Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1301.

Solve : Not sure what is wrong, might be a virus, I'm not sure.?

Answer»

OK, my issue is that I can't sign into AIM, MSN messenger or Yahoo Messenger, and I also cannot use any browser except for Firefox. I'm running Windows XP and this only happened recently.
Thanks for any help! Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the APPLICATION.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as INSTRUCTED below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When DISINFECTION is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.
It might just be a problem with their server, or maybe your messenger has become corrupted. Either way, I would suggest that you try out Pidgin instead. It is able to connect to almost all the messengers (AIM, MSN, Yahoo, Google...), and is completely free.Please WAIT for the OP to reply with the log, before assuming anything.
1302.

Solve : Bearshare?

Answer»

I foolishly downloaded "Bearshare" and it seemed to want to take over my computer.
I uninstalled parts of it, but its ICON and program REMAINS.  It will not uninstall. I am a BEGINNER and not that savvy. But I can follow directions. Help.download "LINK REMOVED."

1303.

Solve : Windows Police Pro on Friends PC?

Answer»

Quote from: evilfantasy on August 31, 2009, 10:34:55 PM

Download UnHackMe and save it to the desktop.

* Open the compressed folder on your desktop named unhackme.zip
* Double click unhackme250.exe to begin the installation.  When asked if you WISH to continue, click Yes.
* Select all the default installation options by clicking Next for every step in the installation.  When prompted, choose Yes to create a directory.
* Select the Check tab at the top of the window and then click on the Check for Trojans, Spyware, Adware button. 
* A dialog box should pop up stating "We strongly recommend you to make the virus scan at the next reboot of your computer. This is required for detecting the hidden rootkits."
* Please allow the restart of the computer.

* When scan is complete it should show what was has found.
* Look at each key and DON'T delete anything you are unsure of. Come back here and ask if you NEED help deciding.
* Click on the key that you want to remove.
* After selecting the key, click on the Delete Key or the Get it out! button. 
* A window will appear asking you to verify the deletion. Click Yes to delete the infected key.
* Repeat this for all of the infected keys in the list.
* When you're finished deleting all the keys in the list close UnHackMe.

Let me KNOW how that goes.

kk we will give it a try but like i said it malware bytes and hijack this just close out after a few seconds most .exes don't even run.Try it in Safe Mode also.

Try RUNNING HJT in Safe Mode also. I need logs... Quote from: evilfantasy on September 01, 2009, 10:50:39 AM
Try it in Safe Mode also.

Try running HJT in Safe Mode also. I need logs...
Hello Evil Fantasy WE run Unhackme Found alot of nasties I made sure to research them on google we deleted them are only problem now is that We still get riderects to odd sites..

We still can't run HJT or Mbam any idea?Download RegRun Reanimator

* Open an executable file to start program installation.
Follow the installer instructions.
* At the end of installing software on your computer you will be prompted to run Scan for Viruses
* Click on the Fix Problems button.
* Restart your computer for the changes to take effect.

----------

Now try Malwarebytes.yup this is the nasty virus i have as well, i can't even run unhack me in safemode. I get the debugger 97 error and then it comes back with the error "windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the file"

yet i'm running everything as admin

that's the issue i get with malware bytes as well, but i cant download the renamer without getting that debugger97 error.

Anyone know how to bypass any of these?slixie , you cannot hijack another topic please start your own topicalright i tried that 2 days later it came backYou need to keep going with my instructions until given the all clear.
1304.

Solve : Combat Arms Virus??

Answer»

My AntiVira Antivirus SOFTWARE detects this:

Virus or unwanted program 'TR/Crypt.TPM.Gen [trojan]'
detected in FILE 'H:\Combat Arms\Game\CShell.dll.
Action performed: Deny access Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has LOADED, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a LOCATION you will remember.
  • The log is automatically SAVED by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.
1305.

Solve : superantispyware step?

Answer»

Hello ALLAN,

I had run CCLEANER successfully and was into running SUPER antispyware at 4:23 minutes when it stopped on:

C:\WINDOWS\SYSTEM32\MSXML3.DLL

The TIMER is not MOVING past 4:23

Shall I wait for SUPERantispyware to resume?

(I am able to move my cursor).

Thank you, Roley1) ccleaner is useless
2) Yes, wait for a while

1306.

Solve : Requesting help fixing trojan infection?

Answer»

Let us know how it goes. If needed we can try a few other things.Im having trouble getting the computer to let me choose to boot from the USB. Im still trying to find the option, but no luck so far. After i START the computer and press F8 to get to the options screen before it boots, i cannot find an option for USB or removible harddisk boot.Try using the F12 key.does nothing. F8 is the key on that computer. i can also load a ROM settings screen with F10. but no where in the menu can i boot from anything other then the hard drive. im just going to put the ISO and the unetbootin file on a gig stick and put it all on there and install it from that computer and reboot thereeven after installing directly onto the hard drive of the computer there is never an option to boot any DIFFERENTLY in any of the starting menus. Thanks for the help, but my patience with the computer is GONE now. Gonna just wipe the hard drive and start FRESH.

1307.

Solve : Computer keeps restarting before it even loads up?

Answer»

Is this a NetBook?

Do you have USB PORTS?

Have you tried starting in Safe Mode?I communicating with you through a laptop, but the computer with the problem is a desktop
I do have usb ports on my laptop notebook
I can't get the desktop to start in safe mode or anythingTry this. http://evilfantasy.wordpress.com/bitdefender-rescue-usb/

Or for a Rescue CD. http://evilfantasy.wordpress.com/2009/05/06/rescue-cds/I've tried the rescue cd and the computer is still restarting. If it MATTERS, I've also ran an error scan of the hard drive and there were no problems. Hopefully there is something else that you could walk me through to resolve my issue.

Thank youMy issue has been resolve with the help of someone else!Sorry I missed your previous reply.

What was it that fixed the computer?Hi guys I'm in no way a Malware Removal Specialist but this is not Malware this is a WINDOWS update error if you call their tech support number there is a message that says if you are getting this error to press 1 or something. they are saying the update error only happens to xp and vista users but I have already fix 4 windows 7 computers with this same message, easy fix on win 7 computers. only way I have got this prob fixed on xp or vista is to do a repair install over top of the windows software.  hope this helps but call the number for MS support you should hear the message the number is 1-800-936-5700. but like i said this is not Malware. don't mean to step on ANYONE toes just THOUGHT I should share this info Quote from: nikis360 on February 15, 2010, 02:43:39 PM

My issue has been resolve with the help of someone else!



heyy how did you fix this?? im gettin the same problem!!!! do i have to wipe out my comp?!?!
1308.

Solve : McAfee Detected Suspect File?

Answer»

I have an HP computer w/XP. Ran MCAFEE last night and it found the following "POTENTIALLY Unwanted File" :  C:\hp\bin\KillWind.exe

It calls this RemAdm-PSkill.

What does this file do? How Does McAfee know it is "potentially unwanted"?

Should I delete it?

Thanks.It's fine, you can consider the file safe.

1309.

Solve : McAfee Slowing Things Down!?

Answer»

Installed MCAFEE 90 day free TRIAL last night. Computer is noticeably slower now. I have HP with XP and FiOS 25/15 internet connection. Is this slowdown typical or should I look for a problem?As a rule I don't badmouth software vendors, but McAfee produces pretty poor products. I don't know which particular McAfee app you've installed, but I strongly suggest uninstalling it and trying a competitor's product (ANY competitor's product).Thanks,  the deed is done. What anti-virus do you recommend?There are so many good products out there. I'm a fan of Kaspersky for a number of reasons (for example, they update their definitions HOURLY as opposed to daily or weekly as most other vendors do, their online forum support is OUTSTANDING - as is their PHONE support, and their products are consistently ranked at or near the top of pretty much every reliable comparative evaluation I've seen). Other very good products (paid and free) include NOD, Avira, Avast, etc. Lot's of threads on other forums you might want to check out - not sure if I'm allowed to POST links here though.

1310.

Solve : The Virus Alert Virus?

Answer»

Okay now lets take away the unnecessary startups the right way. Msconfig is for troubleshooting and is not a real startup manager.

StartupLite

* Download StartupLite by Malwarebytes to your desktop.
* Double click StartupLite to launch the program.
* Ensure the Disable box is checked.
* Click Continue.
* A pop up message will tell you the unnecessary startup items in your list have been disabled and ask you to restart your computer.
* Restart your computer.

----------

Next. Run a new HijackThis scan and post the log please.I'm having a new problem. I can't open msconfig or any other application for that matter. I am asked which program I would like to use to open the file with, the .exe files! When I try to open firefox, it asks me what I should open firefox with! I can't run anything now except the internet, and apparently, I'm lucky to be able to do that. I'm so frustrated with this.Even with the startup lite...i can download the setup file, but when i try to run it, it asks me what program to open it with. Yesterday, I got an error REGARDING rundll32.exe.Hi ,

 I guess that is time to format and reinstall your operating system.

RegardsTry not to restart the computer until one of the tools we use does it  for you or tells you to.

If one of the tools will not run just go on to the next one. Save the logs to post in your next reply.

1) Please download and run the below  tool named Rkill (courtesy of BleepingComputer.com) which  may help allow other programs to run.
 
There are 4 different  versions. If one of them won't run then download and try to run the next  one.
 
Vista and Windows 7 users need to right click Rkill and choose Run as Administrator

You only need to GET one of these to run, not all of them. You may get warnings from your  antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

*  Double-click on the Rkill desktop icon to run the tool.
If using Vista or Windows 7 right-click on it and  choose Run As Administrator.
* A  black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* When finished it will create a log.
* Please post the rkill.log in the next reply.

*  If Rkill does not run from the first link, delete the file, then  download and use the one provided in Link 2. If it does not work, repeat the process and attempt to use one of the remaining links until  the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.


Once you've gotten one of them to run then try to immediately run the following.


2) Download and run exeHelper

*  Please download  exeHelper from Raktor to your desktop.
* Double-click on  exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
*  Add the log.txt file to your next message.

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs  together (they will both be in the one file).


3) If you already have Malwarebytes be sure to update it before running the scan!

Download Malwarebytes' Anti-Malware (MBAM)

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to the following:

* Update Malwarebytes' Anti-Malware
* Launch Malwarebytes' Anti-Malware

* Then click Finish
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is COMPLETE, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy and Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.All of a sudden, without doing anything, these apps now will open. I took your recommendation and ran startuplite as instructed, then ran hijackthis. Here is the new log. Should I still run RKill? Thanks a million, EF.

[Saving space, attachment deleted by admin]You have picked up a new infection.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
  • O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixLooks like the rest of the family doesn't get time on mama's computer anymore. Here is the log and a screenshot of an error box regarding rundll when combofix was WRAPPING up.

[Saving space, attachment deleted by admin]Does that error appear when you restart the computer?

How is the computer running now?Well, all was going fine until I was browsing my brother's picture section on myspace. The first time it POPPED up, I was on myspace. I assumed it was from someone else browsing other things on my computer, but looks like myspace may be the culprit. This time it was Antivirus 7. Do you know of any connections between this Antivirus bug and myspace?Sorry for the delay.

Are you able to run ComboFix in Safe Mode?It is definitely linked to myspace. Every time I go to someone's picture section (this time my own pics) I get a new antivirus soft virus. I'm really just posting back here to let you know that it HAS to be related to myspace, somehow. Go back to this post and try it again please. Here are the new logs. Thanks for getting me back on the wagon, I was close to giving up.

[recovering disk space - old attachment deleted by admin]If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix
1311.

Solve : quick help w/ hjt logs?

Answer»

Hey guys,

I've been keeping up w/ my comp's health ever since I've been a member of CH, and the advice has kept me running smooth. However I did a recent check of my active processes and thought the number of svchost's were more than I'm used to. I've attached my hjt logs. Can anyone tell if these are required to RUN or how I can tell if one is not supposed to be there?

Thanks,
HB

[attachment deleted by admin]Looks fine.i have more svchost s running then that
just ignore it Quote from: smeezekitty on August 24, 2009, 03:15:50 PM

i have more svchost s running then that
just ignore it

Are you a Malware specialist all of a sudden? I'm sure the SPECIALISTS are greatful for your input.i never said i was but the svchost number really doesnt
matter
unless you notice other signs of a malware infectionyou should not GIVE advice unless you can stand over it , LEAVE it to the expertsthanks for the help!looking for other replies out here, I'm also wondering what to do about it.. Quote from: printerface on September 08, 2009, 04:52:45 AM
looking for other replies out here, I'm also wondering what to do about it..

you will have to start your own topic

dont mees with registry and dont take anything out of the hjt log on your own let an expert tell you what to do
1312.

Solve : VIRUS DNA CHANGER?

Answer» HELOO,

CAN ANYONE HELP ME?
Everytime i delete/turn off my virus dna CHANGER my internet stops any idea how?No NEED to post the same question more than once.
1313.

Solve : Application Cannot Be Executed. The File *** is infected - Under Attack?

Answer»

Good EVENING,

I can't imagine I'm having an issue that hasn't been dealt with a million times before but I can say I'm just as frustrated either way >.< The problems all seemed to start when I downloaded an update for Java and now I have some sort of fake anti virus software popping up and causing all sorts of issues. I was able to find this place through Google and was able to stop the onslaught of execution errors by hijacking this step from another thread:

You only need to get ONE of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.exe
Rkill.com
Rkill.scr
Rkill.pif

Once you've gotten one of them to run then try to immediately run the following.
 
Now download and Run exeHelper.

Please download exeHelper from Raktor to your DESKTOP.

    * Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to close once the fix is completed. A log file named log.txt will be created in the directory where you ran exeHelper.com Attach the log.txt file to your next MESSAGE.

      Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

I read that every situation is different and following all the steps that worked for that user might adversely effect my machine. I am willing to do any and everything and look forward to any assistance that can be given.What is your situation now? Are you able to boot into NORMAL Mode? Can you connect to the internet?

1314.

Solve : BAD virus. can't open hijack this, firefox or any other apps.?

Answer»

i meanly talk about this part
Quote

Very important, do the following immediately or as soon as possible!

If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or CHANGE all of your account numbers.
 
