10:19   15,504   --a------   c:\windows\system32\drivers\mbam.sys
    2009-03-18 18:41 . 2009-03-18 18:42      d--------   c:\program files\Malwarebytes' Anti-Malware
    2009-03-18 18:41 . 2009-03-18 18:41      d--------   c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-18 18:41 . 2009-02-11 10:19   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\SUPERAntiSpyware
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\Common Files\Wise Installation Wizard
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\documents and settings\Becky\Application Data\SUPERAntiSpyware.com
    2009-03-18 15:04 . 2009-03-18 15:04      d--------   c:\program files\CCleaner
    2009-03-17 15:50 . 2008-04-13 20:12   116,224   --a--c---   c:\windows\system32\dllcache\xrxwiadr.dll
    2009-03-17 15:50 . 2001-08-17 22:37   99,865   --a--c---   c:\windows\system32\dllcache\xlog.exe
    2009-03-17 15:50 . 2001-08-17 22:37   27,648   --a--c---   c:\windows\system32\dllcache\xrxftplt.exe
    2009-03-17 15:50 . 2001-08-17 22:36   23,040   --a--c---   c:\windows\system32\dllcache\xrxwbtmp.dll
    2009-03-17 15:50 . 2004-08-03 22:29   19,455   --a--c---   c:\windows\system32\dllcache\wvchntxx.sys
    2009-03-17 15:50 . 2008-04-13 20:12   18,944   --a--c---   c:\windows\system32\dllcache\xrxscnui.dll
    2009-03-17 15:50 . 2001-08-17 12:11   16,970   --a--c---   c:\windows\system32\dllcache\xem336n5.sys
    2009-03-17 15:50 . 2004-08-03 22:29   12,063   --a--c---   c:\windows\system32\dllcache\wsiintxx.sys
    2009-03-17 15:50 . 2008-04-13 14:36   8,832   --a--c---   c:\windows\system32\dllcache\wmiacpi.sys
    2009-03-17 15:50 . 2008-04-13 20:12   8,192   --a--c---   c:\windows\system32\dllcache\wshirda.dll
    2009-03-17 15:50 . 2001-08-17 22:37   4,608   --a--c---   c:\windows\system32\dllcache\xrxflnch.exe
    2009-03-17 15:48 . 2001-08-17 22:36   525,568   --a--c---   c:\windows\system32\dllcache\tridxp.dll
    2009-03-17 15:47 . 2001-08-17 22:36   495,616   --a--c---   c:\windows\system32\dllcache\sblfx.dll
    2009-03-17 15:46 . 2001-08-17 13:28   899,146   --a--c---   c:\windows\system32\dllcache\r2mdkxga.sys
    2009-03-17 15:45 . 2001-08-17 12:50   198,144   --a--c---   c:\windows\system32\dllcache\nv3.sys
    2009-03-17 15:44 . 2001-08-17 13:28   802,683   --a--c---   c:\windows\system32\dllcache\ltsm.sys
    2009-03-17 15:43 . 2008-04-13 20:11   702,845   --a--c---   c:\windows\system32\dllcache\i81xdnt5.dll
    2009-03-17 15:42 . 2001-08-17 14:56   1,733,120   --a--c---   c:\windows\system32\dllcache\g400d.dll
    2009-03-17 15:41 . 2001-08-17 12:14   952,007   --a--c---   c:\windows\system32\dllcache\diwan.sys
    2009-03-17 15:40 . 2001-08-17 12:13   980,034   --a--c---   c:\windows\system32\dllcache\cicap.sys
    2009-03-17 15:33 . 2001-08-17 13:28   871,388   --a--c---   c:\windows\system32\dllcache\bcmdm.sys
    2009-03-17 15:32 . 2001-08-17 14:55   382,592   --a--c---   c:\windows\system32\dllcache\atidrab.dll
    2009-03-17 15:31 . 2001-08-17 12:19   747,392   --a--c---   c:\windows\system32\dllcache\adm8830.sys
    2009-03-17 15:30 . 2001-08-17 13:28   762,780   --a--c---   c:\windows\system32\dllcache\3cwmcru.sys
    2009-03-17 15:30 . 2001-08-17 14:55   689,216   --a--c---   c:\windows\system32\dllcache\3dfxvs.dll
    2009-03-17 15:30 . 2001-08-17 14:56   66,048   --a--c---   c:\windows\system32\dllcache\s3legacy.dll
    2009-03-17 15:30 . 2008-04-13 14:46   53,376   --a--c---   c:\windows\system32\dllcache\1394bus.sys
    2009-03-17 15:30 . 2001-08-17 14:06   11,264   --a--c---   c:\windows\system32\dllcache\1394vdbg.sys
    2009-03-17 00:05 . 2009-03-17 00:05   0   --a------   c:\windows\system32\nfr.gpref
    2009-03-16 23:50 . 2009-03-16 23:50   1   --a------   c:\windows\9g234sdfdfgjf23
    2009-03-11 21:16 . 2009-03-11 21:16      d--------   c:\documents and settings\David\Application Data\AVGTOOLBAR

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-19 15:29   ---------   d-----w   c:\documents and settings\user pc\Application Data\WTablet
    2009-03-18 23:12   ---------   d-----w   c:\program files\Java
    2009-03-18 19:00   ---------   d-----w   c:\program files\Lavasoft
    2009-03-18 19:00   ---------   d-----w   c:\documents and settings\All Users\Application Data\Lavasoft
    2009-03-17 16:21   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
    2009-03-17 09:26   ---------   d-----w   c:\documents and settings\user pc\Application Data\uTorrent
    2009-03-15 21:35   138,624   ----a-w   c:\windows\system32\drivers\PnkBstrK.sys
    2009-03-15 04:15   ---------   d-----w   c:\documents and settings\user pc\Application Data\DVD Flick
    2009-03-15 01:38   ---------   d-----w   c:\documents and settings\user pc\Application Data\dvdcss
    2009-03-07 17:20   ---------   d-----w   c:\program files\Ahead
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\ZoomBrowser EX
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\CameraWindowDC
    2009-02-25 15:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\AVGTOOLBAR
    2009-02-12 16:12   ---------   d-----w   c:\program files\Google
    2009-02-11 02:24   34   ----a-w   c:\documents and settings\user pc\jagex_runescape_preferences.dat
    2009-02-10 04:35   ---------   d-----w   c:\documents and settings\Leanne\Application Data\AVGTOOLBAR
    2009-02-10 04:19   ---------   d-----w   c:\documents and settings\Leanne\Application Data\vlc
    2009-02-09 03:08   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Apple Computer
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\WTablet
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Network Associates
    2009-02-09 02:42   ---------   d-----w   c:\documents and settings\Becky\Application Data\AVGTOOLBAR
    2009-02-09 02:38   ---------   d-----w   c:\documents and settings\Becky\Application Data\vlc
    2009-02-05 18:37   ---------   d-----w   c:\documents and settings\user pc\Application Data\vlc
    2009-02-05 18:16   ---------   d-----w   c:\program files\VideoLAN
    2009-02-03 19:16   ---------   d-----w   c:\program files\Improvisation
    2009-01-27 15:56   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
    2009-01-27 15:55   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
    2009-01-25 05:54   ---------   d-----w   c:\documents and settings\user pc\Application Data\Any Video Converter
    2009-01-24 22:06   ---------   d-----w   c:\program files\AVG
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
    2009-01-24 20:56   ---------   d-----w   c:\documents and settings\All Users\Application Data\nView_Profiles
    2008-09-27 02:22   24   ----a-w   c:\documents and settings\David\jagex_runescape_preferences.dat
    .