From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.
the rest of it is good advice
but still if you back up to a flash drive i am sure the virus can also jump drives
when trying to retreave off the flash drive
so wahts to keep it from infecting another computer?Read the reply. It's all explained.would it possibly be good news at all if none of my photos or music files came up as infected in the scan?

i am going to buy a new hard drive tomorrow to transfer these files to. in the meantime, what "action" should i take in the avast scan? should i delete the infected/un-repairable files? they are mostly EXE and tmp files. i know my photoshop, office, etc will be shot, but i would prefer that happen than my photos.

by the way, is there any way to salvage my outlook files? OLD emails, address BOOK, etc? Quote from: landa321 on August 26, 2009, 09:17:24 PM
would it possibly be good news at all if none of my photos or music files came up as infected in the scan?

Yes but I would scan them with another scanner to be sure.

Quote from: landa321 on August 26, 2009, 09:17:24 PM
i am going to buy a new hard drive tomorrow to transfer these files to. in the meantime, what "action" should i take in the avast scan? should i delete the infected/un-repairable files? they are mostly exe and tmp files. i know my photoshop, office, etc will be shot, but i would prefer that happen than my photos.

The files that Avast is going to quarantine will make the drive useless because it will remove critical system files needed for Windows to work.

Quote from: landa321 on August 26, 2009, 09:17:24 PM
by the way, is there any way to salvage my outlook files? old emails, address book, etc?

You can back them up and do the scans on them also. Although I would think that they are the most likely ONES to be infected. Quote from: evilfantasy on August 26, 2009, 09:26:55 PM

The files that Avast is going to quarantine will make the drive useless because it will remove critical system files needed for Windows to work.

should i go ahead and delete those files then? the drive already doesn't boot up anyway since i did the avira scan. i am more concerned with saving what i can before doing the reformat/fresh install.

Quote from: evilfantasy on August 26, 2009, 09:26:55 PM

You can back them up and do the scans on them also. Although I would think that they are the most likely ones to be infected.
is it possible to back them without starting outlook? can i go in and just copy the file? i am not 100% what folder those files are located in. would those be pst and pab files?I'm not sure where they are located and I believe they are .PST files.how about the files? let avast remove them or quarantine?
i know i am eventually going to reformat this drive, but i still feel better getting rid of those files. does it matter?When you reformat you will be getting rid of them,I am finally back up on my desktop. I was able to save all of my important files on to a brand new HD and I ran scans on that HD to make sure all the files were safe.

I ended up reformatting an older hard drive that was only 100GB and doing a fresh XP install on that. This way, I can reformat the infected 750GB HD and just use it as external storage. this way, if I get infected in the future, I will have all of my important files backed up. Lesson learned.

Thanks all around.sometimes spywares are blocking some of our downloads, so you can just close your spyware and download hijack, but if the problem still insist, how about reformatting your computer. Quote from: printerface on September 08, 2009, 04:41:37 AM
sometimes spywares are blocking some of our downloads, so you can just close your spyware and download hijack, but if the problem still insist, how about reformatting your computer.
That's exactly what he/she did.
1315.

Solve : Antivirus just labeled Hosts file as virus and removed it.?

Answer»

Sorry before hand if post should have been directed elsewhere.

AVG 9.0.814 free edition just ran a scan and marked my hosts file as a virus and removed it.

Question is there a way to CREATE a new hosts file or should i just restore it from the virus vault?
NEVER had this happen before.

Running Windows XP service pack 2 (i know i NEED to upgrade).

Thanks again for your help before hand.

Please go to this LINK and follow the directions and post the required logs. Please post your logs in this link.

1316.

Solve : can't get rid of virus/rootkit infection - need help...?

Answer»

hi,

I was in hurry last friday (apr 23) and accidentally clicked on an email link instead of deleting the email - not sure what short circuit happened in my brain at that moment.  My Acrobat opened and I immediately went to shut off my internet, but it was too late.  I can no longer access Windows Update and any google links that would potentially provide help would either not load or redirect to some sleazy ads.  I have tried numerous scans this past week to get rid of it, but I'm still back at pretty much square one.

Here is what I have tried:
- MBAM: initially found a few backdoor bots and what not and got rid of them.  Since then, it has found nothing even with latest updates.

- SAS: found a couple of things, but has found nothing since.

- Hitman pro 3.5: found nothing.

- Windows Defender: I manually updated it today (as the rootkit blocks auto update of it) and found nothing

- PestPatrol: found nothing

- Trendmicro online scanner: found nothing

- ESET online scanner: found nothing.

- MS onecare online scanner: keeps finding "severe threats" but can't remove them and doesn't give me any info about them.

- GMER: found suspicious modifications of "atapi.sys" and "acpiec.sys"

I strongly suspect that I have been hit with a new variant of the TDSS rootkit tdl3 (tdl4?) as indicated by my GMER log, but when I ran TDSSkiller from Kaspersky, it did not find any infections, yet, I still have all the SYMPTOMS of TDSS rootkit infection.

Here's my GMER and DDS reports.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-29 21:05:04
Windows 5.1.2600 Service Pack 2
Running: 1z0hdkjw(gmer).exe; Driver: C:\DOCUME~1\~\LOCALS~1\Temp\pwdoikob.sys


---- Kernel code sections - GMER 1.0.15 ----

.rsrc           C:\WINDOWS\system32\drivers\ACPIEC.sys                                     entry point in ".rsrc" section [0xBACC6194]

---- User code sections - GMER 1.0.15 ----

.text           C:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtProtectVirtualMemory     7C90D6EE 5 Bytes  JMP 0097000A
.text           C:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtWriteVirtualMemory       7C90DFAE 5 Bytes  JMP 0098000A
.text           C:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!KiUserExceptionDispatcher  7C90E47C 5 Bytes  JMP 0096000C
.text           C:\WINDOWS\System32\svchost.exe[1304] USER32.dll!GetCursorPos              7E41BD76 5 Bytes  JMP 028D000A
.text           C:\WINDOWS\System32\svchost.exe[1304] ole32.dll!CoCreateInstance           774FFAC3 5 Bytes  JMP 0280000A
.text           C:\WINDOWS\Explorer.EXE[3256] ntdll.dll!NtProtectVirtualMemory             7C90D6EE 5 Bytes  JMP 00B5000A
.text           C:\WINDOWS\Explorer.EXE[3256] ntdll.dll!NtWriteVirtualMemory               7C90DFAE 5 Bytes  JMP 00C3000A
.text           C:\WINDOWS\Explorer.EXE[3256] ntdll.dll!KiUserExceptionDispatcher          7C90E47C 5 Bytes  JMP 00B4000C

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                     SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                   SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                  SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                  SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)

Device           -> \Driver\atapi \Device\Harddisk0\DR0                                    8A60BAC8

---- Files - GMER 1.0.15 ----

File            C:\WINDOWS\system32\drivers\ACPIEC.sys                                     suspicious modification
File            C:\WINDOWS\system32\drivers\atapi.sys                                      suspicious modification

---- EOF - GMER 1.0.15 ----

*****************************************************************


DDS (Ver_10-03-17.01) - NTFSx86 
Run by ~ at 15:03:12.65 on Thu 04/29/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2038.1133 [GMT -4:00]

FW: Norton Internet Worm Protection *disabled*   {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Utilities\Security\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Utilities\Security\NAV2003\navapsvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Protector Suite QL\menusw.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Utilities\Security\PestPatrol\PPActiveDetection.exe
C:\Utilities\Canon\OmniPageSE2.0\OpwareSE2.exe
C:\Utilities\Security\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Utilities\Media Players\Quicktime v7.1.3\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Productivity\Adobe\Acrobat 6 Pro\Distillr\acrotray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Utilities\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\~\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.sony.com/vaiopeople
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
uWindows: run=""
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\utilities\security\nav2003\NavShExt.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\productivity\adobe\acrobat 6 pro\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\productivity\adobe\acrobat 6 pro\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe
mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [VAIO Update 2] "c:\program files\sony\vaio update 2\VAIOUpdt.exe" /Stationary
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [Biomenu] "c:\program files\protector suite ql\menusw.exe"
mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe"
mRun: [PartSeal] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [eTrust PestPatrol Active Protection] "c:\utilities\security\pestpatrol\PPActiveDetection.exe"
mRun: [Sony Ericsson PC Suite] "c:\utilities\sony ericsson\mobile2\application launcher\Application Launcher.exe" /startoptions
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [OpwareSE2] "c:\utilities\canon\omnipagese2.0\OpwareSE2.exe"
mRun: [Windows Defender] "c:\utilities\security\windows defender\MSASCui.exe" -hide
mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe
mRun: [ccRegVfy] c:\program files\common files\symantec shared\ccRegVfy.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [QuickTime Task] "c:\utilities\media players\quicktime v7.1.3\qttask.exe" -atboottime
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35.exe" /scan:boot
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\productivity\adobe\acrobat 6 pro\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
IE: E&xport to Microsoft Excel - c:\produc~1\office11\office12\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 Plus - c:\program files\sony\image converter 2\menu.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\produc~1\office11\office12\REFIEBAR.DLL
DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=67633
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345}
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162477309765
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1272005459953
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://feiportal.feico.com/InternalSite/WhlCompMgr.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\utilities\security\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: psfus - fusstub.dll
Notify: VESWinlogon - VESWinlogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\utilit~1\security\window~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\utilities\security\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
LSA: Notification Packages = scecli fusstub
Hosts: 207.170.206.71   feiportal.feico.com
============= SERVICES / DRIVERS ===============

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2006-3-22 9216]
R1 SASDIFSV;SASDIFSV;c:\utilities\security\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\utilities\security\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2002-8-8 308936]
R2 FdRedir;FdRedir;c:\program files\common files\protector suite ql\drivers\FdRedir.sys [2006-2-22 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\common files\protector suite ql\drivers\filedisk.sys [2006-2-22 33024]
R2 navapsvc;Norton AntiVirus Auto Protect Service;c:\utilities\security\nav2003\NAVAPSVC.EXE [2002-8-19 116336]
R2 SAVRTPEL;SAVRTPEL;c:\windows\system32\drivers\SAVRTPEL.SYS [2002-7-25 35552]
R2 WinDefend;Windows Defender;c:\utilities\security\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-3-22 36352]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20091223.003\NAVENG.Sys [2009-12-23 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20091223.003\NavEx15.Sys [2009-12-23 1323568]
R3 SAVRT;SAVRT;c:\windows\system32\drivers\SAVRT.SYS [2002-7-25 235744]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-3-22 29184]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2006-3-22 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-3-22 226304]
S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2001-8-14 54408]
S3 ccPwdSvc;Symantec Password Validation Service;c:\program files\common files\symantec shared\ccPwdSvc.exe [2002-8-19 63176]
S3 DiMeiMC;MEI MC Stage;c:\windows\system32\drivers\DiMeiMC.sys [2008-6-12 7832]
S3 DMService;Whale Component Manager;c:\windows\downlo~1\DMService.exe [2008-11-25 423576]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\plcndis5.sys --> c:\windows\system32\PLCNDIS5.SYS [?]
S3 SASENUM;SASENUM;c:\utilities\security\superantispyware\SASENUM.SYS [2010-2-17 12872]
S3 SE2Fbus;Sony Ericsson Device 047 Driver driver (WDM);c:\windows\system32\drivers\SE2Fbus.sys [2006-11-4 61600]
S3 SE2Fmdfl;Sony Ericsson Device 047 USB WMC Modem Filter;c:\windows\system32\drivers\SE2Fmdfl.sys [2006-11-4 9360]
S3 SE2Fmdm;Sony Ericsson Device 047 USB WMC Modem Driver;c:\windows\system32\drivers\SE2Fmdm.sys [2006-11-4 97184]
S3 SE2Fmgmt;Sony Ericsson Device 047 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\SE2Fmgmt.sys [2006-11-4 88688]
S3 se2Fnd5;Sony Ericsson Device 047 USB Ethernet Emulation SEMC47 (NDIS);c:\windows\system32\drivers\se2Fnd5.sys [2006-11-4 18704]
S3 SE2Fobex;Sony Ericsson Device 047 USB WMC OBEX Interface;c:\windows\system32\drivers\SE2Fobex.sys [2006-11-4 86560]
S3 se2Funic;Sony Ericsson Device 047 USB Ethernet Emulation SEMC47 (WDM);c:\windows\system32\drivers\se2Funic.sys [2006-11-4 90800]
S4 LkWebLink;Inter-Tel Collaboration Remote Client;c:\documents and settings\~\my documents\inter-tel\collaboration client 2.0\lkWebLink.exe [2008-9-15 32768]

============== File Associations ===============

regfile=regedit.exe "%1" %*
scrfile="%1" %*

=============== Created Last 30 ================

2010-04-29 19:00:10   0   ----a-w-   c:\documents and settings\~\defogger_reenable
2010-04-26 18:49:08   0   d-----w-   c:\program files\ESET
2010-04-26 02:08:58   0   d-----w-   c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-04-26 02:08:50   0   d-----w-   c:\docume~1\~\applic~1\SUPERAntiSpyware.com
2010-04-26 02:08:03   0   d-----w-   c:\program files\common files\Wise Installation Wizard
2010-04-26 00:38:46   12872   ----a-w-   c:\windows\system32\bootdelete.exe
2010-04-26 00:11:21   15944   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
2010-04-26 00:10:30   0   d-----w-   c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-04-26 00:10:29   0   d-----w-   c:\program files\Hitman Pro 3.5
2010-04-23 19:41:09   45   ----a-w-   c:\windows\system32\_WKERNEL.FRE
2010-04-23 19:40:48   56496   ----a-w-   c:\windows\system32\wbhelp2.dll
2010-04-23 19:40:48   544768   ----a-w-   c:\windows\system32\wbocx.ocx
2010-04-23 19:40:47   4608   ----a-w-   c:\windows\system32\W95INF32.DLL
2010-04-23 19:40:47   439   ----a-w-   c:\windows\system32\shfolder.inf
2010-04-23 19:40:47   33968   ----a-w-   c:\windows\system32\anim.dll
2010-04-23 19:40:47   258352   ----a-w-   c:\windows\system32\unicows.dll
2010-04-23 19:40:47   2272   ----a-w-   c:\windows\system32\W95INF16.DLL
2010-04-13 06:07:41   0   d-----w-   C:\AMTtempImages
2010-04-13 06:06:55   168720   ----a-w-   c:\windows\system32\MSLTUS35.DLL
2010-04-13 06:06:51   0   d-----w-   C:\AMThistory
2010-04-13 06:06:51   0   d-----w-   C:\AmtCommon
2010-04-13 06:06:51   0   d-----w-   C:\Amt600

==================== Find3M  ====================

2010-03-30 07:46:30   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 07:45:52   20824   ----a-w-   c:\windows\system32\drivers\mbam.sys
2010-03-11 12:38:54   832512   ----a-w-   c:\windows\system32\wininet.dll
2010-03-11 12:38:52   78336   ----a-w-   c:\windows\system32\ieencode.dll
2010-03-11 12:38:51   17408   ------w-   c:\windows\system32\corpol.dll
2010-03-09 11:09:18   430080   ----a-w-   c:\windows\system32\vbscript.dll
2010-03-09 08:28:20   411368   ----a-w-   c:\windows\system32\deploytk.dll
2010-02-24 14:16:06   181632   ------w-   c:\windows\system32\MpSigStub.exe
2010-02-16 17:35:40   2143744   ----a-w-   c:\windows\system32\ntoskrnl.exe
2010-02-16 16:57:54   2021888   ----a-w-   c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:47:05   100864   ----a-w-   c:\windows\system32\6to4svc.dll
2008-12-27 06:43:08   32   --sha-w-   c:\windows\{27605EE2-0707-4CF3-BB1C-E808AD90E4BC}.dat
2008-12-27 06:43:08   32   --sha-w-   c:\windows\system32\{F5E374BF-C6B5-407C-A685-94751F290334}.dat

============= FINISH: 15:04:56.70 ===============

**************************************************************


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/2/2006 3:39:15 AM
System Uptime: 4/29/2010 11:55:35 AM (4 hours ago)

Motherboard: Sony Corporation |  | VAIO                           
Processor: Genuine Intel(R) CPU           T2400  1.83GHz | N/A | 1833/166mhz
Processor: Genuine Intel(R) CPU           T2400  1.83GHz | N/A | 1833/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 93 GiB total, 5.085 GiB free.
D: is Removable
E: is CDROM ()
F: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

2007 Microsoft Office system
ACT!
AddressGrabber Standard
AddressGrabber Standard 3.5
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat 6.0.1 Professional
Adobe Acrobat and Reader 6.0.3 Update
Adobe Acrobat and Reader 6.0.4 Update
Adobe Acrobat and Reader 6.0.5 Update
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
AMT Image Capture Engine
AnyDVD
Apple Mobile Device Support
Apple Software Update
Audiograbber 1.83 SE
Bluetooth Stack for Windows by Toshiba
Bonjour
CA eTrust PestPatrol
Canon MP Navigator 2.2
Canon MP530
Canon Utilities Easy-PhotoPrint
Click to DVD 2.0.03 Menu Data
Click to DVD 2.5.32
Collaboration Client 2.0
Compatibility Pack for the 2007 Office system
Content Transfer
DSD Direct
DSD Playback Plug-in 1.0
DSPDriver
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVgate Plus
Easy-WebPrint
Eraser
ESET Online Scanner v3
FileZilla Client 3.2.4.1
Fingerprint Tutorial
GOM Player
GoToMeeting 4.0.0.320
HDAUDIO SoftV92 Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hitman Pro 3.5
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB909667)
Hotfix for Windows XP (KB910728)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Image Converter 2 Plus
ImageJ
Intel(R) Graphics Media Accelerator Driver
Intel(R) PROSet/Wireless Software
InterVideo WinDVD for VAIO
IsoBuster 2.1
ISScript
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java Auto Updater
Java(TM) 6 Update 19
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
LAN Setting Utility
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
MAGIC M4A to MP3 Converter 3.1
Malwarebytes' Anti-Malware
mCore
mDriver
mDrWiFi
Memory Stick Formatter
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Data Access Components KB870669
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Starter Edition 2006
Microsoft Digital Image Starter Edition 2006 Editor
Microsoft Digital Image Starter Edition 2006 Library
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook 2003 with Business Contact Manager Update
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders  (English) 12
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
mIWA
mLogView
mMHouse
Move Networks Media Player for Internet Explorer
mPfMgr
mPfWiz
mProSafe
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
mWlsSafe
mXML
mZConfig
NanoDrive
Nanoscope 5.30r3sr3
Nanoscope 5.31r1
Nanoscope 8.0
NanoScope Analysis
National Instruments Software
Nero 6 Enterprise Edition
NI LabVIEW Run-Time Engine 7.1
Norton AntiVirus 2003
NVIDIA Drivers
NWZ-E340 WALKMAN Guide
Office 2003 Trial Assistant
Office Password Recovery Toolbox 2.0
OmniPage SE 2.0
OpenMG Secure Module 4.4.00
Presto! PageManager 7.15.11
Protector Suite QL 5.3
Quicken 2006
QuickTime
QuoteWerks 3.0 Node
QuoteWerks 4.0 MS CRM link
QuoteWerks 4.0 Node
Roxio DigitalMedia Audio
Roxio DigitalMedia Copy
Roxio DigitalMedia Data
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Setting Utility Series
SigmaTel Audio
SonicStage 3.4
SonicStage Mastering Studio 2.2
SonicStage Mastering Studio Audio Filter
SonicStage Mastering Studio Audio Filter Custom Preset
SonicStage Mastering Studio Plugins
Sony Certificate PCH
Sony Ericsson PC Suite
Sony Ericsson Wireless Modem
Sony MP4 Shared Library
Sony Utilities DLL
Sony Video Shared Library
Super Flexible File Synchronizer v4.75
SUPERAntiSpyware Free Edition
TexasInstVCPDriver
TPM Tutorial
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Service
v720
VAIO Breeze Wallpaper
VAIO Camera Utility
VAIO Central
VAIO Entertainment Platform
VAIO Event Service
VAIO Hardware Diagnostics
VAIO HDD Protection
VAIO Light Flo Wallpaper
VAIO Media 5.0
VAIO Media AC3 Decoder 1.0
VAIO Media Integrated Server 5.0
VAIO Media Redistribution 5.0
VAIO Media Registration Tool 5.0
VAIO Original Screen Saver
VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
VAIO Power Management
VAIO Registration
VAIO Security Center
VAIO Support Central
VAIO Update 2
VAIO Wireless LAN Setup Utility
VAIOSurveySA
VC8 MERGE Modules
VC9 Merge Modules
Vision 4.10
Vision 4.10 Advanced Analyses
Vision 4.10 Update 1
vPod (Remove Only)
WebFldrs XP
Whale Communications' Client Components v3.7.1
Winamp (remove only)
Windows Defender
Windows Driver Package - Digital Instruments, Inc (umpusbxp) MultiportSerial  (11/01/2004 1.2.11.03)
Windows Driver Package - NVIDIA (nv) Display  (06/20/2006 8.4.9.1)
Windows Driver Package - Sheldon Instruments (SIPLXWDM) SIPLXWDM  (01/12/2006 )
Windows Driver Package - Texas Instruments (umpusbxp) Ports  (11/01/2004 1.2.11.03)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Live Upload Tool
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See KB886612 for more information]
Windows XP Hotfix - KB307154
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB884018
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB888402
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893056
WinRAR archiver
WinUtilities 9.58 Free Edition
WinZip
Wireless Switch Setting Utility

==== Event Viewer Messages From Past Week ========

4/29/2010 11:47:32 AM, error: Dhcp [1002]  - The IP address lease 172.16.61.150 for the Network Card with network address 00130235A550 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
4/27/2010 7:00:42 PM, error: DCOM [10005]  - DCOM got error "%1053" attempting to start the service ccPwdSvc with arguments "" in order to run the server: {DBA28A20-5CE1-4E8D-AD35-418B62269E54}
4/27/2010 6:43:45 PM, error: Dhcp [1002]  - The IP address lease 192.168.1.100 for the Network Card with network address 00130235A550 has been denied by the DHCP server 172.16.48.1 (The DHCP Server sent a DHCPNACK message).
4/27/2010 5:46:29 AM, error: Dhcp [1002]  - The IP address lease 192.168.1.101 for the Network Card with network address 00130235A550 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
4/25/2010 10:16:37 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
4/25/2010 10:16:09 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/25/2010 10:05:41 PM, error: Print [6161]  - The document http://www.bleepingcomputer.com/forums/topic311974.html owned by ~ failed to print on printer Canon MP530 Series Printer. Data type: NT EMF 1.008. Size of the spool file in bytes: 1769472. Number of bytes printed: 273004. Total number of pages in the document: 9. Number of pages printed: 0. Client machine: \\SFR_LAPTOP08. Win32 error code returned by the print processor: 6 (0x6).
4/23/2010 3:26:10 PM, error: Ftdisk [49]  - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
4/23/2010 3:26:10 PM, error: Ftdisk [45]  - The system could not sucessfully load the crash dump driver.
4/22/2010 9:53:56 AM, error: Dhcp [1002]  - The IP address lease 192.168.1.100 for the Network Card with network address 00130235A550 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================


I'm at my wits end and I'm still no where near killing this bugger.  Any help would be much appreciated.

Thanks.Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Thank you for the reply.  I ran ComboFix and it *seems* to have worked 
I can now go onto Windows Update again.  Here is the ComboFix log, please let me know if there is anything in there that indicates it might still be infected.  I'm going to run GMER again just in case.  Let me know if you want that log posted also.

*************************************************************
ComboFix 10-05-01.04 - ~ 05/01/2010  20:50:03.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2038.1500 [GMT -4:00]
Running from: c:\documents and settings\~\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\data
C:\install.exe
c:\program files\WindowsUpdate
c:\recycler\S-1-5-21-1248417570-2269146281-292178343-500
c:\recycler\S-1-5-21-2308831925-2314612040-1759109179-500
c:\windows\jestertb.dll
c:\windows\setup.exe
c:\windows\Sonysys\VAIO Recovery\PartSeal.exe
c:\windows\system32\fusstub.dll

Infected copy of c:\windows\system32\drivers\acpiec.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
(((((((((((((((((((((((((   Files Created from 2010-04-02 to 2010-05-02  )))))))))))))))))))))))))))))))
.

2010-05-02 00:29 . 2010-05-02 00:35   --------   d-----w-   C:\CoboFix
2010-04-30 20:07 . 2004-08-04 12:00   95360   ----a-w-   C:\atapi.sys
2010-04-26 18:49 . 2010-04-26 18:49   --------   d-----w-   c:\program files\ESET
2010-04-26 02:08 . 2010-04-26 02:08   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-04-26 02:08 . 2010-04-26 02:08   --------   d-----w-   c:\documents and settings\~\Application Data\SUPERAntiSpyware.com
2010-04-26 02:08 . 2010-04-26 02:08   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2010-04-26 00:38 . 2010-04-26 00:38   12872   ----a-w-   c:\windows\system32\bootdelete.exe
2010-04-26 00:11 . 2010-04-30 14:07   15944   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
2010-04-26 00:10 . 2010-04-26 00:38   --------   d-----w-   c:\documents and settings\All Users\Application Data\Hitman Pro
2010-04-26 00:10 . 2010-04-26 00:10   --------   d-----w-   c:\program files\Hitman Pro 3.5
2010-04-24 21:35 . 2010-04-30 07:45   --------   d-----w-   c:\program files\Windows Live Safety Center
2010-04-23 19:40 . 2007-08-31 16:52   56496   ----a-w-   c:\windows\system32\wbhelp2.dll
2010-04-23 19:40 . 2007-08-31 16:52   33968   ----a-w-   c:\windows\system32\anim.dll
2010-04-23 19:40 . 2004-12-07 14:11   258352   ----a-w-   c:\windows\system32\unicows.dll
2010-04-23 19:40 . 1999-11-22 19:50   4608   ----a-w-   c:\windows\system32\W95INF32.DLL
2010-04-23 19:40 . 1999-11-22 19:50   2272   ----a-w-   c:\windows\system32\W95INF16.DLL
2010-04-13 06:07 . 2010-04-13 06:07   --------   d-----w-   C:\AMTtempImages
2010-04-13 06:06 . 1999-09-10 05:06   168720   ----a-w-   c:\windows\system32\MSLTUS35.DLL
2010-04-13 06:06 . 2010-04-13 06:07   --------   d-----w-   C:\AMThistory
2010-04-13 06:06 . 2010-04-13 06:06   --------   d-----w-   C:\AmtCommon
2010-04-13 06:06 . 2010-04-13 06:06   --------   d-----w-   C:\Amt600

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-02 01:32 . 2008-12-27 06:41   --------   d-----w-   c:\program files\Common Files\Symantec Shared
2010-05-02 00:15 . 2008-03-12 01:07   --------   d-----w-   c:\documents and settings\~\Application Data\Canon
2010-04-29 19:39 . 2008-07-28 15:03   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2008-06-04 16:49   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2010-04-27 05:14 . 2006-11-02 16:46   --------   d-----w-   c:\documents and settings\~\Application Data\AdobeUM
2010-04-15 20:38 . 2009-01-15 16:32   --------   d-----w-   c:\documents and settings\~\Application Data\FileZilla
2010-04-09 16:02 . 2006-03-22 23:00   --------   d-----w-   c:\program files\Common Files\Java
2010-04-09 16:01 . 2006-03-22 23:00   --------   d-----w-   c:\program files\Java
2010-03-11 12:38 . 2006-03-22 17:56   832512   ----a-w-   c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2006-03-22 17:56   78336   ----a-w-   c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2006-03-22 17:56   17408   ------w-   c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2006-03-22 17:56   430080   ----a-w-   c:\windows\system32\vbscript.dll
2010-03-09 08:28 . 2009-02-24 14:27   411368   ----a-w-   c:\windows\system32\deploytk.dll
2010-03-08 00:30 . 2007-03-31 18:22   --------   d-----w-   c:\documents and settings\All Users\Application Data\DVD Shrink
2010-03-04 22:56 . 2007-01-11 18:31   --------   d-----w-   c:\documents and settings\~\Application Data\U3
2010-02-24 14:16 . 2009-10-04 05:23   181632   ------w-   c:\windows\system32\MpSigStub.exe
2010-02-24 12:31 . 2006-03-22 17:56   454016   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 17:35 . 2006-03-22 17:56   2143744   ----a-w-   c:\windows\system32\ntoskrnl.exe
2010-02-16 16:57 . 2004-08-03 22:59   2021888   ----a-w-   c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:47 . 2006-03-22 17:56   100864   ----a-w-   c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2006-03-22 17:56   226880   ----a-w-   c:\windows\system32\drivers\tcpip6.sys
2004-03-15 22:51 . 2004-03-15 22:51   114688   ----a-w-   c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2008-12-25 21:45 . 2008-12-25 21:45   0   --sh--w-   c:\windows\S3A6D9F76.tmp
2008-12-27 06:43 . 2008-12-27 06:43   32   --sha-w-   c:\windows\{27605EE2-0707-4CF3-BB1C-E808AD90E4BC}.dat
2008-12-27 06:43 . 2008-12-27 06:43   32   --sha-w-   c:\windows\system32\{F5E374BF-C6B5-407C-A685-94751F290334}.dat
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-20 7561216]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-17 118784]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-01-26 212992]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-21 167936]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [2006-02-23 1354240]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-03 700416]
"eTrust PestPatrol Active Protection"="c:\utilities\Security\PestPatrol\PPActiveDetection.exe" [2004-09-27 106496]
"Sony Ericsson PC Suite"="c:\utilities\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"OpwareSE2"="c:\utilities\Canon\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"Windows Defender"="c:\utilities\Security\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-08-20 50880]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-20 34504]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"QuickTime Task"="c:\utilities\Media Players\Quicktime v7.1.3\qttask.exe" [2009-05-26 413696]
"HitmanPro35"="c:\program files\Hitman Pro 3.5\HitmanPro35.exe" [2010-04-30 5937984]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\productivity\Adobe\Acrobat 6 Pro\Distillr\acrotray.exe [2003-10-24 217194]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-2-22 1765376]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\utilities\Security\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21   548352   ----a-w-   c:\utilities\Security\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-08-12 00:09   73728   ----a-w-   c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\ImageJ\\jre\\bin\\javaw.exe"=
"c:\\Productivity\\Office11\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nanoscope\\v720\\DspNsSimulator.exe"=
"c:\\Program Files\\Common Files\\QuoteWerks\\QWWebConnector4.exe"=
"c:\\Program Files\\Whale Communications\\Client Components\\3.1.0\\WhlClnt3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Utilities\\Media Players\\iTunes v8.1.1\\iTunes.exe"=
"c:\\Utilities\\FTP Clients\\FileZilla FTP Client\\filezilla.exe"=