    (((((((((((((((((((((((((((((   [email protected]_ 0.53.12.29   )))))))))))))))))))))))))))))))))))))))))
    .
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\admxprox.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\admxprox.dll
    - 2002-08-29 12:00:00   49,664   -c--a-w   c:\windows\system32\dllcache\adrot.dll
    + 2004-08-04 01:07:00   49,664   -c--a-w   c:\windows\system32\dllcache\adrot.dll
    - 2002-08-29 12:00:00   10,240   -c--a-w   c:\windows\system32\dllcache\aspperf.dll
    + 2004-08-04 01:07:00   10,240   -c--a-w   c:\windows\system32\dllcache\aspperf.dll
    - 2002-08-29 12:00:00   29,184   -c--a-w   c:\windows\system32\dllcache\asptxn.dll
    + 2004-08-04 01:07:00   29,184   -c--a-w   c:\windows\system32\dllcache\asptxn.dll
    - 2002-08-29 12:00:00   9,216   -c--a-w   c:\windows\system32\dllcache\authfilt.dll
    + 2004-08-04 01:07:00   9,216   -c--a-w   c:\windows\system32\dllcache\authfilt.dll
    - 2002-08-29 12:00:00   45,568   -c--a-w   c:\windows\system32\dllcache\browscap.dll
    + 2004-08-04 01:07:00   45,568   -c--a-w   c:\windows\system32\dllcache\browscap.dll
    - 2002-08-29 12:00:00   6,656   -c--a-w   c:\windows\system32\dllcache\c_is2022.dll
    + 2004-08-04 01:07:00   6,656   -c--a-w   c:\windows\system32\dllcache\c_is2022.dll
    - 2002-08-29 12:00:00   10,752   -c--a-w   c:\windows\system32\dllcache\c_iscii.dll
    + 2004-08-04 01:07:00   10,752   -c--a-w   c:\windows\system32\dllcache\c_iscii.dll
    - 2002-08-29 12:00:00   54,528   -c--a-w   c:\windows\system32\dllcache\cap7146.sys
    + 2004-08-04 01:07:00   54,528   -c--a-w   c:\windows\system32\dllcache\cap7146.sys
    - 2002-08-29 12:00:00   9,728   -c--a-w   c:\windows\system32\dllcache\change.exe
    + 2004-08-04 01:07:00   9,728   -c--a-w   c:\windows\system32\dllcache\change.exe
    - 2002-08-29 12:00:00   13,312   -c--a-w   c:\windows\system32\dllcache\chglogon.exe
    + 2004-08-04 01:07:00   13,312   -c--a-w   c:\windows\system32\dllcache\chglogon.exe
    - 2002-08-29 12:00:00   15,872   -c--a-w   c:\windows\system32\dllcache\chgport.exe
    + 2004-08-04 01:07:00   15,872   -c--a-w   c:\windows\system32\dllcache\chgport.exe
    - 2002-08-29 12:00:00   14,336   -c--a-w   c:\windows\system32\dllcache\chgusr.exe
    + 2004-08-04 01:07:00   14,336   -c--a-w   c:\windows\system32\dllcache\chgusr.exe
    - 2002-08-29 12:00:00   1,677,824   -c--a-w   c:\windows\system32\dllcache\chsbrkr.dll
    + 2004-08-04 01:07:00   1,677,824   -c--a-w   c:\windows\system32\dllcache\chsbrkr.dll
    - 2002-08-29 12:00:00   838,144   -c--a-w   c:\windows\system32\dllcache\chtbrkr.dll
    + 2004-08-04 01:07:00   838,144   -c--a-w   c:\windows\system32\dllcache\chtbrkr.dll
    - 2002-08-29 12:00:00   33,792   -c--a-w   c:\windows\system32\dllcache\controt.dll
    + 2004-08-04 01:07:00   33,792   -c--a-w   c:\windows\system32\dllcache\controt.dll
    - 2002-08-29 12:00:00   56,320   -c--a-w   c:\windows\system32\dllcache\convlog.exe
    + 2004-08-04 01:07:00   56,320   -c--a-w   c:\windows\system32\dllcache\convlog.exe
    - 2002-08-29 12:00:00   20,480   -c--a-w   c:\windows\system32\dllcache\counters.dll
    + 2004-08-04 01:07:00   20,480   -c--a-w   c:\windows\system32\dllcache\counters.dll
    - 2002-08-29 12:00:00   18,944   -c--a-w   c:\windows\system32\dllcache\cprofile.exe
    + 2004-08-04 01:07:00   18,944   -c--a-w   c:\windows\system32\dllcache\cprofile.exe
    - 2002-08-29 12:00:00   31,744   -c--a-w   c:\windows\system32\dllcache\esucmd.dll
    + 2004-08-04 01:07:00   31,744   -c--a-w   c:\windows\system32\dllcache\esucmd.dll
    - 2002-08-29 12:00:00   57,856   -c--a-w   c:\windows\system32\dllcache\esuimgd.dll
    + 2004-08-04 01:07:00   57,856   -c--a-w   c:\windows\system32\dllcache\esuimgd.dll
    - 2002-08-29 12:00:00   45,056   -c--a-w   c:\windows\system32\dllcache\esunid.dll
    + 2004-08-04 01:07:00   45,056   -c--a-w   c:\windows\system32\dllcache\esunid.dll
    - 2002-08-29 12:00:00   25,856   -c--a-w   c:\windows\system32\dllcache\et4000.sys
    + 2004-08-04 01:07:00   25,856   -c--a-w   c:\windows\system32\dllcache\et4000.sys
    - 2002-08-29 12:00:00   14,848   -c--a-w   c:\windows\system32\dllcache\flattemp.exe
    + 2004-08-04 01:07:00   14,848   -c--a-w   c:\windows\system32\dllcache\flattemp.exe
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\ftlx041e.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\ftlx041e.dll
    - 2002-08-29 12:00:00   7,680   -c--a-w   c:\windows\system32\dllcache\ftpctrs2.dll
    + 2004-08-04 01:07:00   7,680   -c--a-w   c:\windows\system32\dllcache\ftpctrs2.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\ftpsapi2.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\ftpsapi2.dll
    - 2002-08-29 12:00:00   111,104   -c--a-w   c:\windows\system32\dllcache\fxscfgwz.dll
    + 2004-08-04 01:07:00   111,104   -c--a-w   c:\windows\system32\dllcache\fxscfgwz.dll
    - 2002-08-29 12:00:00   132,608   -c--a-w   c:\windows\system32\dllcache\fxsclntr.dll
    + 2004-08-04 01:07:00   132,608   -c--a-w   c:\windows\system32\dllcache\fxsclntr.dll
    - 2002-08-29 12:00:00   31,744   -c--a-w   c:\windows\system32\dllcache\fxsroute.dll
    + 2004-08-04 01:07:00   31,744   -c--a-w   c:\windows\system32\dllcache\fxsroute.dll
    - 2002-08-29 12:00:00   11,264   -c--a-w   c:\windows\system32\dllcache\fxssend.exe
    + 2004-08-04 01:07:00   11,264   -c--a-w   c:\windows\system32\dllcache\fxssend.exe
    - 2002-08-29 12:00:00   36,864   -c--a-w   c:\windows\system32\dllcache\hanjadic.dll
    + 2004-08-04 01:07:00   36,864   -c--a-w   c:\windows\system32\dllcache\hanjadic.dll
    - 2002-08-29 12:00:00   10,096,640   -c--a-w   c:\windows\system32\dllcache\hwxcht.dll
    + 2004-08-04 01:07:00   10,096,640   -c--a-w   c:\windows\system32\dllcache\hwxcht.dll
    - 2002-08-29 12:00:00   10,129,408   -c--a-w   c:\windows\system32\dllcache\hwxkor.dll
    + 2004-08-04 01:07:00   10,129,408   -c--a-w   c:\windows\system32\dllcache\hwxkor.dll
    - 2002-08-29 12:00:00   60,928   -c--a-w   c:\windows\system32\dllcache\iisclex4.dll
    + 2004-08-04 01:07:00   60,928   -c--a-w   c:\windows\system32\dllcache\iisclex4.dll
    - 2002-08-29 12:00:00   19,456   -c--a-w   c:\windows\system32\dllcache\iiscrmap.dll
    + 2004-08-04 01:07:00   19,456   -c--a-w   c:\windows\system32\dllcache\iiscrmap.dll
    - 2002-08-29 12:00:00   3,584   -c--a-w   c:\windows\system32\dllcache\iismui.dll
    + 2004-08-04 01:07:00   3,584   -c--a-w   c:\windows\system32\dllcache\iismui.dll
    - 2002-08-29 12:00:00   14,336   -c--a-w   c:\windows\system32\dllcache\iisreset.exe
    + 2004-08-04 01:07:00   14,336   -c--a-w   c:\windows\system32\dllcache\iisreset.exe
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\iisrstap.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\iisrstap.dll
    - 2002-08-29 12:00:00   6,656   -c--a-w   c:\windows\system32\dllcache\iissync.exe
    + 2004-08-04 01:07:00   6,656   -c--a-w   c:\windows\system32\dllcache\iissync.exe
    - 2002-08-29 12:00:00   169,984   -c--a-w   c:\windows\system32\dllcache\iisui.dll
    + 2004-08-04 01:07:00   169,984   -c--a-w   c:\windows\system32\dllcache\iisui.dll
    - 2002-08-29 12:00:00   44,032   -c--a-w   c:\windows\system32\dllcache\imekrmig.exe
    + 2004-08-04 01:07:00   44,032   -c--a-w   c:\windows\system32\dllcache\imekrmig.exe
    - 2002-08-29 12:00:00   102,463   -c--a-w   c:\windows\system32\dllcache\imepadsm.dll
    + 2004-08-04 01:07:00   102,463   -c--a-w   c:\windows\system32\dllcache\imepadsm.dll
    - 2002-08-29 12:00:00   311,359   -c--a-w   c:\windows\system32\dllcache\imepadsv.exe
    + 2004-08-04 01:07:00   311,359   -c--a-w   c:\windows\system32\dllcache\imepadsv.exe
    - 2002-08-29 12:00:00   57,398   -c--a-w   c:\windows\system32\dllcache\imjpdadm.exe
    + 2004-08-04 01:07:00   57,398   -c--a-w   c:\windows\system32\dllcache\imjpdadm.exe
    - 2002-08-29 12:00:00   45,109   -c--a-w   c:\windows\system32\dllcache\imjpuex.exe
    + 2004-08-04 01:07:00   45,109   -c--a-w   c:\windows\system32\dllcache\imjpuex.exe
    - 2002-08-29 12:00:00   59,904   -c--a-w   c:\windows\system32\dllcache\imkrinst.exe
    + 2004-08-04 01:07:00   59,904   -c--a-w   c:\windows\system32\dllcache\imkrinst.exe
    - 2002-08-29 12:00:00   471,102   -c--a-w   c:\windows\system32\dllcache\imskdic.dll
    + 2004-08-04 01:07:00   471,102   -c--a-w   c:\windows\system32\dllcache\imskdic.dll
    - 2002-08-29 12:00:00   7,680   -c--a-w   c:\windows\system32\dllcache\inetmgr.exe
    + 2004-08-04 01:07:00   7,680   -c--a-w   c:\windows\system32\dllcache\inetmgr.exe
    - 2002-08-29 12:00:00   19,968   -c--a-w   c:\windows\system32\dllcache\inetsloc.dll
    + 2004-08-04 01:07:00   19,968   -c--a-w   c:\windows\system32\dllcache\inetsloc.dll
    - 2002-08-29 12:00:00   8,704   -c--a-w   c:\windows\system32\dllcache\infoctrs.dll
    + 2004-08-04 01:07:00   8,704   -c--a-w   c:\windows\system32\dllcache\infoctrs.dll
    - 2002-08-29 12:00:00   7,168   -c--a-w   c:\windows\system32\dllcache\isapips.dll
    + 2004-08-04 01:07:00   7,168   -c--a-w   c:\windows\system32\dllcache\isapips.dll
    - 2002-08-29 12:00:00   9,216   -c--a-w   c:\windows\system32\dllcache\iwrps.dll
    + 2004-08-04 01:07:00   9,216   -c--a-w   c:\windows\system32\dllcache\iwrps.dll
    - 2002-08-29 12:00:00   18,432   -c--a-w   c:\windows\system32\dllcache\jupiw.dll
    + 2004-08-04 01:07:00   18,432   -c--a-w   c:\windows\system32\dllcache\jupiw.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbd101a.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbd101a.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda1.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda1.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda2.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda2.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda3.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbda3.dll
    - 2002-08-29 12:00:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdarme.dll
    + 2004-08-04 01:07:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdarme.dll
    - 2002-08-29 12:00:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdarmw.dll
    + 2004-08-04 01:07:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdarmw.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbddiv1.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbddiv1.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbddiv2.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbddiv2.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdfa.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdfa.dll
    - 2002-08-29 12:00:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdgeo.dll
    + 2004-08-04 01:07:00   5,120   -c--a-w   c:\windows\system32\dllcache\kbdgeo.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdheb.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdheb.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdindev.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdindev.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinguj.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinguj.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinhin.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinhin.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinkan.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinkan.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinmar.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdinmar.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdinpun.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdinpun.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdintam.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdintam.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdintel.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdintel.dll
    - 2002-08-29 12:00:00   7,168   -c--a-w   c:\windows\system32\dllcache\kbdnec95.dll
    + 2004-08-04 01:07:00   7,168   -c--a-w   c:\windows\system32\dllcache\kbdnec95.dll
    - 2002-08-29 12:00:00   9,216   -c--a-w   c:\windows\system32\dllcache\kbdnecat.dll
    + 2004-08-04 01:07:00   9,216   -c--a-w   c:\windows\system32\dllcache\kbdnecat.dll