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/22/2006 1:57 PM 9216]
R1 SASDIFSV;SASDIFSV;c:\utilities\Security\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\utilities\Security\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 11:15 AM 66632]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2/22/2006 10:13 PM 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2/22/2006 10:13 PM 33024]
R2 WinDefend;Windows Defender;c:\utilities\Security\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [3/22/2006 1:57 PM 36352]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [3/22/2006 1:57 PM 29184]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [3/22/2006 1:57 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [3/22/2006 1:57 PM 226304]
S3 DiMeiMC;MEI MC Stage;c:\windows\system32\drivers\DiMeiMC.sys [6/12/2008 3:52 PM 7832]
S3 DMService;Whale Component Manager;c:\windows\DOWNLO~1\DMService.exe [11/25/2008 12:30 PM 423576]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\PLCNDIS5.SYS --> c:\windows\system32\PLCNDIS5.SYS [?]
S3 SASENUM;SASENUM;c:\utilities\Security\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 11:15 AM 12872]
S3 SE2Fbus;Sony Ericsson Device 047 Driver driver (WDM);c:\windows\system32\drivers\SE2Fbus.sys [11/4/2006 8:18 PM 61600]
S3 SE2Fmdfl;Sony Ericsson Device 047 USB WMC Modem Filter;c:\windows\system32\drivers\SE2Fmdfl.sys [11/4/2006 8:19 PM 9360]
S3 SE2Fmdm;Sony Ericsson Device 047 USB WMC Modem Driver;c:\windows\system32\drivers\SE2Fmdm.sys [11/4/2006 8:19 PM 97184]
S3 SE2Fmgmt;Sony Ericsson Device 047 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\SE2Fmgmt.sys [11/4/2006 8:21 PM 88688]
S3 se2Fnd5;Sony Ericsson Device 047 USB Ethernet Emulation SEMC47 (NDIS);c:\windows\system32\drivers\se2Fnd5.sys [11/4/2006 8:23 PM 18704]
S3 SE2Fobex;Sony Ericsson Device 047 USB WMC OBEX Interface;c:\windows\system32\drivers\SE2Fobex.sys [11/4/2006 8:20 PM 86560]
S3 se2Funic;Sony Ericsson Device 047 USB Ethernet Emulation SEMC47 (WDM);c:\windows\system32\drivers\se2Funic.sys [11/4/2006 8:22 PM 90800]
S4 LkWebLink;Inter-Tel Collaboration Remote Client;c:\documents and settings\~\My Documents\Inter-Tel\Collaboration Client 2.0\lkWebLink.exe [9/15/2008 10:35 AM 32768]
.
Contents of the 'Scheduled Tasks' folder

2010-05-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\utilities\Security\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2010-05-02 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-12-27 14:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\produc~1\Office11\Office12\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 Plus - c:\program files\Sony\Image Converter 2\menu.htm
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-VAIO Recovery - c:\windows\Sonysys\VAIO Recovery\PartSeal.exe
HKLM-Run-PartSeal - c:\windows\Sonysys\VAIO Recovery\PartSeal.exe
Notify-psfus - fusstub.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 21:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1208)
c:\utilities\Security\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'explorer.exe'(2808)
c:\windows\system32\WININET.dll
c:\utilities\Canon\OmniPageSE2.0\ophookSE2.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Protector Suite QL\mysafe.dll
c:\program files\Protector Suite QL\infra.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\utilities\Security\NAV2003\navapsvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Apoint\Apntex.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\utilities\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\program files\Messenger\msmsgs.exe
c:\program files\Common Files\Symantec Shared\NMain.exe
.
**************************************************************************
.
Completion time: 2010-05-01  21:42:52 - machine was rebooted
ComboFix-quarantined-files.txt  2010-05-02 01:42

Pre-Run: 5,244,211,200 bytes free
Post-Run: 5,410,398,208 bytes free

- - End Of File - - 2C8102964AEC911BA4B7D668F149F0C0

Thanks again!
Go ahead with the GMER log.If this is indeed cleaned, I can't thank you enough.  So far so good, my hibernate function is working again too (it stopped working when I picked up the rootkit virus).  NAV scan - clean, MS Onecare online - clean, MBAM, SAS and ESET scans next.  Should I also run DDS again?

Here's the GMER log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-02 11:31:35
Windows 5.1.2600 Service Pack 2
Running: 1z0hdkjw(gmer).exe; Driver: C:\DOCUME~1\~\LOCALS~1\Temp\pwdoikob.sys


---- Kernel code sections - GMER 1.0.15 ----

?               Combo-Fix.sys                               The system cannot find the file specified. !
?               C:\DOCUME~1\~\LOCALS~1\Temp\mbr.sys  The system cannot find the file specified. !
?               C:\ComboFix\catchme.sys                     The system cannot find the path specified. !
?               C:\WINDOWS\system32\Drivers\PROCEXP113.SYS  The system cannot find the file specified. !
?               System32\Drivers\hiber_WMILIB.SYS           The system cannot find the path specified. !

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                      SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Ip                    SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Tcp                   SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\Udp                   SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice  \Driver\Tcpip \Device\RawIp                 SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)

---- EOF - GMER 1.0.15 ----

Thank you!Log looks fine.

Please run a free online scan with the ESET Online Scanner

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Hi,

Here's the ESET log.  I don't think that one file it found was actually bad, but I let it delete it anyway just in case.  BTW, do you know if there is any updates or anything out there that will prevent future TDSS rootkit infections?  I will obviously not make the same mistake again and pay full attention next time I delete bad emails (so that I click Delete instead of the link  ).

************************************************************************************

[email protected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=53084455feb56a4bbcbf6ea0ddeb8a5e
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-05-03 12:04:28
# local_time=2010-05-02 08:04:28 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 109470394 109470394 0 0
# compatibility_mode=3586 16764925 100 81 0 697131779 0 0
# compatibility_mode=5889 16768381 100 100 59385052 112653725 0 59456579
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=129823
# found=1
# cleaned=1
# scan_time=15689
C:\Downloads\Utilities\framework-3.0.exe   JS/TrojanDownloader.Psyme.NCX trojan (deleted - quarantined)   00000000000000000000000000000000   C

*******************************************************************************

Thanks!

Safe surfing. I recommend to stay away from downloading anything, including from P2P programs/sites, torrents. Rootkits get distributed highly in P2P downloads.

Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP BUTTON click this
  • Accept the Warning and select OK again, the program will close and you are done
To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have SAVED all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
1317.

Solve : How does Win Police Pro gets into your computer?

Answer»

I have a friend that his OP crashed because he had Win Police Pro. It downloaded itself and BEGAN its DESTRUCTIVE course. My question is  how did  she get it in her COMPUTER, via e-mail, via the Internet. anyone know it comes thru?Can be via email, but usually from a link on a website or sometimes downloads,,.....Use Web of Trust to screen all websites while browsing and the CHANCES of it happening again will be greatly reduced......

1318.

Solve : The only thing I can see if my screen saver.?

Answer»

Quote from: rker321 on September 09, 2009, 05:03:24 PM

A name change  UH!!!!!!
just got the CD going to dinner will try it a little LATER and see what happens. thanks you guys.
Didn't mean to confuse you. The name change thing has NOTHING to do with your posts.Ok 
I downloaded a boot  CD and it scanned the computer, it showed all kinds of viruses. most of them low, but about three of them very HIGH. I couldn't clean them because they wanted 40.00 to do the fixing. So I THOUGHT that I would use my McAffe CD to clean the viruses. Is that ok?
Now by clicking control- alt-delete and clicking the apps. I was able to see all the folders, but couldn't make Windows open them. So I could not use the antivirus installed in the computer.
The desktop  seem to be behind the screen saver. Is there a way that I can reach that screen saver and delete it?yes use mcafee

who wanted 40.00 to clean it you must have bought it Or you can download a free boot virus scanner (Avira, Avast, etc).One of the three that I was told to get. it was not Karpaski they wanted 89.00 
Anyway, I will create a Boot for Avast that is the system that I have in the computer. I could not bring it up or have Win open it upas allen said avast or avira , dont pay for any thing you will get good free stuff here
1319.

Solve : Can't get past welcome screen?

Answer»

Had a virus on my netbook.  Use XP.  Some kind of 'security essential 2010...buy my software or else'.  Downloaded spybot and ran it.  Might have worked...don't know.  Can't get by the welcome screen.  When you get to the welcome screen, it has USER there...not what I had set it up for.  When I press USER, it looks like it is going to start but then closes down on itself.  It doesn't turn off the computer, it just stays at the welcome screen with USER still there.  You can't go any farther.

I tries safe mode and the ADMINISTRATOR box comes up in the welcome screen with the USER box.  When I press the administrator box, it does the exact same thing.  It goes nowhere. I am kinda stuck. I don't have a dvd drive on this netbook.  Any ideas?

removedspybot is useless. And unless you want to be inundated with spam, NEVER post your email address on a forum.

I'd suggest you download and run a boot TIME anti virus utility.Thanks allan, i will try thatI have ALMOST same thing but it is full page lite blue, scans and says 47 problems. they seem to have complete control of my computer. say eplorer.exe, tastmater.exe and quite a few more even my enternet will not work to buy. I have a paid avg and the virus says it is encluded and will not go on line.Name seems to be ... Security even has 2 short cuts on my desk top, which will not do anything. help please if possible. I am on my other computer with win7. Alson on my xp os has a Trustee Rap----something that was supused to WATCH all this. says trojans, and keggloggers tring to get into my bank.sunboysunday - please start your own thread.there is nothing that can be added to this computer. Cannot get to control panel,internet or any files. I have the hijackthis on a flash drive. Will not install. no files will open. When i try to activate the product .......... Security it can not get online just keeps on rolling. Surly somewhere this has happen to someone else so there is a way around it
Thanks so much for your help evilfantasy. any other ideas? Quote from: Allan on MAY 03, 2010, 03:07:54 PM

sunboysunday - please start your own thread.
i did.
 thank you.
1320.

Solve : Please Help Something is eating my Memory?

Answer»

yes this is your TOPIC go ahead and do it

were did you post it and i'll get it removedHere in computer viruses and Software....THANKS !
OK...Here are the files that you requested....

   ATTACHED

[attachment deleted by admin]You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:
•ViewMgr.exe - Useless

•Viewpoint to Plunge Into Adware
It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove PROGRAMS and remove the following programs if present.
•Viewpoint

•Viewpoint Manager

•Viewpoint Media Player

•Viewpoint Toolbar

•Viewpoint Experience Technology

do above please

and also go to add and remove and take out fun web products

can you post a clean sas and malware log here
It would be wise to allow the program to clean the computer....all the entries say No action takenyou mean the hjt logMalwarebytes....all the entries say No Action taken.....they were not quarantined or removed. Quote from: Karnac on September 09, 2009, 05:30:24 PM

Malwarebytes....all the entries say No Action taken.....they were not quarantined or removed.

never noticed that , thanks karnac , just amazed at the amount was in the pc

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxx



BUYDELL , RERUN SAS AND MALWARE AND DELETE ANYTHING THAT COMES UP PLEASE  , and then rerun your

hjt  and place all 3 logs HERE

edit at 1.30 am GMT going to bed have to get for my pension , see them to-morrow
1321.

Solve : Extremely aggressive worm chokes instant messaging?

Answer»

New variant of Palevo blasts unprotected systems via fake photo gallery links.

The latest offspring of the Palevo family has begun spreading these days via a massive wave of AUTOMATICALLY generated IM SPAM. The unsolicited message INCITES the recipients to click a link accompanied by a grinning smiley face, which purportedly leads them to an image or photo gallery.

http://tinyurl.com/3anctv4 Is the THREAT was discovered by BitDefender  only

1322.

Solve : How to remove windows defender?

Answer»

Hi,

Over the past week or so the Window Defender icon showed up on the bottom right of my screen with the other icons.  Since then I've turned down updates and tried to remove the icon (it comes back when I turn the computer back on).  I've looked around and there seems to be some chat about this being a virus.  Aside from the FACT that it won't go away, I don't seem to be having problems with my computer other than a wifi connection issue which I think is related to an ROUTER that needs to be replaced.  How can I tell if this Windows Defender is something to be worried about or just an unsolicited Windows update?  I have Vista and Avast.If you don't want Windows Defender running you can simply disable the Windows Defender Service (start - run - services.msc)Please go to this link and follow the DIRECTIONS and post the required logs. Please post your logs in this link.Hi, I've tried going through the steps but HIT a snag.  I can't seem to find an "add or remove programs" icon. I do have one called "programs and features."  Also today I have noticed something different.  I usually use Google to search and it looks a little strange.  It is hard to explain but the box you type in is a BIT larger and when the list of results comes up there is a left-hand margin on the page.   Something strange with Yahoo too.  When I check my e-mail on Yahoo and log-out the screen that shows up is really different with only a few sentences of info and a beige banner across screen.If your OS is XP it's Add/Remove Programs. Vista and Windows 7 it's Program and Features. My Google changed yesterday also. The main thing is to run the scans and get the logs.

1323.

Solve : Rogue Problem?

Answer»

You're welcome! This problem came back again. Should I follow the same procedure in removing this MALWARE? Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make SURE all other running programs are closed and no other actions LIKE a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.I dont know what s going on with my computer, but the original problem disappeared and new one came. Now, the computer is working very very slow, and programs are taking way too long to open up. Even as I am TYPING this message it freezes EVERY 5 seconds then comes back to normal. its like its on for 5 secs then freezes. Is this still a malware problem? Never mind. I did a system restore and it fixed this problem. thanks again Dragonmaster. There seems to be no malware. OK. No problem at all.this problem re-appeared again. Please advise. Thanks. Start a new topic, please.

=>LOCKED.
1324.

Solve : Cannot Open Anything?

Answer»

I have tried using the "Read this before requesting malware help" thread, but after installing and running CC cleaner, and installing and beginning a scan with SUPER Anti Spyware, my computer froze and now i cant open up CC cleaner, or Super Anti Spyware. I have tried REINSTALLING, but i cannot open the installer.If you've lost your CONNECTION, download the programs to a USB stick on a good PC and transfer them to your PC.
If you have difficulty, you may have to run them in safe mode, TAP F8 at start, .
If you have difficulty, you may have to rename the programs when you save them.
If you get stuck on a step, proceed to the next .

Post the logs for step 3,4 and 6.
I can open firefox and my computer. I haven't tried MANY but things like itunes, internet explorer, mcafee, ccleaner, super anti-spyware, etc. won't open.I need help. Can you get HijackThis to run?  It is in the "Read this" topic that you read before requesting help.

Since you can at least get Firefox to open, try running an online scan: http://www.kaspersky.com/virusscanner

1325.

Solve : Application cannot be executed. The file --- is infected?

Answer»

My housemateat university is having issues with his computer which a lot of other forum members seem to be having. Having read some of SuperDave's advice it seems each case is quite unique so I would appreciate any possible help in fixing his laptop. Here is a HJthis log from safe mode, but I can't manage to launch one in normal startup;


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:07:12, on 03/05/2010
Platform: UNKNOWN Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\SKYPE\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\AVG\AVG9\avgscanx.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgscanx.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ipwrvumw] C:\Users\Robert\AppData\Local\utxxeovkl\qrrwrhttssd.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple INC. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 5048 bytes


Sorry for such a delay. It seems almost everyone needs help.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
Save Rkill to your desktop.

There are 4 different versions. If one of them won't run then download and try to run the other one.
 
Vista and Win7 users need to right click Rkill and choose Run as Administrator
 

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.exe
Rkill.com
Rkill.scr
Rkill.pif

Once you've gotten one of them to run then try to immediately run the following.
 
Now download and Run exeHelper.

Please download exeHelper from Raktor to your desktop.

  • Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to CLOSE once the fix is completed. A log file named log.txt will be created in the directory where you ran exeHelper.com Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If this works, please try to run HJT in Normal Mode and send me the log.
1326.

Solve : computer won't install any mal-ware removal programs?

Answer»

Go to this LINK to create a Rescue CD or to this site to create a Rescue USB. Carefully FOLLOW all the instructions for whichever METHOD you choose.

1327.

Solve : APPLICATION CANNOT BE EXECUTED! WHAT DO I DOOO?

Answer»

I keep getting this alert and I don't know what to do. My laptop is run by WINDOWS vista bought 2.5 years ago. SOMEONE HELPPPSome applications cannot be run in vista because of compatability issue....Right click on application --> properties --> compatabilty. and select Run this program in compatability mode for then choose the windows version.noooo its a malware thingy rogue program or whateverI FOLLOWED SuperDave's instructions i saw in other threads. But I can't seem to update SUPERAntiSpyware cause of the firewall or something


This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Owner on 08/05/2010 at 12:11:42.


Processes terminated by Rkill or while it was running:


C:\Users\Owner\AppData\Local\pducbhtkn\pmvpcektssd.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Owner\Desktop\rkill.com


Rkill completed on 08/05/2010  at 12:11:48.


-


exeHelper by Raktor
Build 20100414
Run at 00:32:52 on 05/08/10
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--

exeHelper by Raktor
Build 20100414
Run at 12:13:53 on 05/08/10
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--

HIJACKTHIS LOOGGG

MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
C:\Program Files\Rogers\SelfHealing\shs.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Registry Mechanic\RMTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet SETTINGS,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\ADOBE\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Rogers Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
O4 - HKLM\..\Run: [Rogers SHS] C:\Program Files\Rogers\SelfHealing\shs.exe
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.nba.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - PROTOCOL: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Rogers SHS Service (RogersSelfHelpService) - Rogers Cable Communications - C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe
O23 - Service: Rogers Update Manager (RogersUpdateManager) - Rogers Cable Communications - C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 14149 bytes
What do you mean by Hijack it?

1328.

Solve : Total Security 2009?

Answer»

I've tried everything..

Taskmanager is DISABLED, I tried renaming it.

You can NOT start in safe mode.

You can NOT do a system restore.

Can not connect to the internet with this pc either.

Can NOT download hjt.

Please advise..

Thank you for any help.

Have you tried transferring the AV programs to the infected PC via a USB stick?...Try renaming the programs when you save them.It won't let you do anything once the pc is up and running. It just launches virus updates and scans.

What I did do though, was installed y new U3 Data stick with auto launch enabled. That caused enough lag that gave me enough time to launch a taskmanager REPAIR and then USE the task manager to CLOSE out the program as it was starting. Then once it was closed out I went ahead and deleted the virus and all the reg that it had installed. It was NOT easy, but it's done an my granny gets her pc BACK

1329.

Solve : Suspicions of Malware on my laptop?

Answer»

Hi guys and girls

My LAPTOP is an ACER Aspire 5920G, with Intel Core 2 duo processor, and running windows Vista SP2. My antivirus program is Avast and I also run half monthly scans with Malwarebytes and Superantispyware. My browser is Firefox.

I have got a feeling that there may be something nasty on my laptop that I can't find. Last WEEK I clicked on a link from Google and this screen pops up saying that my laptop has problems and starts a scan screen. I click the cross to close it, but this simply opened another screen asking if I wanted to scan my computer. I suspected a virus so I shut off the internet and powered down my laptop. After restarting I immediately ran Malwarebytes and Superantispyware. Malwarebytes detected nothing, and all Superantispyware picked up was 3 tracking cookies which it finds all the time. Since then  startup times have been increasing for the last week. I have run Malwarebytes and Superantispyware a couple times since then (See logs) but they have detected nothing. I have also posted a hijackthis log done a few minutes ago. I am wondering if despite me closing off the internet and powering down a virus managed to GET in.

Also I nearly forgot - my internet has slowed down lots - more than just a usual busy period. For example a 5 min youtube X factor vid would have played through smoothly no gaps, maybe a minute to reach full download - now its taking close to 10 minutes. I am wondering whether a virus is causing this as well? I have checked my bandwidth and its fine, got lots of capacity left.

Can you see anything that might be causing problems? Is it possible that there are other causes for system slow down?

Thanks

Razor

[attachment DELETED by admin]

1330.

Solve : Yahoo Instant Messenger ???

Answer»

Win XP   Java is updated. all other updates currant. On my sisters computer, doing  a cleanup. Used AVG and malware BYTES, also deleted all unused programs.  Tried to remove Yahoo IM and it will not delete.  All other programs not wanted deleted just fine. Runs much faster now but am WORRIED about any file that will not allow us to delete it.  We had IE 8 and had to remove it also.  Please direct me how to remove. THANKS  RC 1) Deleting unused programs does not speed up your system
2) Reinstall Yahoo Messenger then uninstall it. I am sure you are right about unused programs, so I guess that means that it needed the cleaning AVG and Maleware Bytes gave it was needed badly.  THANK you for the tip will try it right away.    R C

1331.

Solve : "Your System is Infected" is virus leeching my computer - help please! :)?

Answer»

I'm not sure what you mean by 'paid' - the PC Guard I was using was 'free' with my broadband, but I was PAYING for the Broadband... so I guess it's paid? It was also updated. However, I've since changed to avast, which has thrown up a few viruses. The file names are:

A0088169.exe - Win32: Trojan - gen
A0088444.exe - "
A0088763.exe - "
A0095249.exe - Win32: Rootkit - gen
Win32avs.exe.vir

I've deleted the above, but the following system files remain in the avast 'chest', as I didn't know what to do with them:

kernel32.dll
winsock.dll
wsock32.dll

My computer has also developed an annoying habit of opening the My DOCUMENTS folder on start up. This has only started occuring since I deleted PC Guard and downloaded avast.

I've attached my latest Malwarebytes log

[attachment deleted by admin] Quote

I've deleted the above, but the following system files remain in the avast 'chest', as I didn't know what to do with them:

kernel32.dll
winsock.dll
wsock32.dll

Leave them there.

Run a new HijackThis scan and post the log please.Thanks

[attachment deleted by admin]Disable Spybot's TeaTimer

While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes. Please disable TeaTimer for now until we are done.

1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
2. Run Spybot S&D
3. Go to the Mode menu, and make sure Advanced Mode is selected.
4. On the left hand side, choose Tools > Resident
uncheck Resident TeaTimer and OK any prompt and Restart your computer.

Note:
If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

If TeaTimer will not turn off then uninstall Spybot until we are done cleaning.

----------

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

- F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\word64main.exe,

Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixI performed the Malwarebytes scan, and checked and fixed
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\word64main.exe,

However, it seemed to fix it so quickly, that I wasn't sure that I done done it properly. I pressed scan again, and found:

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\word64main.exe,

Is this right?

I've also attached the latest ComboFix log.

[attachment deleted by admin] 

[attachment deleted by admin]That's the same log you posted earlier.Download OTM by OldTimer to your desktop.

Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

* Save it to your Desktop.
* Double-click OTM.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code: [Select]:Processes
explorer.exe

:services

:reg

:files

:Commands
[purity]
[emptytemp]
[start explorer]

* Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes.
Oh dear....

After I copied that information into OTM and clicked Moveit!, the program did its thing, then asked to reboot. I couldn't select any of the information in the Results section, so couldn't copy it.

When the computer rebooted, all I got was my background. I managed to get task manager up, and rebooted several times, but still, just the background. I rebooted in Safe Mode, but all I got was a black screen, so had to restart.

I've managed to get my internet connected and an internet browser window up using Task Manager, but do not have a Task bar or start button, and there's NOTHING on my desktop. I tried to run OTM, and it brought up a log, so I've posted that.

I must have done something wrong, but followed the instructions exactly. I was sure that I only highlighted the text on the previous Code box; would it have made a difference if there was an extra space in it??

With regards to the previous Combo Fix log - I definately attached a log that was different to the previous one - unless I failed to follow previous instructions properly....

[attachment deleted by admin]Start the computer in Safe Mode. Getting into Windows Safe Mode.

From the options choose Last Known Good Configuration.

Let me know how that goes.

Do you have your Windows install CD?I'll do that now.

I don't have the Windows Install CD - I have recovery discs, though. Will this do any good?

 - Had a go at starting in Last Known Good Configuration... no luck. I'll get the recovery discs ready!

-  Sorry to modify my post yet again, but something STRANGE has happened. I tried to open just any old folder in desperation using Task Manager (I think it was shared documents or something), and a Windows message came up:

/idlist.:992:3832,C:\Documents
Windows cannot find '/idlist.:992:3832,C:\Documents'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

My start menu, task bar and Desktop came back at this. When I restarted my computer, they were gone again, but when I opened another folder, I got the Windows message and they came back again, although my computer is slowing down at odd moments, then picking up in speed again. Hummm... is this no longer a malware problem? Should I post this in another forum?

ThanksEdited.I had a similar-looking virus wreak havoc on my comp a few weeks ago. I had norton antvirus, which, apparently, proved to be useless. The virus simply messed it up. The virus prevented me from opening any antivirus programs...so I restarted in safe-mode and ran Malwarebytes. MB picked up the virus and squashed it flat against the wall, like a disgusting bug. I know this method doesn't work for everyone...but it's worth a try. Due to no further response from the OP, this thread is locked. If the OP wants it re-opened, please pm me.
1332.

Solve : Undetectable malware/virus/Antispyware Pro??

Answer»

I've been fighting this problem for a few weeks now, off and on.  Occasionally I'll be infected with Antivirus Pro 2010, Antivirus Pro 2009, and most recently Antispyware Pro.  After running the usual "remedies" such as SAS, Malwarebytes Pro, Trojan REMOVER, and Spybot it'll somewhat go back to NORMAL...only with a random popup here and there.  Everytime a popup hits, AVG will tell me that there is a threat, so it's almost like something is there but not being detected.

Now, whenever I run Malwarebytes Pro absolutely NOTHING comes up as a threat/error; which is uncommon.  Some smaller stuff will come up with the other tests, but nothing that seems to fix the problem.  Any help would greatly be appreciated.

- MikeI'm not sure what version of MBAM you're using. Could you please uninstall the version you have and download this newest one. Run a FULL scan and post the log.

Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.Peterwolfe, please don't make this more confusing for the OP. THANK you.
1333.

Solve : AVR09.EXE, Cannot Launch CMD, or Task Manager?

Answer» OH sweet lord in heaven. It found it. Rebooting computer to take CHANGES now. Whewww thanks for recommending SUPERAntiSpyware. I checked their website about winupdate.exe, and the POSSIBLE sizes for the files, matched the exact SIZE of my winupdate.exe. I hope this PROBLEM is resolved...
1334.

Solve : Rogue.A360AntiVirus and other problems?