    - 2002-08-29 12:00:00   7,680   -c--a-w   c:\windows\system32\dllcache\kbdnecnt.dll
    + 2004-08-04 01:07:00   7,680   -c--a-w   c:\windows\system32\dllcache\kbdnecnt.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdsyr1.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdsyr1.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdsyr2.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdsyr2.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdth0.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdth0.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdth1.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdth1.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdth2.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdth2.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdth3.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\kbdth3.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdurdu.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdurdu.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdusa.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdusa.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdvntc.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\kbdvntc.dll
    - 2002-08-29 12:00:00   70,656   -c--a-w   c:\windows\system32\dllcache\korwbrkr.dll
    + 2004-08-04 01:07:00   70,656   -c--a-w   c:\windows\system32\dllcache\korwbrkr.dll
    - 2002-08-29 12:00:00   22,016   -c--a-w   c:\windows\system32\dllcache\logscrpt.dll
    + 2004-08-04 01:07:00   22,016   -c--a-w   c:\windows\system32\dllcache\logscrpt.dll
    - 2002-08-29 12:00:00   26,624   -c--a-w   c:\windows\system32\dllcache\mdsync.dll
    + 2004-08-04 01:07:00   26,624   -c--a-w   c:\windows\system32\dllcache\mdsync.dll
    - 2002-08-29 12:00:00   92,032   -c--a-w   c:\windows\system32\dllcache\mga.dll
    + 2004-08-04 01:07:00   92,032   -c--a-w   c:\windows\system32\dllcache\mga.dll
    - 2002-08-29 12:00:00   92,416   -c--a-w   c:\windows\system32\dllcache\mga.sys
    + 2004-08-04 01:07:00   92,416   -c--a-w   c:\windows\system32\dllcache\mga.sys
    - 2002-08-29 12:00:00   34,304   -c--a-w   c:\windows\system32\dllcache\migisol.exe
    + 2004-08-04 01:07:00   34,304   -c--a-w   c:\windows\system32\dllcache\migisol.exe
    - 2002-08-29 12:00:00   98,304   -c--a-w   c:\windows\system32\dllcache\msir3jp.dll
    + 2004-08-04 01:07:00   98,304   -c--a-w   c:\windows\system32\dllcache\msir3jp.dll
    - 2002-08-29 12:00:00   229,439   -c--a-w   c:\windows\system32\dllcache\multibox.dll
    + 2004-08-04 01:07:00   229,439   -c--a-w   c:\windows\system32\dllcache\multibox.dll
    - 2002-08-29 12:00:00   53,248   -c--a-w   c:\windows\system32\dllcache\nextlink.dll
    + 2004-08-04 01:07:00   53,248   -c--a-w   c:\windows\system32\dllcache\nextlink.dll
    - 2002-08-29 12:00:00   36,927   -c--a-w   c:\windows\system32\dllcache\padrs411.dll
    + 2004-08-04 01:07:00   36,927   -c--a-w   c:\windows\system32\dllcache\padrs411.dll
    - 2002-08-29 12:00:00   14,336   -c--a-w   c:\windows\system32\dllcache\padrs412.dll
    + 2004-08-04 01:07:00   14,336   -c--a-w   c:\windows\system32\dllcache\padrs412.dll
    - 2002-08-29 12:00:00   31,744   -c--a-w   c:\windows\system32\dllcache\pagecnt.dll
    + 2004-08-04 01:07:00   31,744   -c--a-w   c:\windows\system32\dllcache\pagecnt.dll
    - 2002-08-29 12:00:00   20,992   -c--a-w   c:\windows\system32\dllcache\permchk.dll
    + 2004-08-04 01:07:00   20,992   -c--a-w   c:\windows\system32\dllcache\permchk.dll
    - 2002-08-29 12:00:00   6,144   -c--a-w   c:\windows\system32\dllcache\pmxgl.dll
    + 2004-08-04 01:07:00   6,144   -c--a-w   c:\windows\system32\dllcache\pmxgl.dll
    - 2002-08-29 12:00:00   11,264   -c--a-w   c:\windows\system32\dllcache\pmxmcro.dll
    + 2004-08-04 01:07:00   11,264   -c--a-w   c:\windows\system32\dllcache\pmxmcro.dll
    - 2002-08-29 12:00:00   131,584   -c--a-w   c:\windows\system32\dllcache\pmxviceo.dll
    + 2004-08-04 01:07:00   131,584   -c--a-w   c:\windows\system32\dllcache\pmxviceo.dll
    - 2002-08-29 12:00:00   9,728   -c--a-w   c:\windows\system32\dllcache\query.exe
    + 2004-08-04 01:07:00   9,728   -c--a-w   c:\windows\system32\dllcache\query.exe
    - 2002-08-29 12:00:00   16,384   -c--a-w   c:\windows\system32\dllcache\quser.exe
    + 2004-08-04 01:07:00   16,384   -c--a-w   c:\windows\system32\dllcache\quser.exe
    - 2002-08-29 12:00:00   14,848   -c--a-w   c:\windows\system32\dllcache\register.exe
    + 2004-08-04 01:07:00   14,848   -c--a-w   c:\windows\system32\dllcache\register.exe
    - 2002-08-29 12:00:00   79,872   -c--a-w   c:\windows\system32\dllcache\rwia001.dll
    + 2004-08-04 01:07:00   79,872   -c--a-w   c:\windows\system32\dllcache\rwia001.dll
    - 2002-08-29 12:00:00   79,872   -c--a-w   c:\windows\system32\dllcache\rwia330.dll
    + 2004-08-04 01:07:00   79,872   -c--a-w   c:\windows\system32\dllcache\rwia330.dll
    - 2002-08-29 12:00:00   18,944   -c--a-w   c:\windows\system32\dllcache\simptcp.dll
    + 2004-08-04 01:07:00   18,944   -c--a-w   c:\windows\system32\dllcache\simptcp.dll
    - 2002-08-29 12:00:00   25,088   -c--a-w   c:\windows\system32\dllcache\sm59w.dll
    + 2004-08-04 01:07:00   25,088   -c--a-w   c:\windows\system32\dllcache\sm59w.dll
    - 2002-08-29 12:00:00   30,208   -c--a-w   c:\windows\system32\dllcache\sm81w.dll
    + 2004-08-04 01:07:00   30,208   -c--a-w   c:\windows\system32\dllcache\sm81w.dll
    - 2002-08-29 12:00:00   30,208   -c--a-w   c:\windows\system32\dllcache\sm87w.dll
    + 2004-08-04 01:07:00   30,208   -c--a-w   c:\windows\system32\dllcache\sm87w.dll
    - 2002-08-29 12:00:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm89w.dll
    + 2004-08-04 01:07:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm89w.dll
    - 2002-08-29 12:00:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm8aw.dll
    + 2004-08-04 01:07:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm8aw.dll
    - 2002-08-29 12:00:00   29,184   -c--a-w   c:\windows\system32\dllcache\sm8cw.dll
    + 2004-08-04 01:07:00   29,184   -c--a-w   c:\windows\system32\dllcache\sm8cw.dll
    - 2002-08-29 12:00:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm8dw.dll
    + 2004-08-04 01:07:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm8dw.dll
    - 2002-08-29 12:00:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm90w.dll
    + 2004-08-04 01:07:00   26,112   -c--a-w   c:\windows\system32\dllcache\sm90w.dll
    - 2002-08-29 12:00:00   26,624   -c--a-w   c:\windows\system32\dllcache\sm92w.dll
    + 2004-08-04 01:07:00   26,624   -c--a-w   c:\windows\system32\dllcache\sm92w.dll
    - 2002-08-29 12:00:00   26,624   -c--a-w   c:\windows\system32\dllcache\sm93w.dll
    + 2004-08-04 01:07:00   26,624   -c--a-w   c:\windows\system32\dllcache\sm93w.dll
    - 2002-08-29 12:00:00   38,912   -c--a-w   c:\windows\system32\dllcache\sm9aw.dll
    + 2004-08-04 01:07:00   38,912   -c--a-w   c:\windows\system32\dllcache\sm9aw.dll
    - 2002-08-29 12:00:00   31,744   -c--a-w   c:\windows\system32\dllcache\sma3w.dll
    + 2004-08-04 01:07:00   31,744   -c--a-w   c:\windows\system32\dllcache\sma3w.dll
    - 2002-08-29 12:00:00   31,744   -c--a-w   c:\windows\system32\dllcache\smb6w.dll
    + 2004-08-04 01:07:00   31,744   -c--a-w   c:\windows\system32\dllcache\smb6w.dll
    - 2002-08-29 12:00:00   15,872   -c--a-w   c:\windows\system32\dllcache\smierrsm.dll
    + 2004-08-04 01:07:00   15,872   -c--a-w   c:\windows\system32\dllcache\smierrsm.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\smierrsy.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\smierrsy.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\smimsgif.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\smimsgif.dll
    - 2002-08-29 12:00:00   10,240   -c--a-w   c:\windows\system32\dllcache\snmpstup.dll
    + 2004-08-04 01:07:00   10,240   -c--a-w   c:\windows\system32\dllcache\snmpstup.dll
    - 2002-08-29 12:00:00   143,422   -c--a-w   c:\windows\system32\dllcache\softkey.dll
    + 2004-08-04 01:07:00   143,422   -c--a-w   c:\windows\system32\dllcache\softkey.dll
    - 2002-08-29 12:00:00   101,376   -c--a-w   c:\windows\system32\dllcache\srusbusd.dll
    + 2004-08-04 01:07:00   101,376   -c--a-w   c:\windows\system32\dllcache\srusbusd.dll
    - 2002-08-29 12:00:00   16,896   -c--a-w   c:\windows\system32\dllcache\status.dll
    + 2004-08-04 01:07:00   16,896   -c--a-w   c:\windows\system32\dllcache\status.dll
    - 2002-08-29 12:00:00   13,192   -c--a-w   c:\windows\system32\dllcache\tdasync.sys
    + 2004-08-04 01:07:00   13,192   -c--a-w   c:\windows\system32\dllcache\tdasync.sys
    - 2002-08-29 12:00:00   21,896   -c--a-w   c:\windows\system32\dllcache\tdipx.sys
    + 2004-08-04 01:07:00   21,896   -c--a-w   c:\windows\system32\dllcache\tdipx.sys
    - 2002-08-29 12:00:00   19,464   -c--a-w   c:\windows\system32\dllcache\tdspx.sys
    + 2004-08-04 01:07:00   19,464   -c--a-w   c:\windows\system32\dllcache\tdspx.sys
    - 2002-08-29 12:00:00   185,344   -c--a-w   c:\windows\system32\dllcache\thawbrkr.dll
    + 2004-08-04 01:07:00   185,344   -c--a-w   c:\windows\system32\dllcache\thawbrkr.dll
    - 2002-08-29 12:00:00   14,336   -c--a-w   c:\windows\system32\dllcache\tsprof.exe
    + 2004-08-04 01:07:00   14,336   -c--a-w   c:\windows\system32\dllcache\tsprof.exe
    - 2002-08-29 12:00:00   48,256   -c--a-w   c:\windows\system32\dllcache\w32.dll
    + 2004-08-04 01:07:00   48,256   -c--a-w   c:\windows\system32\dllcache\w32.dll
    - 2002-08-29 12:00:00   4,608   -c--a-w   c:\windows\system32\dllcache\w3ctrs51.dll
    + 2004-08-04 01:07:00   4,608   -c--a-w   c:\windows\system32\dllcache\w3ctrs51.dll
    - 2002-08-29 12:00:00   73,728   -c--a-w   c:\windows\system32\dllcache\w3ext.dll
    + 2004-08-04 01:07:00   73,728   -c--a-w   c:\windows\system32\dllcache\w3ext.dll
    - 2002-08-29 12:00:00   5,632   -c--a-w   c:\windows\system32\dllcache\w3svapi.dll
    + 2004-08-04 01:07:00   5,632   -c--a-w   c:\windows\system32\dllcache\w3svapi.dll
    - 2002-08-29 12:00:00   9,216   -c--a-w   c:\windows\system32\dllcache\wamps51.dll
    + 2004-08-04 01:07:00   9,216   -c--a-w   c:\windows\system32\dllcache\wamps51.dll
    - 2002-08-29 12:00:00   7,168   -c--a-w   c:\windows\system32\dllcache\wamregps.dll
    + 2004-08-04 01:07:00   7,168   -c--a-w   c:\windows\system32\dllcache\wamregps.dll
    - 2002-08-29 12:00:00   41,600   -c--a-w   c:\windows\system32\dllcache\weitekp9.dll
    + 2004-08-04 01:07:00   41,600   -c--a-w   c:\windows\system32\dllcache\weitekp9.dll
    - 2002-08-29 12:00:00   31,232   -c--a-w   c:\windows\system32\dllcache\weitekp9.sys
    + 2004-08-04 01:07:00   31,232   -c--a-w   c:\windows\system32\dllcache\weitekp9.sys
    + 2009-03-19 15:41:43   16,384   ----atw   c:\windows\temp\Perflib_Perfdata_6f0.dat
    .
    -- Snapshot reset to current date --
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-31 180269]
    "McAfeeFireTray"="c:\progra~1\NETWOR~1\MCAFEE~1\Firetray.exe" [2005-04-12 655420]
    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
    "NvMediaCenter"="NvMCTray.dll" [2008-05-03 c:\windows\system32\nvmctray.dll]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-01-27 11:56 10520 c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
    backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Personal Coach.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Personal Coach.lnk
    backup=c:\windows\pss\Personal Coach.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTZDetec.exe]
    --a------ 2007-12-18 15:20 401408 c:\documents and settings\user pc\Desktop\David\Creative Media Lite\CTZDetec.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-03-28 23:37 413696 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-04-04 19:00 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    --a------ 2008-05-03 06:46 1630208 c:\windows\system32\nwiz.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-24 325128]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-24 107272]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-24 903960]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-24 298264]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