Answer»

This is a Dell Inspiron 1525 laptop, Vista HOME Basic SP1.
Lately it's been slow and some settings were changed mysteriously.
I completed the steps listed in themalware removal guide
 At this point I'm not sure what to fix or not with the HJT PROCESS tool.
Thanks
Mike

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/14/2009 at 06:55 AM

Application Version : 4.28.1010

Core Rules Database Version : 4097
Trace Rules Database Version: 2037

Scan type       : Complete Scan
Total Scan Time : 16:10:06

Memory items scanned      : 665
Memory threats detected   : 0
Registry items scanned    : 8673
Registry threats detected : 0
File items scanned        : 646704
File threats detected     : 30

Adware.Tracking Cookie
   C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
   C:\Documents and Settings\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Cookies\[email protected][1].txt
   C:\Documents and Settings\selbyclu\Cookies\[email protected][1].txt
   C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Administrator\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Administrator\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Administrator\Cookies\[email protected][1].txt
   C:\Users\Administrator\Cookies\[email protected][2].txt
   C:\Users\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\selbyclu\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\selbyclu\Cookies\[email protected][1].txt
   C:\Users\selbyclu\Cookies\[email protected][1].txt
   C:\Users\selbyclu\Cookies\[email protected][1].txt


Malwarebytes' Anti-Malware 1.41
Database version: 2812
Windows 6.0.6001 Service Pack 1

9/16/2009 2:26:52 PM
mbam-log-2009-09-16 (14-26-52).txt

Scan type: Quick Scan
Objects scanned: 96934
Time elapsed: 6 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Start Menu\A360 (Rogue.A360AntiVirus) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Start Menu\A360\A360.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully.
C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Help.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully.
C:\Users\selbyclu\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Registration.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\System\Uninstall\Uninstall A360.lnk (Rogue.AV360) -> Quarantined and deleted successfully.


  Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:43:22 PM, on 9/16/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Creative Home\Hallmark Card Studio 2008 Deluxe\Planner\PLNRnote.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\sniper\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myembarq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Automatic E-Mail Printing.lnk = C:\Program Files\INETPRN\INETPRN1.EXE
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Event Planner REMINDER 2008.lnk = ?
O4 - Global Startup: McAfee Security Scan.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll
O13 - Gopher Prefix:
O16 - DPF: {997C5A94-77F6-427D-A388-AC2B6ECF0F7C} (InstallShield Setup Player V14) - https://www.mnlife.com/LifeSolutionsUpdate/setup.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\Windows\system32\brsvc01a.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\Program Files\Retrospect\Retrospect Express HD 2.0\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect Express HD 2.0\retrorun.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10892 bytes
Go ahead and download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

1335.

Solve : anti viruses?

Answer»

Quote from: Ironman on DECEMBER 31, 2009, 01:57:13 PM

I have 5 pitbulls that serve as my anti-virus and firewall.

thats fine , as long as there are no kids there for the DOGS to KILL Quote from: harry 48 on December 31, 2009, 01:11:29 PM
avg                        no , takes up to much room , slows the pc when running

bit DEFENDER          do not know anything about it

avast                     it is good

norto security        no

mac afee                no

avira                       it is good


i had avg , macafee and norton they all gave trouble , so i have avira free now
thanks for your info
1336.

Solve : Bad virus help plz?

Answer»

Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

* Scroll down to Non-plug and Play Drivers and click the plus icon to open those drivers.
* Search for any of the following:
* Important! The letters can appear in either upper case or lower case letters.

- UACd.sys <- Or anything beginning with UAC
- gaopdxserv.sys <- Or anything beginning with gaopd
- gxvxcserv.sys <- Or anything beginning with gxvx
- Seneka.sys <- Or anything beginning with Seneka
- clbdriver.sys <- Or anything beginning with clbdriver
- TDSSserv.sys <- Or anything beginning with TDSS
- ovfst.sys <- Or anything beginning with ovfst
- lowsec.sys <- Or anything beginning with lowsec

* If you do find it, right click on it, and select Disable. Do not try to uninstall them.
* Now restart the computer and see if you can run the scans that would not run.
* Let me know if you found them or not.when i try to click on system from the control panel i get that stupid black box that looks like CMD or RUN... there is a message that pops up in the black box right before it disappears and says.. The programs is too big to fit in memory... any suggestions on a different way to get to system... thxDoes it do the same thing in Safe Mode also?not sure which safe mode you want me to use... if i just use regular safe mode i get files that go down my screen mosly in system 32 and then a blue screen appears... saying  A problem has been dected and windows has been shut down to prevent damage to your computer.. then tells me some steps to prevent further damage and cant do anything but restart my computer.. Technical information *** Stop: 0x0000007B (0xF78EA528, 0xc0000034, 0x00000000, 0x00000000).. not sure if there is a way around this or a different route you want me to choose...Try this please.

Click Start > Run

Now type this in exactly as it is typed, note the space between the chkdsk and /r

Code: [Select]chkdsk /r
Then press Enter on your keyboard.

You will likely see an error about why chkdsk can't run. Just type Y and then press the Enter key. Be sure the computer restarts.

Let me know how that goes.i typed in exactly how you said and again that black window appears .. says program too cant fit in memory... then quickly disappears.. leaving me no chance to click Y and enter...There are definite malware issues but I'm also afraid this is more than malware. The OS or possibly the Hard Drive itself is corrupted.

Do you have your Windows install CD?unfortunitly the windows cd is nowhere to be found.. i have a key with no cd... not sure if that matters... any suggestions ? thxKnowing the key is a good thing. Do you have a friend that has the same OS as you that you could borrow a disk from?You might also try another rescue cd.

Dr.Web LiveCD

1. Download the image of the Dr Web LiveCD

The download link is at the BOTTOM of the page. Click Download Dr.Web LiveCD. On the next page click on the most recent modified version, which is usually either the first or second download.

2.  Burn the Dr Web LiveCD ISO images to a CD or DVD.

- If you need a free burning application, CDBurnerXP works on all operating SYSTEMS from Microsoft Windows 2000 SP4 onwards.

3. Start the computer with the Dr Web LiveCD in the CD/DVD tray. As loading starts a dialog window will prompt you to choose between the standard and safe mode. Use arrow keys to select Dr Web LiveCD (Default) mode and press Enter on the keyboard.

4. When Dr.Web LiveCD (Default) is selected, all available disk drives will be detected automatically. The operating system will also try to CONNECT to the local network if available.

5. When the system is loaded, check all disks or folders you want to scan and click Start

6. Let Dr. Web FINISH it's scan and then remove any threats found and then exit out of the scanner..

7. Take the CD out of the CD/DVD tray and then restart the computer.

The Dr Web LiveCD also includes other useful features and helpoptions if needed.

* If you’d like to start the scanner using the command line (console) select Dr.Web LiveCD (Safe Mode).
* Choose Start Local HDD if you want to boot from the hard drive instead of Dr.Web LiveCD.
* Select Testing Memory to launch the Memtest86+ utility.

See the Dr.Web LiveCD Homepage for complete details.
not Windows Media Center.. i do have a Windows xp Home edition restallation cd but that is different from media center... i dont think i can use home edition on my labtob.... Home edition is different but a XP Pro disk would work. XP Pro is the same as Media Center only without the Media Center SOFTWARE which can be downloaded separately from Microsoft.yeah i dont have a xp pro disc.... i will try the Live cd, though i dont think i will be much use... let me know if you have any other ideas.... i will let you know how the cd rescue works.. thx

1337.

Solve : please read this hjt log?

Answer»

could you let me know what you think of the log please


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:08:25, on 04/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sky.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0621.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0621.0\msneshellx.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed LAUNCHER] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1218757052609
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c98584a11905de) (gupdate1c98584a11905de) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 12210 bytes
Well, it's not complete for one thing. The top part is missing and that's important also.
sorry dave never seen that , i have ADDED it onI am examining your log right now, but next time please include more info.you don't need info to read the log  do you Quote from: harry 48 on October 07, 2009, 04:28:26 PM

you don't need info to read the log  do you
It usually helps just in case the hjt is clean, So if the person has problems with a clean hjt we can get another tool to examine with. (like RSIT)

By the way I found nothing.
Hello Harry. The HJT log is clean. Let's try this:

Download random's system information tool (RSIT) by random/random from here and save it to your Desktop.

•Double CLICK on RSIT.exe to run.

•Click Continue at the disclaimer screen.

•Once it has finished, two logs will open.
log.txt <will be maximized and info.txt <will be minimized

•Please post the contents of both logs in the next reply. Quote from: cat-bomb on October 07, 2009, 04:31:37 PM
It usually helps just in case the hjt is clean, So if the person has problems with a clean hjt we can get another tool to examine with. (like RSIT)

By the way I found nothing.

ok i checked it myself as well and found nothing

Quote from: SuperDave on October 07, 2009, 05:07:12 PM
Hello Harry. The HJT log is clean. Let's try this:

Download random's system information tool (RSIT) by random/random from here and save it to your Desktop.

•Double click on RSIT.exe to run.

•Click Continue at the disclaimer screen.

•Once it has finished, two logs will open.
•log.txt <will be maximized and info.txt <will be minimized

•Please post the contents of both logs in the next reply.

THANKS dave , it's a friends log so i'll pass that on , i got her to take things out of add and remove , i have been going through her pc by e-mail all WEEK  and all her logs are clean so after the hjt was clean we will do the post you sent if there is any more bother i'll get her to join up , the pc seems to be going fine  but on the last checks now, harry

1338.

Solve : Toshiba Laptop Super slow and non responsive, was directed to post in the malwar?

Answer»

I followed the instructions in the guide and I finally got Avast antivirus installed on the laptop but was not able to update it as the system would not let it connect to the web site, I ran a boot scan and it did not find anything, then I was able to update the virus scanner and ran a scan and it found 5 or 6 infections which I placed in the chest, then I installed the cc cleaner and ran it and then I could not connect to have it analyzed so the log is gone, now the computer is so slow that it takes about 20 minutes to get to my desktop, and the control panel will not open, when I click on control panel I get a silhouette of the window and the rest is invisible then it closes on its own, also it keeps closing and locking the user after less than 60 seconds, I am so frustrated and confused I don't know what to do now, Please help!! Irven  You have to produce some logs....try running them in safe mode and/or when you save the programs rename them , For example...test.exe or sniper.exe...this will allow the programs to fool the virus.......this may enable you to run them and produce logs for analysis...........You may even have to download the programs to a USB drive and transfer them to the infected pc......Calm down, relax, and someone will get you up and running,,,,Thank you Karnac for your post, I am sorry I did not see it until now as when I posted in this section I neglected to click on notify of posts, But I did make some headway as I was finally able to open the control panel by going through the windows explorer and was able to delete some of the malware using the rogue tool list, As far as starting in safe mode I cannot get past the loading of the files as it sets there for hours and I have to shut it down. I ran the virus scan again and it did not find anything so I tried to back up all of the files that I need to save to my external hard drive but after about 2 hours it failed and the window said that it could not find file 0x80070002, I have no idea what it is, I tried backing up just one file to see if maybe the missing file was in one of the other files but now matter what file I try to back up I get the same error list the same missing file, Also I did get it so that it no longer shuts down every 60 seconds, so that help a lot, It is still very slow booting,(takes about 20  to 30 minutes to reach the desktop).Problems this serious are often hard to fix.  In some cases, it can't be fixed at all without someone actually PHYSICALLY accessing your computer.  Even then, there's no guarantee.  I'm just giving you this warning so you are prepared.

I know you are having many issues with your computer, but is there any chance you can get a HijackThis log posted on here?  It could really help give us an idea of what's lurking around on your computer.  Additional tools will be needed later, but let's just focus on this for now, as it's one of the simpler steps.As of today the computer will not boot, I get the error  windows\system32\winload.exe cannot load, the selected entry could not be loaded because the APPLICATION is missing or corrupt, I tried the Toshiba's recovery disc and get a error 10-FC12-045D I do not know what that means but I cannot get it to boot, I am almost ready to give up  I can't be entirely certain, but you may actually have a faulty hard drive.  It could be a physical problem or could be a matter of boot files missing.  I would strongly urge you to run a drive diagnostic utility, but if you're having that much trouble booting, it may not work even if run from a boot disk.  If you'd like to try, someone here can surely give you easy steps to follow.  I personally don't have enough experience with this to feel comfortable with guiding you through it.


If you want to reformat, you can try DBAN: http://www.dban.org/about

Just keep in mind that all files on your computer will be gone.  HOWEVER, it's hard to say if they are even still there as we speak.  I would suggest trying out the diagnostic utility before deciding to reformat.  You can make a new post in the Software or Windows section and let them know that I suggested checking for drive errors.  Somebody should be able to help set you up.CBmat, I have downloaded the boot disc from the link you provided but I dont know if I will be able to reinstall windows Vista as I only have the recovery disc,  Please advise if this will work.Have you tried my first suggestion of getting appropriate steps for the diagnostic utility?  I would try that first, just to see if it FINDS anything.

Unfortunately, I can't really answer your question 100% because every manufacturer is different.  Recovery discs will usually reinstall Windows for you.  However, there are some that only repair system files.  Yours should install Windows for you, but you may want to call Toshiba and ask them first, as I don't know what their standard practice is.

Also, keep in mind that there's a chance this won't help ANYWAY.  Your hard drive could be failing physically, which would mean that it is basically dying.  That's why I think running a diagnostic first would be a good idea.I want to thank all who tried to help me with this problem,  I got a copy of Windows vista installation disc and installed a second copy of Vista on my laptop then deleted the default copy and now all is great, everything is working fine   Great, I'm glad to hear that everything is working fine.  I was concerned that it may have been a physical problem, but it sounds like you probably just had a corrupt boot sector.  In any case, I'm happy that you are up and running again.  And now, make sure you get a good anti-virus and firewall installed immediately!  Avast and AVG are both good free anti-virus, and Comodo and ZoneAlarm are good free firewalls.Thank you,  I have installed Avast so I think I will be fine now  Good to hear.  I would still suggest getting a firewall, however.  Vista is a bit more protected than XP, but I don't trust the Vista Firewall.  Heh.  But it's ultimately up to you, I suppose.

To learn more about how to protect yourself while on the internet, read this article by Tony Klein: So how did I get infected in the first place?Thank you for the link, it has a lot of helpful information that I would have had trouble finding, I have installed the super anti spyware for protection, I am still trying to decide what firewall to use. Again thanks for all of your time and effort, it sure helpedYou're very welcome.  Let's not see you back in here anytime soon!

1339.

Solve : cant navigate windows?

Answer»

If you are using the FREE version of SUPERANTISPYWARE, real-time protection isn't available.  At this POINT, it would probably be easier to just close the programs.  Go AHEAD and disable Avast LIKE you did before, then close it.  Then, for SAS, just exit the program rather than trying to disable it.  Even if ComboFix gives you a warning about it, it shouldn't interfere because its real-time protection is turned off.  ComboFix just sees that the program is PRESENT, even if it is disabled.

1340.

Solve : Don't know how to remove this bug. I've done research! SASW, MBAM & HJT logs!?

Answer»

This STARTED because I'm unable to access Internet Options in any way.
No Spybot, and Internet Options is not available in Control Panel either, it shows the icon, however the name is blank and when clicked it gives the same result as trying the Start:Run:inetcpl.cpl trick.
I am also unable to RIGHT click anywhere in IE, (I believe this is 8, unable to access the drop down menus either!)
Anyways, back to Internet Options, I went to restore the inetcpl.cpl file... guess what: it's GONE. So is the backup location and the entire win\sys32\dllcache directory!!!  So at this point I got nervous.  I tried SFC /scannow and it says my CD is the wrong version of xp pro.

I found viruses using AVG yet they kept coming back. I came here, downloaded the step by step process and followed it.

So here I am (on a different pc, as I'm unable to post the logs from the sick one), very afraid! 

ADDED: 09-10-07: I did try the Java update, it allows internet access, even followed the link to update Java, but the "Download Java" button just causes a quick blink of the screen and then nothing.  This thing gives me the heebiejeebies LOL!
I am not trying to bump my post, I do see that people who posted after me have replies but maybe this is a tough one? Even a little hint as to which direction to go would be appreciated.  I will continue to do the Self Help scanner, It did find a malicious process in the HJT log - the facebookphotouploader  thing in blue - but I was waiting as I didn't want to do something and then have someone come along to help and it mess them up! After looking this over I do not understand how to remove the facebook thing.  So... back to waiting

Logs follow:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/06/2009 at 01:00 PM

Application Version : 4.29.1002

Core Rules Database Version : 4148
Trace Rules Database Version: 2077

Scan type       : Complete Scan
Total Scan Time : 00:43:00

Memory items scanned      : 469
Memory threats detected   : 0
Registry items scanned    : 5420
Registry threats detected : 0
File items scanned        : 44214
File threats detected     : 3

Trojan.Agent/Gen
   C:\WINDOWS\system32\A.TMP
   C:\WINDOWS\system32\B.TMP

Trojan.Agent/Gen-Dropper[Temp]
   C:\WINDOWS\SYSTEM32\9.TMP

Malwarebytes' Anti-Malware 1.41
Database version: 2916
Windows 5.1.2600 Service Pack 3

10/6/2009 2:17:44 PM
mbam-log-2009-10-06 (14-17-44).txt

Scan type: Quick Scan
Objects scanned: 100595
Time elapsed: 4 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{231f6fab-eced-4975-9ef2-c0c7bc81927b} (Adware.AdSponsor) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HIJACKTHIS v2.0.2
Scan saved at 2:27:18 PM, on 10/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\desksite\bin\cma.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DE83E0A-4065-4D93-8D7C-690A8A8C9A40}: NameServer = 10.150.1.10,10.150.1.11
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

--
End of file - 7584 bytes

Thank you very much in advance for your time, I have tried not to be wasteful or ignorant, and have spent about a day reading and researching, trying out every logical next step I could find... I'm Lost
Blessings,
MBooted to WinXP Pro CD. Ran CHKDSK /R - this restored the inetcpl.cpl file and several others that were missing when I tried to uninstall IE8.

Found a post on another site stating that there are multiple inetcpl.cpl files on a search and that the smaller ones actually work... so I searched.

inetcpl.cpl = 350 kb or 353 kb both bring up Internet Options just fine. These are located in the c\win\IE7 dir and c\win\sftwr distro\cf8ec... folder respectively.

inetcpl.cpl = 1,788 kb cause the flash and nada.  Incidently if I copy the 350 kb ver into win\sys32 then the shortcut from Control Panel works... if I click one of the others it overwrites the 350 in Sys32...
(and, incidently the source file inetcpl.cpl.mui are both 1,244 kb)

So, IE7 works, yet there's this file that seems to be somehow evading all attempts to overcome.  I am not going to re-install IE8 on possibility that it is more vulnerable.
*shrug* I stumped.  I will try the self-help some more...

10-12-09  Still no response or contact other than some newbie flipping crap.
Since 20+ posts above me have responses, I get the hint.
g'luck all,
Maj out.
Bumping your thread just made it longer before help comes.

1341.

Solve : Virus - malware help.?

Answer»

So I discovered that I had a virus by trying to play Starcraft : Broodwar. I couldnt connect to battle.net and the error message I got told me that I needed to reinstall SC (which I did) and if it didnt work, it might because I had a virus. So I scanned with Ad-Aware which gave me a bunch of malwares as result (win32 stuff, you'll get more info later). It deleted them all and we I rebooted, it wasnt loading my session and I was GETTING error messages. After a few REBOOTS I finally reached my desktop with this error message :


Yes its in french (I'm french-canadian so forgive my sloppy english), and it means that MOM.exe couldnt load PROPERLY (0xc000007b).

Then my avast started giving me these warnings :



So I came here and got all the logs for you guys :

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/07/2009 at 07:36 PM

Application Version : 4.26.1002

Core Rules Database Version : 3838
Trace Rules Database Version: 1794

Scan type       : Complete Scan
Total Scan Time : 00:45:02

Memory items scanned      : 661
Memory threats detected   : 0
Registry items scanned    : 6375
Registry threats detected : 0
File items scanned        : 27008
File threats detected     : 7

Adware.Tracking Cookie
   C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
   C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
   C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
   C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt
   C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt
   C:\Documents and Settings\LocalService\Cookies\[email protected][3].txt
   C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:46:26, on 2009-10-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Shareware.Pro-EN Toolbar - {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - C:\Program Files\Peer2Peer-EN\tbPee1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Shareware.Pro-EN Toolbar - {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - C:\Program Files\Peer2Peer-EN\tbPee1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Shareware.Pro-EN Toolbar - {da21bd13-ca22-42e3-a071-98f08f1ca1e7} - C:\Program Files\Peer2Peer-EN\tbPee1.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [lifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [HPWUTOOLBOX] C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe "-i"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ter8m] RUNDLL32.EXE C:\WINDOWS\system32\msxm192z.dll,w
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Documents and Settings\Owner\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4C833081-D026-4FF8-968F-7EAB660D2FBA} (TVAnts ActiveX Control) - http://download.tvants.com/pub/tvants/tvants1/win32/cab/tvants.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate1c9fa73ff021c62) (gupdate1c9fa73ff021c62) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS

--
End of file - 10889 bytes


This is the first malwarebyte log :

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3

2009-10-07 20:22:41
mbam-log-2009-10-07 (20-22-37).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 80522
Time elapsed: 26 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\BtwSrv.dll (Trojan.Agent) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\btwsrv (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\BtwSrv.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\1VOL9AAC\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SSWL1JPP\w[1].bin (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SSWL1JPP\w[3].bin (Backdoor.Bot) -> No action taken.


Then after quarantine, delete and reboot and seeing that my problem wasnt fixed I scanned again :

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3

2009-10-07 20:50:06
mbam-log-2009-10-07 (20-50-03).txt

Scan type: Quick Scan
Objects scanned: 115959
Time elapsed: 15 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 9
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\msxm192z.dll (Trojan.Agent) -> No action taken.

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe (Security.Hijack) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe (Security.Hijack) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ter8m (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> No action taken.

Files Infected:
C:\WINDOWS\Temp\VRTB9.tmp (Malware.Tool) -> No action taken.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\msxm192z.dll (Trojan.Agent) -> No action taken.


And even after all of those, when I rebooted, I got the same error message as the beginning and another one that said that C:\WINDOWS\system32\msxm192z.dll couldnt run properly.

Thanks in advance for your help, I really need my Starcraft to work again, I got some important matches coming up soon .you need to delete your malware log , run it again and delete what it brings up , there was no action taken in the log you sent , you need to post a clean one

you have 2 problems in your hjt log but you will have to WAIT for an expert to help

i think the problem comes from your P2P I did delete, I guess the log was saved from before I deleted everything.

1342.

Solve : Cannot Run Adaware or HiJackThis?

Answer»

After installing adaware to try and deal with redirecting IE pages, I tried to run a scan of my computer.  It kicked me out of the program with no error message whatsoever in about 10 SECONDS.  When trying to REOPEN the program I get an error message "Failed to Connect to Service".  My internet connection how ever is fine.  I then downloaded HiJackThis and tried to give that a run, same issue.  It kicked me out of the prorgam with no error message and when trying to open it up again i get this error message "Windows cannot access the specified devide, PATH, or file.  You may not have the appropriate permissions to access the item."  Yet theres only one profile on this computer.  Im LOST.  Help anyone?

ChrisInstead of AdAware try either MalwareBytes or Super AntiSpyware. If no luck, try running from Safe Mode.Some malware/spyware prevents anti-malware/spyware from opening. Try renaming the exe file for ad-Aware.If it's particularly tricky, you may need to try both of the above suggestions.

1343.

Solve : I've been attacked! Malwarebytes no longer working. Please help?

Answer»

No worries; I understand.  Things are looking a little better, but one of the infections has SPREAD somewhat.  It's not doing a lot of damage right now, but we still want to get rid of it, of course.


Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
cgwc
fpinlgk
inyiqiv
lpvlpm
lqel
pjqefld
rpwlfydw
rxium
weolfr
xxgy

File::
c:\windows\Hdofuviyakidalos.dat
c:\windows\Jgilupewadag.bin
c:\windows\uyomodoruvoz.dll
c:\windows\system32\drivers\admvgxwb.sys
c:\windows\system32\drivers\xnpj.sys
c:\windows\system32\drivers\kcsmpoxa.sys
c:\windows\system32\drivers\sqxof.sys
c:\windows\system32\drivers\hflfdgs.sys
c:\windows\system32\drivers\gczmyi.sys
c:\windows\system32\drivers\mfmbtf.sys
c:\windows\system32\drivers\qjnb.sys
c:\windows\system32\drivers\fqff.sys
c:\windows\system32\drivers\bwnabzzh.sys

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kbozaqawicoziqow"=-

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After REBOOT (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply, along with a new HijackThis log.

Note: Do not click ComboFix's window while it is running. That may cause your system to freezeOk CBMatt, here is the new Combo log

ComboFix 09-10-04.01 - Mike 10/05/2009 19:34.3.4 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3323.2758 [GMT -4:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}

FILE ::
"c:\windows\Hdofuviyakidalos.dat"
"c:\windows\Jgilupewadag.bin"
"c:\windows\system32\drivers\admvgxwb.sys"
"c:\windows\system32\drivers\bwnabzzh.sys"
"c:\windows\system32\drivers\fqff.sys"
"c:\windows\system32\drivers\gczmyi.sys"
"c:\windows\system32\drivers\hflfdgs.sys"
"c:\windows\system32\drivers\kcsmpoxa.sys"
"c:\windows\system32\drivers\mfmbtf.sys"
"c:\windows\system32\drivers\qjnb.sys"
"c:\windows\system32\drivers\sqxof.sys"
"c:\windows\system32\drivers\xnpj.sys"
"c:\windows\uyomodoruvoz.dll"
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Hdofuviyakidalos.dat
c:\windows\Jgilupewadag.bin
c:\windows\uyomodoruvoz.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CGWC
-------\Legacy_FPINLGK
-------\Legacy_INYIQIV
-------\Legacy_LPVLPM
-------\Legacy_LQEL
-------\Legacy_PJQEFLD
-------\Legacy_RPWLFYDW
-------\Legacy_RXIUM
-------\Legacy_WEOLFR
-------\Legacy_XXGY
-------\Service_cgwc
-------\Service_fpinlgk
-------\Service_inyiqiv
-------\Service_lpvlpm
-------\Service_lqel
-------\Service_pjqefld
-------\Service_rpwlfydw
-------\Service_rxium
-------\Service_weolfr
-------\Service_xxgy


(((((((((((((((((((((((((   Files Created from 2009-09-05 to 2009-10-05  )))))))))))))))))))))))))))))))
.

2009-10-05 23:33 . 2009-10-05 23:34   --------   d-----w-   C:\32788R22FWJFW
2009-09-27 21:55 . 2009-09-27 21:55   --------   d-----w-   c:\documents and settings\Heather\Local Settings\Application Data\{7C57F359-DCD5-4829-A18F-24C46AF9A74E}
2009-09-27 00:01 . 2009-09-27 00:01   --------   d-----w-   c:\documents and settings\Mike\Local Settings\Application Data\Citrix
2009-09-27 00:01 . 2009-09-27 00:01   103720   ----a-w-   c:\documents and settings\Mike\GoToAssistDownloadHelper.exe
2009-09-25 18:00 . 2009-09-25 18:00   --------   d-----w-   C:\My Music
2009-09-25 17:00 . 2009-09-25 17:00   --------   d-----w-   c:\program files\Common Files\xing shared
2009-09-25 17:00 . 2009-09-25 17:00   --------   d-----w-   c:\program files\real
2009-09-23 04:43 . 2009-09-10 18:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-23 04:43 . 2009-09-23 04:43   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-09-23 04:43 . 2009-09-10 18:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-09-23 04:12 . 2009-09-23 04:12   --------   d-----w-   c:\documents and settings\Mike\Local Settings\Application Data\{13185E59-E9FA-4277-B5BA-D271999892E3}
2009-09-22 06:36 . 2009-09-22 06:36   --------   d-----w-   c:\program files\Trend Micro
2009-09-22 05:22 . 2009-09-22 05:22   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-22 05:22 . 2009-09-23 04:31   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-09-22 05:22 . 2009-09-22 05:22   --------   d-----w-   c:\documents and settings\Mike\Application Data\SUPERAntiSpyware.com
2009-09-20 18:26 . 2009-09-20 18:26   --------   d-----w-   c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-09 08:00 . 2009-06-21 21:44   153088   -c----w-   c:\windows\system32\dllcache\triedit.dll
2009-09-05 23:45 . 2009-09-05 23:45   --------   d-----w-   c:\documents and settings\Mike\Application Data\YouSendIt
2009-09-05 23:45 . 2009-09-05 23:45   --------   d-----w-   c:\program files\YouSendIt
2009-09-05 23:44 . 2009-09-05 23:44   --------   d-----w-   c:\windows\Downloaded Installations
2009-09-05 23:44 . 2009-09-05 23:44   --------   d-----w-   c:\program files\WinPcap
2009-09-05 23:43 . 2009-09-05 23:43   --------   d-----w-   c:\windows\Replay Converter 3
2009-09-05 23:43 . 2009-09-11 08:13   --------   d-----w-   c:\program files\Replay AV 8