    2009-03-17 c:\windows\Tasks\Uniblue SpyEraser Nag.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []

    2007-09-04 c:\windows\Tasks\Uniblue SpyEraser.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
    .
    .
    ------- Supplementary Scan -------
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Becky\Application Data\Mozilla\Firefox\Profiles\v0zlm1jn.default\
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-19 11:42:12
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0]
    DACL=(02 0000)
    ="HtmldocPlugin 1.0 Type Library"

    [HKEY_LOCAL_MACHINE\software\PortraitDisplays\DisplayTune\MGJ74D0C06550]
    DACL=(02 0000)
    "Analog 0.700,0.300Caps"="vcp(02 04 05 06 08 0E 10 12 14(01 05 08 0B) 16 18 1A 1E 20 30 3E 52 60(01 03) 68 AC AE B2 B6 C0 C6 C8 C9 CA D6(01 04) DF FA FB FC FD FE AA(01 04)) vcp_p2(37 38 39 3B) type(LCD) mccs_ver(2.0) asset_eep(64) mpu(0.04)"

    [HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\HID\Vid_045e&Pid_00f9&MI_01&Col02\7&36e0efb9&0&0001\LogConf]
    DACL=(02 0000)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(648)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Creative\Shared Files\CTDevSrv.exe
    c:\progra~1\NETWOR~1\MCAFEE~1\FireSvc.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\PnkBstrA.exe
    c:\windows\system32\PnkBstrB.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\Tablet.exe
    c:\windows\wanmpsvc.exe
    c:\windows\system32\WTablet\TabUserW.exe
    c:\windows\system32\Tablet.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\windows\system32\rundll32.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-19 11:45:02 - machine was rebooted
    ComboFix-quarantined-files.txt  2009-03-19 15:44:58
    ComboFix2.txt  2009-03-19 04:54:14

    Pre-Run: 32,409,468,928 bytes free
    Post-Run: 32,390,303,744 bytes free

    Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
    534   --- E O F ---   2009-03-13 22:12:01
    Were getting closer.

    Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    Folder::
    c:\windows\system32\nfr.gpref
    c:\windows\9g234sdfdfgjf23

    File::
    c:\windows\system32\nfr.gpref
    c:\windows\9g234sdfdfgjf23

    RegLock::
    [-HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0]

    [-HKEY_LOCAL_MACHINE\software\PortraitDisplays\DisplayTune\MGJ74D0C06550]

    [-HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\HID\Vid_045e&Pid_00f9&MI_01&Col02\7&36e0efb9&0&0001\LogConf]

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
    ComboFix 09-03-18.01 - Becky 2009-03-19 14:09:30.3 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1535.1096 [GMT -4:00]
    Running from: c:\documents and settings\Becky\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Becky\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
     * Created a new restore point

    FILE ::
    c:\windows\9g234sdfdfgjf23
    c:\windows\system32\nfr.gpref
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\9g234sdfdfgjf23
    c:\windows\system32\nfr.gpref

    .
    (((((((((((((((((((((((((   Files Created from 2009-02-19 to 2009-03-19  )))))))))))))))))))))))))))))))
    .

    2009-03-18 19:09 . 2009-03-18 19:09   410,984   --a------   c:\windows\system32\deploytk.dll
    2009-03-18 18:42 . 2009-03-18 18:42      d--------   c:\documents and settings\Becky\Application Data\Malwarebytes
    2009-03-18 18:42 . 2009-02-11 10:19   15,504   --a------   c:\windows\system32\drivers\mbam.sys
    2009-03-18 18:41 . 2009-03-18 18:42      d--------   c:\program files\Malwarebytes' Anti-Malware
    2009-03-18 18:41 . 2009-03-18 18:41      d--------   c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-18 18:41 . 2009-02-11 10:19   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\SUPERAntiSpyware
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\program files\Common Files\Wise Installation Wizard
    2009-03-18 15:11 . 2009-03-18 15:11      d--------   c:\documents and settings\Becky\Application Data\SUPERAntiSpyware.com
    2009-03-18 15:04 . 2009-03-18 15:04      d--------   c:\program files\CCleaner
    2009-03-17 15:50 . 2008-04-13 20:12   116,224   --a--c---   c:\windows\system32\dllcache\xrxwiadr.dll
    2009-03-17 15:50 . 2001-08-17 22:37   99,865   --a--c---   c:\windows\system32\dllcache\xlog.exe
    2009-03-17 15:50 . 2001-08-17 22:37   27,648   --a--c---   c:\windows\system32\dllcache\xrxftplt.exe
    2009-03-17 15:50 . 2001-08-17 22:36   23,040   --a--c---   c:\windows\system32\dllcache\xrxwbtmp.dll
    2009-03-17 15:50 . 2004-08-03 22:29   19,455   --a--c---   c:\windows\system32\dllcache\wvchntxx.sys
    2009-03-17 15:50 . 2008-04-13 20:12   18,944   --a--c---   c:\windows\system32\dllcache\xrxscnui.dll
    2009-03-17 15:50 . 2001-08-17 12:11   16,970   --a--c---   c:\windows\system32\dllcache\xem336n5.sys
    2009-03-17 15:50 . 2004-08-03 22:29   12,063   --a--c---   c:\windows\system32\dllcache\wsiintxx.sys
    2009-03-17 15:50 . 2008-04-13 14:36   8,832   --a--c---   c:\windows\system32\dllcache\wmiacpi.sys
    2009-03-17 15:50 . 2008-04-13 20:12   8,192   --a--c---   c:\windows\system32\dllcache\wshirda.dll
    2009-03-17 15:50 . 2001-08-17 22:37   4,608   --a--c---   c:\windows\system32\dllcache\xrxflnch.exe
    2009-03-17 15:48 . 2001-08-17 22:36   525,568   --a--c---   c:\windows\system32\dllcache\tridxp.dll
    2009-03-17 15:47 . 2001-08-17 22:36   495,616   --a--c---   c:\windows\system32\dllcache\sblfx.dll
    2009-03-17 15:46 . 2001-08-17 13:28   899,146   --a--c---   c:\windows\system32\dllcache\r2mdkxga.sys
    2009-03-17 15:45 . 2001-08-17 12:50   198,144   --a--c---   c:\windows\system32\dllcache\nv3.sys
    2009-03-17 15:44 . 2001-08-17 13:28   802,683   --a--c---   c:\windows\system32\dllcache\ltsm.sys
    2009-03-17 15:43 . 2008-04-13 20:11   702,845   --a--c---   c:\windows\system32\dllcache\i81xdnt5.dll
    2009-03-17 15:42 . 2001-08-17 14:56   1,733,120   --a--c---   c:\windows\system32\dllcache\g400d.dll
    2009-03-17 15:41 . 2001-08-17 12:14   952,007   --a--c---   c:\windows\system32\dllcache\diwan.sys
    2009-03-17 15:40 . 2001-08-17 12:13   980,034   --a--c---   c:\windows\system32\dllcache\cicap.sys
    2009-03-17 15:33 . 2001-08-17 13:28   871,388   --a--c---   c:\windows\system32\dllcache\bcmdm.sys
    2009-03-17 15:32 . 2001-08-17 14:55   382,592   --a--c---   c:\windows\system32\dllcache\atidrab.dll
    2009-03-17 15:31 . 2001-08-17 12:19   747,392   --a--c---   c:\windows\system32\dllcache\adm8830.sys
    2009-03-17 15:30 . 2001-08-17 13:28   762,780   --a--c---   c:\windows\system32\dllcache\3cwmcru.sys
    2009-03-17 15:30 . 2001-08-17 14:55   689,216   --a--c---   c:\windows\system32\dllcache\3dfxvs.dll
    2009-03-17 15:30 . 2001-08-17 14:56   66,048   --a--c---   c:\windows\system32\dllcache\s3legacy.dll
    2009-03-17 15:30 . 2008-04-13 14:46   53,376   --a--c---   c:\windows\system32\dllcache\1394bus.sys
    2009-03-17 15:30 . 2001-08-17 14:06   11,264   --a--c---   c:\windows\system32\dllcache\1394vdbg.sys
    2009-03-11 21:16 . 2009-03-11 21:16      d--------   c:\documents and settings\David\Application Data\AVGTOOLBAR

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-19 18:03   ---------   d-----w   c:\documents and settings\user pc\Application Data\WTablet
    2009-03-18 23:12   ---------   d-----w   c:\program files\Java
    2009-03-18 19:00   ---------   d-----w   c:\program files\Lavasoft
    2009-03-18 19:00   ---------   d-----w   c:\documents and settings\All Users\Application Data\Lavasoft
    2009-03-17 16:21   ---------   d-----w   c:\documents and settings\All Users\Application Data\avg8
    2009-03-17 09:26   ---------   d-----w   c:\documents and settings\user pc\Application Data\uTorrent
    2009-03-15 21:35   138,624   ----a-w   c:\windows\system32\drivers\PnkBstrK.sys
    2009-03-15 04:15   ---------   d-----w   c:\documents and settings\user pc\Application Data\DVD Flick
    2009-03-15 01:38   ---------   d-----w   c:\documents and settings\user pc\Application Data\dvdcss
    2009-03-07 17:20   ---------   d-----w   c:\program files\Ahead
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\ZoomBrowser EX
    2009-02-26 18:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\CameraWindowDC
    2009-02-25 15:41   ---------   d-----w   c:\documents and settings\user pc\Application Data\AVGTOOLBAR
    2009-02-12 16:12   ---------   d-----w   c:\program files\Google
    2009-02-11 02:24   34   ----a-w   c:\documents and settings\user pc\jagex_runescape_preferences.dat
    2009-02-10 04:35   ---------   d-----w   c:\documents and settings\Leanne\Application Data\AVGTOOLBAR
    2009-02-10 04:19   ---------   d-----w   c:\documents and settings\Leanne\Application Data\vlc
    2009-02-09 03:08   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Apple Computer
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\WTablet
    2009-02-09 02:56   ---------   d-----w   c:\documents and settings\Leanne\Application Data\Network Associates
    2009-02-09 02:42   ---------   d-----w   c:\documents and settings\Becky\Application Data\AVGTOOLBAR
    2009-02-09 02:38   ---------   d-----w   c:\documents and settings\Becky\Application Data\vlc
    2009-02-05 18:37   ---------   d-----w   c:\documents and settings\user pc\Application Data\vlc
    2009-02-05 18:16   ---------   d-----w   c:\program files\VideoLAN
    2009-02-03 19:16   ---------   d-----w   c:\program files\Improvisation
    2009-01-27 15:56   325,128   ----a-w   c:\windows\system32\drivers\avgldx86.sys
    2009-01-27 15:55   107,272   ----a-w   c:\windows\system32\drivers\avgtdix.sys
    2009-01-25 05:54   ---------   d-----w   c:\documents and settings\user pc\Application Data\Any Video Converter
    2009-01-24 22:06   ---------   d-----w   c:\program files\AVG
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2009-01-24 21:59   0   ---ha-w   c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
    2009-01-24 20:56   ---------   d-----w   c:\documents and settings\All Users\Application Data\nView_Profiles
    2008-09-27 02:22   24   ----a-w   c:\documents and settings\David\jagex_runescape_preferences.dat
    .

    (((((((((((((((((((((((((((((   SnapShot_2009-03-19_11.44.11.57   )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-03-19 18:13:52   16,384   ----atw   c:\windows\temp\Perflib_Perfdata_780.dat
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-31 180269]
    "McAfeeFireTray"="c:\progra~1\NETWOR~1\MCAFEE~1\Firetray.exe" [2005-04-12 655420]
    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
    "NvMediaCenter"="NvMCTray.dll" [2008-05-03 c:\windows\system32\nvmctray.dll]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-01-27 11:56 10520 c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
    backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Personal Coach.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Personal Coach.lnk
    backup=c:\windows\pss\Personal Coach.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTZDetec.exe]
    --a------ 2007-12-18 15:20 401408 c:\documents and settings\user pc\Desktop\David\Creative Media Lite\CTZDetec.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-03-28 23:37 413696 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-04-04 19:00 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    --a------ 2008-05-03 06:46 1630208 c:\windows\system32\nwiz.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-24 325128]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-24 107272]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-24 903960]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-24 298264]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

    2009-03-17 c:\windows\Tasks\Uniblue SpyEraser Nag.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []

    2007-09-04 c:\windows\Tasks\Uniblue SpyEraser.job
    - c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
    .
    .
    ------- Supplementary Scan -------
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Becky\Application Data\Mozilla\Firefox\Profiles\v0zlm1jn.default\
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-19 14:14:22
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32]
    DACL=(02 0000)
    ="c:\\Program Files\\MyWebSearch\\bar\\1.bin\\F3REPROX.DLL"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(648)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Creative\Shared Files\CTDevSrv.exe
    c:\progra~1\NETWOR~1\MCAFEE~1\FireSvc.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\PnkBstrA.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\PnkBstrB.exe
    c:\windows\system32\Tablet.exe
    c:\windows\wanmpsvc.exe
    c:\windows\system32\WTablet\TabUserW.exe
    c:\windows\system32\Tablet.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-19 14:17:05 - machine was rebooted
    ComboFix-quarantined-files.txt  2009-03-19 18:17:01
    ComboFix2.txt  2009-03-19 15:45:04
    ComboFix3.txt  2009-03-19 04:54:14

    Pre-Run: 32,374,824,960 bytes free
    Post-Run: 32,355,348,480 bytes free

    Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
    243   --- E O F ---   2009-03-13 22:12:01
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Go to:
      • Start
      • Run
      • type: CLEANMGR.EXE
      • Press Enter.
      When prompted select the
    C: drive and click OK.
    Check the boxes for:
    • Temporary Internet Files
    • Downloaded Program Files
    • Recycle Bin
    • Temporary Files
    .
    Click OK or Enter

    ----------

    How is the computer running now?
    Thanks so far for all of your help. The computer seems to be running fine. 

    I still get this error message on my user account (not the other ones) when I log on to it:  "Error Loading dll32  The specified module could not be found".  I am assuming dll32 is important.  I tried doing
    START>RUN> sfc /scannow  and then inserting my WinXP disc to repair the dll32 file.  Nada, didn't work.  Is there somewhere to get this file?

    Also, what was the problem(s) you saw with all of the logs I sent you?  It seems Notepad had something to do with it.

    And I'm still wondering why we re-named HijackThis to Sniper?

    Quote
    And I'm still wondering why we re-named HijackThis to Sniper?

    Some malware can "hide" from the hijackthis.exe. Renaming it ensures this won't happen.

    Quote
    Also, what was the problem(s) you saw with all of the logs I sent you?  It seems Notepad had something to do with it.

    I'm not sure what the deal was with the Notepad entries. It shouldn't be running from the locations it was found in so might have been exploited by the malware. The biggest problem was adware, MyWebSearch.

    Quote
    Error Loading dll32  The specified module could not be found

    Sounds like something wasn't completely removed, probably part of the MyWebSearch.

    Let's have a closer look at where the error is coming from.

    Please download from DDS by sUBs and save it to your Desktop.

    Vista users. Right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)
    • Double click on dds to run it.
    • When done, DDS.txt will open.
    • You will receive another prompt after a while. Click Yes at the prompt. It will take another few minutes to scan.
    • When done, Attach.txt will open.
    • Please copy and paste the contents of DDS.txt and Attach.txt in your next reply.
    490.

    Solve : need help with this?

    Answer»

    Hi Experts, may machine is still infected may malware. I cannot open installed applications in my machine like CCleaner, BitDefender, etc.

    I cannot open also my Registry Editor and Task Manager, it has been disabled by your administrator. (or has been disabled by malware  )

    I scan my machine using SAS and Malwarebytes, and performed HiJackThis. Attached are the logs. Please advice.

    [attachment deleted by admin]Before you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode.

    Download SDFix by AndyManchesta and save it to your desktop.

    When using this tool, you must use the Administrator's account or an account with Administrative rights


    * Now, double-click on the SDFix icon that should now be residing on your desktop. If a Open File - Security Warning box opens, click on the Run button.
    * A window will now open showing SDFix being extracted into the C:\SDFix folder.     
    * Once the installation program has finished extracting SDFix, it will open a Notepad with further instructions.
    * DO NOT use it just yet.

    Reboot your COMPUTER in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    When your computer has started in safe mode, and you see the desktop, close all open Windows.

    * Click on the Start button, click on the Run menu option, and type the following text from the Code Box into the Open: field then click the OK  button.

    Code: [Select]C:\SDFix\RunThis.bat
    * SDFix window will open containing some brief info and a disclaimer on the use of the tool.
    * Type Y on your keyboard and then press Enter to begin the cleanup process.
    * It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    * Press any Key and it will restart the PC.
    * When the PC restarts, the Fixtool will run again and complete the removal process then DISPLAY Finished, press any key to END the script and load your desktop icons.
    * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    * Copy and paste the contents of the results file Report.txt in your next reply.
    Hi Sir, thanks for the reply. Sorry but the our admin decided to reformat my machine and restore the OS backup.Thanks for letting me know.

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like FIREFOX.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

    491.

    Solve : 2 strange reports found in my pc?

    Answer»

    i found these 2 reports in my pc , and have no IDEA were they came from, one says

    bug and the other MGS , harry

    [attachment deleted by admin]Bug.txt is a ComboFix log. It can be deleted.

    MSG.TXT looks to be a diagnostics report for some hardware, not SURE. It can likely be deleted.thank you as USUAL for your help  , unrelated question , you are a specialist so how can

    you be a BEGINNER , harryThe more you learn the less you know...

    492.

    Solve : Need Some Help !?

    Answer»

    I don't actually know if this would be the right place to post this but I have a question in regards to the SUPERAntiSpyware that I downloaded and installed on both mine and my mom's computer. I RAN the scan on her computer and it worked fine, then I ran a scan on my laptop and it scans for about 20mins until it gets to SOMETHING I see called Blackbox.bin then my whole computer FREEZES. This has HAPPENED three TIMES. I tried to go into my folders to see what this BlackBox file is, but it's under All Users\Application Data and it won't let me into that....

    Anyone know whats going on?I've never seen anything like that before. Might be a good question for the SUPERAntiSpyware Forums

    493.

    Solve : spyware/virus problem. can't access C: drive, can't open certain programs?

    Answer»

    Just yesterday when I turned my computer on I noticed it was acting funny.  The taskbar and window frames changed back to the old grey and blue theme, and the computer kept freezing sometimes when I wanted to open a folder or program.  Sometimes my internet browser said it couldn't find a internet connection when I know there was indeed a working connection because I was still online with Windows Live Messenger, even then I sometimes can't connect with Messenger.  Also when I try to google something now, I'll click on the link and it will re-direct to another site which has nothing to do with what I was looking for.  So I'm guessing it's a bad case of spyware.  I also cannot access my C: drive from My Computer.  Whenever I try I GET a warning message that says:

    "Windows cannot find 'RECYCLER\S-5-6-41-100003439-100006549-100030719-1810.com'.  Make sure you typed the name correctly, and then try again.  To search for a file, click the Start button, and then click Search."

    and the name of the Window frame on the top of the message says: RECYCLER\S-5-6-41-100003439-100006549-100030719-1810.com

    Also, when Windows Xp starts up and loads, I get another warning message with the title "svchost.exe" saying something like: "Instruction at "0x7564d27e" referenced memory at "0x00000060".  The memory could not be read.  Click OK to terminate program."  When I click on OK, the same thing comes up but 0x7564d27e changes slightly with the last letter.  It goes away after popping up 2-3 times.

    I followed the steps to post a log here and I was able to download and install all programs needed (SuperAntispyware, Malwarebytes' Anti-Malware, and HijackThis), but I cannot get SuperAntispyware and Malwarebytes' Anti-Malware to open up for some reason.  It's the same thing for when I try to open up Ad-Aware or Spybot-Search and Destroy which I already have installed.  I was able to use CCleaner and cleaned up everything needed, and I have a log from HiJackThis.  Here it is and hopefully I was clear enough as to what's wrong.

    Logfile of TREND Micro HijackThis v2.0.2
    Scan saved at 2:43:07 PM, on 3/17/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe
    C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\DNA\btdna.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [GLDStart] C:\Program Files\GLDirect\gldirect.exe -filterstart
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    O4 - HKLM\..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
    O4 - S-1-5-18 Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
    O4 - .DEFAULT Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
    O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} - http://inst.c-wss.com/117p/html/gtdownlr.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127550568500
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127620937437
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by102fd.bay102.hotmail.msn.com/activex/HMAtchmt.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FD09C446-B534-4DD2-82D7-37ABB3791FBC}: NameServer = 85.255.112.72,85.255.112.151
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.72,85.255.112.151
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.125,85.255.112.159
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.72,85.255.112.151
    O18 - Protocol: bw+0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {27AF91C8-8305-483A-9BC4-05455388A288} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c98bfdc2345f6e) (gupdate1c98bfdc2345f6e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe

    --
    End of file - 25734 bytes



    Thank you and regards,
    Allanyou forgot your MBAM log.  It makes it a lot easier to look over your hjt log with the MBAM logAs I said before I can't get Malwarebytes' Anti-Malware to open up for some reason.  Therefore I can't get a log for it.  Is it necessary to have it?Go to Add or Remove Programs and uninstall Logitech Desktop Messenger. This is a useless program and is not needed.

    ----------

    Three antivirus.


    The real-time protection of two antivirus programs may conflict with each other and cause the following:

    1) False Alarms: When the anti virus software TELLS you that your PC has a virus when it actually doesn't.
    2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
    3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

    Please uninstall all but one antivirus before we continue.

    Antivir
    BitDefender
    Norton/Symantec

    ----------

    You may want to print the below instructions that are in blue text, or copy them to a Notepad file and save it to your desktop. You might loose your Internet connection temporarily and you will need to have them available to get it back.

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O17 - HKLM\System\CCS\Services\Tcpip\..\{FD09C446-B534-4DD2-82D7-37ABB3791FBC}: NameServer = 85.255.112.72,85.255.112.151
    • O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.72,85.255.112.151
    • O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.125,85.255.112.159
    • O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.72,85.255.112.151
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    <<>>

    Go to Start > Control Panel - If you are using Windows XP's Category View, select the Network and Internet Connections category. If you are in Classic View, go to the next step.

    * Double-click the Network Connections icon.
    * Right-click the Local Area Connection icon and select Properties.
    * Highlight Internet Protocol (TCP/IP) and click the Properties button.
    * Be sure Obtain DNS server address automatically is selected.
    * OK your way out.

    Go to Start > Run and type in cmd
    Click OK

    * This will open a command prompt.
    * Type the following line in the command window:
     
     ipconfig /flushdns (note the space between ipconfig and /)

    * Press Enter on the keyboard.
    * Exit the command window

    Now restart your computer.

    <<>>

    ----------

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
    * Search for any of the following:

    - Seneka.sys <- Or anything beginning with Seneka
    - clbdriver.sys <- Or anything beginning with clbdriver
    - TDSSserv.sys <- Or anything beginning with TDSS

    * Let me know if you find them or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall them.


    * Now reboot and see if you can run the scans that would not run.
    494.

    Solve : Serious AVG Anti-Virus Problem?

    Answer»

    I have been putting it off, but for over a month my AVG anti-virus has not worked.
    It is supposed to go on every time I turn on the computer.
    However, when I do it keeps flashing up a warning that I am unprotected.
    I go to windows, it says no anti-virus is on, I try to switch it on, and too no avail.
    I get this message
    Quote

    AVG INTERFACE has encountered a problem and needs to close.  We apologize for the inconvenience.

    I have AVG 8.0.
    I tried to uninstall it...hoping to reinstall.
    When I did....I got the following message

    Quote
    Installer initialization failed due to the following error:
        Warning: Internal error. Dialog with id "WinFwDeactivationDlg" was not found in the setup.
    I am not allowed to uninstall.

    My question
    1) Why is this occurring?
    2)  What can and should I do?

    THANKS!Use the AVG Remover Tool. http://www.avg.com/download-toolsOK....I did that....the AVG does not show up on my desktop or in my control panal.
    I have attached the avgremover.log.

    However when I turned on my computer I was prompted with a message stating "your computer may be at risk, avg is turned off".
       1)  Why is this message coming up?
                -AVG removed
               -Is there some virus keeping it?
        2)  If AVG is removed....why did this whole problem occur...is this just a bug anybody can get...no big issue?
        3)  Should I re-download AVG?


    As of now I have NO virus protection, so if you can help sooner...thanks!



    [attachment deleted by admin]Just install an antivirus.

    Remember to only install one antivirus!
     
    1) Avast! Home Free Edition
    2) AVG Free Edition
    3) Avira AntiVir Personal OK...well I tried the new AVG 8.5 and got this message

    Quote
    C:\Documents and Settings\Trent Berger\Desktop\avg_free_stf_en_85_278a1439.exe.part could not be saved, because the source file could not be read.

    Try again later, or contact the server administrator.
    So what's going on?
    Why do I keep getting these errors?
    What is the problem...is it AVG or my computer?
    Is AVG gone from computer or not?
    What do I need to do to flush it out and put on a new anti-virus?
    I thought AVG was fine...why has it been so difficult with numerous errors for over a month even after trying to uninstall and now put on a new one?

    It is very frustrating to have illogical errors pop up out of nowhere and remain here for months FOR NO apparent cause.
    Why is it I am my computer is randomly picked to have AVG, which is supposed to HELP, cause errors?

    Ugh....please just let me know
    1)  What is going on
    2) Why
    3) How to fix

    Sorry for the 'tude but I am frustrated.This is the exact REASON I stopped using AVG and went to Avast.

    You can try here but good luck. http://freeforum.avg.com/Alright...well I want install a new anti-virus...but first I need to know

    1)  Is AVG anti-virus gone from my computer?
    -I do not see it on my program list in the control panel
    -However when I start the computer a red shield alerts me that my computer might be at risk since AVG is not on

    -I used the link to removed AVG...and it really is inconclusive to me if it is removed.
    -I have attached the log below

    -Is AVG gone from my computer?
    -If not, how can I get it to be removed entirely?


    2)  I do not want AVG or Avast, last time I had Avast it slowed up my computer.
    -Are there any other good anti-virus programs you can recommend?

    Thanks!

    [attachment deleted by admin]Avira AntiVir Personal  is probably the best.

    Other free ones are these, but I would go with Avira.

    Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)

    PC Tools AntiVirus Free EditionBefore I install a new anti-virus, I want to make certain the AVG is completely gone.

    1)  Is there anyway for me to see if it has been removed from the computer?
    2)  If it still is present, how can I go remove it?Go to C:\ > Program Files > AVG and delete the AVG folder.

    Done...is it all gone now and safe to install a new anti-virus program?Yes you should be able to now.Thanks!
    495.

    Solve : general question?

    Answer»

    Do anti-virus programs find ALL viruses on your computer?  What I'm asking is, should I reinstall my OS every now and then to ensure that ALL viruses have been checked?

    I use a combination of Anit-malware programs.......AVG, Spybot, Malwarebytes, sometimes Kaspersky ON-line.  Is this enough to keep Malware in check or should I reinstall, on occasion, to insure NOTHING has been missed? What you're doing is fine.

    Just make sure you only have one antivirus program running at one time.

    Reinstalling the OS is not necessary, and IMO is a waste of time.

    If AVG doesn't find anything, you're most likely safe.thankyou


    I actually keep the tea timer in Spybot turned off, it's annoying.  The only real-time protection I have running is from AVG. I also keep Windows Defender turned off because in all the time I've USED it, it never once notifed me of ANYTHING, even if I tell it to "notify" me... plus, anytime I've EVER run a manual SCAN with it, never finds anything... I may be wrong, but as far as I can see Windows Defender is a waste of resources.
    thanks again

    Quote from: hot DOG on March 16, 2009, 02:06:47 AM

    Windows Defender is a waste of resources.
    Can't argue with you there. I would suggest if you are going to run an online scan to use one that will delete or repair what's found.

    BitDefender works very well.

    This scanner works with Internet Explorer only! - BitDefender Online Scanner
    496.

    Solve : Virus Notification?

    Answer»

    If a CUSTOMER has a COMPUTER virus, should it be your responsibility to NOTIFY them?If you want them to have faith in your service then yes.

    If you don't CARE for return business then no.

    497.

    Solve : Need help! Virus screwing with my computer!?

    Answer»

    I recently got a virus on my computer.  it says that they are both trojans one says detected as Vundo!grb and the other says is a generic rootkit.  Can anyone help me?  It says it is deleted but every TIME I restart my computer they are there again!  Thanks!Read this before requesting MALWARE removal help, evilfantasy

    go to top of this page as above and do everything it says , harryu can use mc afee antivirus to just get ride of these virus but if u want a good ANTI virus u can use Malwarebytes' Anti-Malware....    Quote from: helene on March 06, 2009, 05:52:39 AM

    u can use mc afee antivirus to just get ride of these virus but if u want a good anti virus u can use Malwarebytes' Anti-Malware....  

    Another useless post...... Another useless post......

    i agree , i did not think malware was an anti-virus , i could be wrong but i think not 

    andiek 1987 , do as my first post the experts will be looking for logs to check over , harryI think all anti virus (freebies) are a virus within themselves . if you love your machine pay per play in the mean time rent yourself a hijack this on this site and then attack with no mercy but follow all instructions carefully  as kierans guidance is worth its weight in gold !!I think all anti virus (freebies) are a virus within themselves


     i have had 5 freebies for 4 years with no trouble of any sort , i bought mcafee and norton and took them out nothing but trouble Quote from: ELVIROS on March 07, 2009, 02:59:39 AM
    I think all anti virus (freebies) are a virus within themselves.

    You have it backwards. Norton and mcafee do not offer little to no protection, they also root themselves deep into the system- and charge you for the privilege every month. Avira, and Avast! along with a few others, in contrast, provide better protection, don't root themselves deeply into the system (IE: you don't need a "removal tool" for most of them- Uninstall and they are gone), And most importantly- they do NOT charge you for the privilege.

    498.

    Solve : Computer very slow..*Please Help*?

    Answer»

    Ive done the :

    Scanned pc with anti-virus
    Defragged
    Updated drivers
    Updated Xp


    Im just noticing weird performance issues , games CONSTANTLY crashing extreme hang on START up of xp. 3-4 minute boot times.....

    Ive got a hijackthis log here , if it is clean please respond.

    Logfile of HijackThis v1.99.1
    Scan saved at 6:04:57 PM, on 3/8/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\tlntsvr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Java(tm) Plug-In SSV HELPER - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.22\RivaTuner.exe" /S
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1236529738281
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E7A33FCB-ADF1-4667-8610-3317C070F4D3}: NameServer = 212.139.132.9 212.139.132.8
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

    499.

    Solve : Frustrated Home Worker needs Help?

    Answer»

    when I first came to this forum I was having a problem with "scvhost.exe" Application Error.

    The application error window popped up saying:

    "The instruction at "0x75606eb5" referenced memory at "0x000000008". The memory could not be "read".

    Click on OK to terminate the program


    But it does not terminate the application, "svchost.exe - Application Error" Pop up
    keeps popping up.

    I typed the message into yahoo search window and found you guys.


    I read and followed all the instructions I found at evilfantasy's GUIDE to Getting Started.

    I went thru steps 1 - 5 and the above problem went away.

    However when I came to Step 6 - Hijack This -  I found out that I cannot OPEN

    Local Disk (C:) -  When I click on the Local Disk (C:)  icon I get this message:

    "Windows cannot find "RECYCLERS\S-7-1-10-1000016218-100016988.com'. Make sure you typed the name correctly, and then try again. To search for a file click the Start button and the click search."

    When I right click to open (C:) a pop up message comes up with a red x and says C:/ cannot be accessed


    Also when I try to open Internet Explorer  Windows installer keeps opening up and tries
    to install "HP Smart Web Printing"  which is by the way already installed.

    I cannot stop this action and unfortunately have to force my computer to boot down...



    My questions is do I really need to change Hiajckthis.exe name in order to run the software
    to get my report


    I ran housecall in hopes that they might find something still in my computer so that i could
    open Local Disk (C:)  and change the name on HiJackThis.exe.

    After an hour or so of housecall running my computer crashed. So I installed and ran HighJack this
    as is....

    I attached two logs for MalwareBytes as I ran it and the SuperAvtiVirsus Program twice.

    Both times MawareBytes found infections. Second time with SuperAntiVirus found nothing

    [attachment deleted by admin]Welcome to CH.

    Download ComboFix© by sUBs from one of the below links. Be sure top SAVE it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixPretty awesome!  I now have access to my Local Driive (C:)

    Still having the same problem with opening up IE: Windows Installer Starts and Keeps trying

    to install:  "HP Smart Web Printing" 

    But Now I cannot use firefox When I click on the firefox icon a window  pops up and says that
    firefox has created an error and needs to close. I tried rebooting again with no luck.

    I have no use of fire fox or IE.  Right now I am using Mozilla's "SeaMonkey"

    Attached are the logs from running: ComboFix

    [attachment deleted by admin]You may have to reinstall your printer software.


    Download the OTMoveIt3 by OldTimer

    Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

    * Save it to your Desktop.
    * Double-click OTMoveIt3.exe to run it.
    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

    Code: [Select]:Processes
    explorer.exe

    :reg

    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]

    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

    :files
    c:\windows\SET88.tmp
    c:\windows\SET86.tmp

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    * Click the red Moveit! button.
    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    Close OTMoveIt3

    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes.

    ----------

    Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

    • Open the folder and run Dial-a-fix.exe
    • 2 windows will open. Close the one in the background labeled Restrictive Policies
    • Check the box in section 1, Empty temp folders.
    • Check the box in section 2, Fix Windows Installer.
    • Check the box in section 3, Fix Windows Update.
    • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
    • Check all boxes in section 5, labeled Registration Center.
    • Click Go
    • OK any error messages if received, but write them down and post them here.
    • Restart the computer when done.
    .
    Does IE work now?

    First attachment: Moveit Resluts-   Report-Before computer needed to be rebooted - Moveit Results.txt

    Second attachment: After Reboot Report Log -  03062009_121958.log

    [attachment deleted by admin]How is Dial-a-Fix working?Dial-a-Fix is running now...

    It seems to be stuck in step  4...
    SSL/HTTPS/Cryptography...

    Bottom task says Stopping CRYPTSVC...

    It has been been there for about 10-15 minutes...


    If it doesn't move on from that then stop it and uncheck that box then run Dial a fix again.

    Once finished restart and see if IE is working. There are some solutions on this page http://support.microsoft.com/?kbid=822798 for manual fixes. LOOK under the RESOLUTION tab.Also do you have your XP CD?Yes I do have my XP Disk.

    You thinking running repair could possibly fix this issue?...

    ------------------------

    I stopped Dial-a-Fix then ran again.

    When I click on the Explorer Icon IE does not  open...

    Each time I click on the icon is creates another short cut for IE
    on my desktop...

    So far I have 4 short cuts for IE on my desktop...

    FireFox:   Mozilla Crash Reporter pops up:

    "We're Sorry

    Firefox had a problem and crashed. We'll try to restore your  tabs
    and windows when it restarts"

    And it won't restart - I keep getting the Mozilla Crash Report window...
    We might try a Repair but I'm not sure that will help with this.

    1. Download IEFix.zip and run it.
    2. Click the Apply button.
    3. You'll be prompted for the Operating System CD or the Service Pack Files location.
    4. Once finished Restart Windows.

    Does IE work now?

    If not...

    From here http://techtipdaily.com/2008/07/30/opening-internet-explorer-creates-desktop-shortcut/

       1. Go to the control panel (Start Menu->Control Panel) and go to Add/Remove programs.
       2. Check the “Show Updates” (”Show hotfixes” in some versions) check boxes to show all installed patches.
       3. Scroll down until you see “Security Update for Windows XP (KB943460)”
       4. Click the remove button, and follow the prompts.

    If you can't uninstall it that way then visit the link for more suggestions.I ran IEFix.zip   

    and IE still does not work...keeps creating shortcuts..

    Firefox doesn't work...Mozilla Crash Report

    Crazy Browser works and
    Sea Monkey Works

    I went to Add/Remove Programs...

    I did not find "hot fix" Windows XP (KB943460)

    In my computer...

     - I Checked Show Updates Box



    Evidently I been having problems and didn't know
    it. Have not been getting updates I guess..OK lets make sure the malware is completely gone before moving on to repairs. No need in fighting a repair if it is actually malware interfering.

    First some clean up.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    ----------

    Download ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    Download OTCleanIt.exe and save it to your Desktop.
    • Double-click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it yourself.
    .
    Important: Restart the computer before continuing.

    ----------

    Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
    • Double-click on drweb-cureit.exe and then click Start
    • An information notice will appear, click OK.
    • This starts a short scan that will scan the files currently running in memory.
    • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
    • If or when something is found, click the Yes button when it asks you if you want to cure it.
    • Once the short scan has finished, Click Settings > Change Settings
    • Under the Scanning tab UNcheck Heuristic analysis and click OK
    • Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
      • Click Yes to all if it asks if you want to cure/move any file(s).
    • When the scan is done.
    • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
    • Save the DrWeb.csv report to your Desktop.
    • Exit Dr.Web Cureit.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    [/COLOR]
    • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
    • Copy and paste that log in the next reply
    Wow that took some time to complete Here is the log - Dr.Web

    So far nothing has changed with Firefox or IE...

    ========================================================

    cleaner42.exe\data001;C:\Documents and Settings\Administrator\Desktop\cleaner42.exe;Program.XPCSpy.23;;
    cleaner42.exe;C:\Documents and Settings\Administrator\Desktop;Archive contains infected objects;Moved.;
    cleaner42.exe\data001;C:\Documents and Settings\Administrator\My Documents\Cleaner\New Folder1\cleaner42.exe;Program.XPCSpy.23;;
    cleaner42.exe;C:\Documents and Settings\Administrator\My Documents\Cleaner\New Folder1;Archive contains infected objects;Moved.;
    New Leads.txt;C:\Documents and Settings\Administrator\My Documents\Desktop Junk\Daily Leads\Rec Leads;Modification of CeyDem.6574;Moved.;
    New Leads2.txt;C:\Documents and Settings\Administrator\My Documents\Leads\Daily Leadsb\Daily Leads 2;Modification of CeyDem.6574;Moved.;
    New Leads.txt;C:\Documents and Settings\Administrator\My Documents\Leads\Daily Leadsb\Rec Leads;Modification of CeyDem.6574;Moved.;
    cleaner42.exe\data001;C:\Documents and Settings\Administrator\My Documents\Software\Software\cleaner42.exe;Program.XPCSpy.23;;
    cleaner42.exe;C:\Documents and Settings\Administrator\My Documents\Software\Software;Archive contains infected objects;Moved.;
    cleaner.exe;C:\Program Files\The Cleaner;Program.XPCSpy.23;;
    A0000022.exe\data001;C:\System Volume Information\_restore{22FBF451-E3C7-49DB-9BAC-31A48CDCC2AC}\RP1\A0000022.exe;Program.XPCSpy.23;;
    A0000022.exe;C:\System Volume Information\_restore{22FBF451-E3C7-49DB-9BAC-31A48CDCC2AC}\RP1;Archive contains infected objects;Moved.;
    500.

    Solve : dictionary attack??

    Answer»

    in peergardian 2 in the BLOCKED it SAID dictionary attacker
    should I be worried?http://en.wikipedia.org/wiki/Dictionary_attackSo its like brute forcers and stuff? Is that bad that it was on the blocked of pg2? Is someone trying to steal my passwordS?I'm not SURE. Sometimes SOFTWARE identifies SOMETHING as one thing but it really isn't true. I'm sure it's blocking something but what it's blocking is the question.ohh how do you find out?Honestly I'm not sure. I did find this from the PG Forums. http://forums.phoenixlabs.org/showthread.php?p=119924