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-05 23:26 . 2008-11-06 22:04   --------   d-----w-   c:\documents and settings\All Users\Application Data\Google Updater
2009-10-05 01:23 . 2008-11-02 20:26   189184   ----a-w-   c:\windows\system32\PnkBstrB.exe
2009-10-05 00:25 . 2009-01-10 16:38   138064   ----a-w-   c:\windows\system32\drivers\PnkBstrK.sys
2009-09-25 17:00 . 2009-03-09 08:34   --------   d-----w-   c:\program files\Common Files\Real
2009-09-25 17:00 . 2003-03-19 00:14   499712   ----a-w-   c:\windows\system32\msvcp71.dll
2009-09-22 05:53 . 2008-10-20 07:49   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-09-19 22:53 . 2008-02-06 16:42   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-09-18 18:40 . 2009-09-20 16:47   20780477   ----a-w-   c:\program files\PROCESSLIST.DB
2009-09-18 18:40 . 2009-09-20 16:47   1230109   ----a-w-   c:\program files\PROCESSLISTRELATED.DB
2009-09-11 08:16 . 2009-06-01 04:56   --------   d-----w-   c:\program files\iWin Games
2009-09-05 23:45 . 2008-11-09 17:50   --------   d-----w-   c:\program files\Replay Music 3
2009-09-05 23:40 . 2008-08-28 21:11   323584   ----a-w-   c:\windows\system32\AUDIOGENIE2.DLL
2009-08-21 20:34 . 2008-08-03 05:06   --------   d-----w-   c:\program files\Common Files\DVDVideoSoft
2009-08-21 20:34 . 2008-08-03 05:06   --------   d-----w-   c:\program files\DVDVideoSoft
2009-08-07 07:13 . 2008-06-04 01:41   --------   d-----w-   c:\documents and settings\Mike\Application Data\LimeWire
2009-08-05 09:01 . 2008-02-05 22:39   204800   ----a-w-   c:\windows\system32\mswebdvd.dll
2009-07-29 03:40 . 2009-01-10 16:37   75064   ----a-w-   c:\windows\system32\PnkBstrA.exe
2009-07-17 19:01 . 2008-02-05 22:39   58880   ----a-w-   c:\windows\system32\atl.dll
2009-07-14 03:43 . 2008-02-05 22:39   286208   ----a-w-   c:\windows\system32\wmpdxm.dll
2008-08-11 05:08 . 2008-08-11 05:08   978396   ----a-w-   c:\program files\BDAXP.cab
2008-06-30 17:44 . 2008-08-30 06:45   324976   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-08-13 23:02 . 2008-08-13 23:02   35840   ----a-w-   c:\program files\mozilla firefox\components\FFComm.dll
.

(((((((((((((((((((((((((((((   [email protected]_06.20.05   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-16 20:58 . 2009-09-23 12:17   57344              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\texticon.exe
- 2008-09-16 20:58 . 2009-08-07 15:48   57344              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\texticon.exe
- 2008-09-16 20:58 . 2009-08-07 15:48   22486              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\register_icon.exe
+ 2008-09-16 20:58 . 2009-09-23 12:17   22486              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\register_icon.exe
+ 2008-09-16 20:58 . 2009-09-23 12:17   32768              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\maintenance_icon.exe
- 2008-09-16 20:58 . 2009-08-07 15:48   32768              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\maintenance_icon.exe
+ 2008-09-16 20:58 . 2009-09-23 12:17   61440              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\helpicon.exe
- 2008-09-16 20:58 . 2009-08-07 15:48   61440              c:\windows\Installer\{5DF86878-462F-41F2-96E0-E82EE57EC7D3}\helpicon.exe
+ 2009-09-25 17:00 . 2009-09-25 17:00   5632              c:\windows\system32\pndx5032.dll
- 2009-03-09 08:34 . 2009-03-09 08:34   5632              c:\windows\system32\pndx5032.dll
- 2009-03-09 08:34 . 2009-03-09 08:34   6656              c:\windows\system32\pndx5016.dll
+ 2009-09-25 17:00 . 2009-09-25 17:00   6656              c:\windows\system32\pndx5016.dll
+ 2009-09-25 17:00 . 2009-09-25 17:00   185920              c:\windows\system32\rmoc3260.dll
- 2009-03-09 08:34 . 2009-03-09 08:34   185920              c:\windows\system32\rmoc3260.dll
- 2009-03-09 08:34 . 2009-03-09 08:34   278528              c:\windows\system32\pncrt.dll
+ 2009-03-09 08:34 . 2009-09-25 17:00   278528              c:\windows\system32\pncrt.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2008-08-15 716800]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-08-11 69632]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-25 198160]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Mike\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"VSSERV"=2 (0x2)
"NVSvc"=2 (0x2)
"NMIndexingService"=3 (0x3)
"mi-raysat_3dsMax2009_32"=2 (0x2)
"LIVESRV"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iWinTrusted"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=2 (0x2)
"FlipShare Service"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Autodesk Licensing Service"=2 (0x2)
"Arrakis3"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"aliasdocserver"=2 (0x2)
"Adobe Version Cue CS3"=3 (0x3)
"Adobe LM Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Adobe\\After Effects 6.5\\Support Files\\AfterFX.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\discreet\\cleaner XL\\cleaner XL.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Adobe After Effects CS3\\Support Files\\AfterFX.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"c:\\Program Files\\Alias\\Maya6.0\\bin\\mayabatch.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [8/12/2008 6:40 PM 111112]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [7/17/2008 1:06 PM 118784]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
S4 aliasdocserver;Alias Documentation Server;c:\program files\Alias\Maya6.0\docs\Wrapper.exe [8/7/2008 3:29 PM 110592]
S4 FlipShare Service;FlipShare Service;c:\program files\Pure Digital Technologies\FlipShare\FlipShareService.exe [11/13/2008 2:17 PM 439616]
S4 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [3/10/2008 12:04 AM 65536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx   REG_MULTI_SZ      scan

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled TASKS' folder

2009-10-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-06 06:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Block This Image (ABP) - c:\program files\Adblock Pro\blockimg.html
IE: Add to  Evernote - c:\program files\Evernote\Evernote3\enbar.dll/2000
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Save YouTube Video - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {{E7FD3540-AB30-40f1-91E7-101F733C1FD5} - {7685B225-8229-4321-BA13-A24485B0A760} - c:\program files\Adblock Pro\AdblockPro.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\wikb88jo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - component: c:\program files\Evernote\Evernote3\FfTbClipper\components\enbar3.dll
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Java\jre6\bin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre6\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre6\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre6\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre6\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre6\bin\npjpi160_05.dll
FF - plugin: c:\program files\Java\jre6\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {13185E59-E9FA-4277-B5BA-D271999892E3} - c:\documents and settings\Mike\Local Settings\Application Data\{13185E59-E9FA-4277-B5BA-D271999892E3}
FF - HiddenExtension: XULRunner: {7C57F359-DCD5-4829-A18F-24C46AF9A74E} - c:\documents and settings\Heather\Local Settings\Application Data\{7C57F359-DCD5-4829-A18F-24C46AF9A74E}\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware DETECTOR by Gmer, http://www.gmer.net
Rootkit scan 2009-10-05 19:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:b5,fe,1f,11,e2,04,7e,b7,fc,0a,c1,20,08,71,d0,02,df,f4,be,19,54,
   08,cb,c2,b3,08,e8,0c,49,3f,c1,02,bf,77,83,4c,ab,64,df,fe,0c,9f,86,a3,db,7d,\

[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:32,49,1f,c5,b7,af,7b,ea,03,22,52,c7,8a,2e,ee,06,b4,cf,43,6a,0e,
   62,7f,57,c9,4e,21,1c,11,d6,1f,1d,93,a9,eb,25,94,7e,07,96,d6,a8,ad,db,1b,65,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3024)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\BitDefender\BitDefender 2009\vsserv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\searchindexer.exe
c:\program files\BitDefender\BitDefender 2009\seccenter.exe
.
**************************************************************************
.
Completion time: 2009-10-05 19:47 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-05 23:46
ComboFix2.txt  2009-09-23 04:39
ComboFix3.txt  2009-09-22 06:26

Pre-Run: 631,884,476,416 bytes free
Post-Run: 631,833,182,208 bytes free

310   --- E O F ---   2009-09-11 04:23
And here is the new HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:52:47 PM, on 10/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O8 - Extra context menu item: &Block This Image (ABP) - C:\Program Files\Adblock Pro\blockimg.html
O8 - Extra context menu item: Add to  Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save YouTube Video - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Adblock Pro Preferences - {E7FD3540-AB30-40f1-91E7-101F733C1FD5} - C:\Program Files\Adblock Pro\AdblockPro.dll
O9 - Extra 'Tools' menuitem: Adblock Pro Preferences - {E7FD3540-AB30-40f1-91E7-101F733C1FD5} - C:\Program Files\Adblock Pro\AdblockPro.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://www.yougamers.com/systeminfo/MSC3.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Packet CAPTURE Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 8486 bytes
Great, that looks much better!  Judging by what I can see in these logs, you look clean.  Is everything still running smoothly?  If so, go ahead and uninstall ComboFix.  You can do that by going to Start > Run, typing in combofix /u (note the space before "/u"), and clicking OK.  You can also remove HijackThis.

You should also reset and re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files.  This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

1. Turn off System Restore.

  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.

    2. Restart your computer.

    3. Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore.
  • Click Apply, and then click OK.
    System Restore will now be active again.


    Once you've done that, you are good to go.
Ok I deleted the Combo fix and HiJackThis, and did the System Restore.
Thank you very very much Matt, and yes my computer has never felt more smooth- it feels like new, what an awesome feeling right? (whew!)

Take care and god bless,

Mike.Fantastic, I'm glad everything is going well.  Take care!
1344.

Solve : Need help please. Unknown Infection?

Answer»

Tried almost EVERYTHING. But, throwing the DANG thing out the WINDOW. Anyway heres the requested logs. Thanks in advance.

[Saving space, attachment deleted by admin]

1345.

Solve : AVG WILL NOT INSTALL PLEASE HELP?

Answer»

i have unistalled AVG and trying to install again, i am geting this messege :
"Action failed for file avgcsrvx.exe: creating file....      Specified file was not found."

i have seen other posts on this site and have run dds this is the output :
dds.txt:

DDS (Ver_09-07-30.01) - NTFSx86 
Run by dr victor balter at 16:08:08.90 on Fri 09/18/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1015.248 [GMT 3:00]

FW: Norton Internet Worm Protection *disabled*   {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program FILES\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\dr victor balter\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Picasa Media Detector] c:\documents and settings\dr victor balter\my documents\picasa2\PicasaMediaDetector.exe
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" -NoStart
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
IE: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} - hxxp://www.tapuz.co.il/irc/main/launcher.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows PRESENTATION foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S2 gupdate1c95d1655ed8364;Google Update Service (gupdate1c95d1655ed8364);c:\program files\google\update\GoogleUpdate.exe [2008-12-13 133104]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-6-21 66048]

=============== Created Last 30 ================

2009-09-18 15:12      --d-----   c:\windows\system32\Lang
2009-09-18 14:39   333,288   a-------   c:\windows\system32\sqlite3.dll
2009-09-12 13:40      --d-----   c:\program files\OctopUi
2009-09-09 07:14   153,088   -c------   c:\windows\system32\dllcache\triedit.dll
2009-08-19 21:01   91,136   ac------   c:\windows\system32\dllcache\kswdmcap.ax
2009-08-19 21:01   53,760   ac------   c:\windows\system32\dllcache\vfwwdm32.dll
2009-08-19 21:01   43,008   ac------   c:\windows\system32\dllcache\ksxbar.ax
2009-08-19 21:01   91,136   a-------   c:\windows\system32\kswdmcap.ax
2009-08-19 21:01   53,760   a-------   c:\windows\system32\vfwwdm32.dll
2009-08-19 21:01   43,008   a-------   c:\windows\system32\ksxbar.ax
2009-08-19 21:01   61,952   ac------   c:\windows\system32\dllcache\kstvtune.ax
2009-08-19 21:01   61,952   a-------   c:\windows\system32\kstvtune.ax
2009-08-19 20:56   57,344   a-------   c:\windows\ZSSnp211.exe
2009-08-19 20:56   49,152   a-------   c:\windows\Domino.exe
2009-08-19 20:56   1,469,312   a-------   c:\windows\system32\drivers\ZS211.sys
2009-08-19 20:56   172,115   a-------   c:\windows\system32\ZS211Prp.Ax
2009-08-19 20:56   172,032   a-------   c:\windows\amcap.exe
2009-08-19 20:56   81,920   a-------   c:\windows\system32\ZS211STI.dll
2009-08-19 20:56   77,824   a-------   c:\windows\ZS211Cap.exe
2009-08-19 20:56      --d-----   c:\program files\Vimicro

==================== Find3M  ====================

2009-08-05 12:01   204,800   a-------   c:\windows\system32\mswebdvd.dll
2009-07-17 22:01   58,880   a-------   c:\windows\system32\atl.dll
2009-07-13 23:43   286,208   a-------   c:\windows\system32\wmpdxm.dll
2009-07-03 20:09   915,456   a-------   c:\windows\system32\wininet.dll
2008-01-17 20:17   32   a-------   c:\docume~1\alluse~1\applic~1\ezsid.dat
2009-06-05 19:18   0   ---shr--   c:\windows\FFSSET.BIN
2008-11-28 12:54   32,768   a--sh---   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008112820081129\index.dat

============= FINISH: 16:08:29.18 ===============

attach.txt:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/17/2008 3:07:19 PM
System Uptime: 9/18/2009 3:12:05 PM (1 hours ago)

Motherboard: MSI |  | MS-7267
Processor: Intel(R) Pentium(R) Dual  CPU  E2160  1.80GHz | CPU 1 | 1795/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 128.991 GiB free.
D: is CDROM ()
E: is REMOVABLE

==== Disabled Device Manager Items =============

Class GUID:
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_2772&SUBSYS_72671462&REV_02\3&11583659&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_2772&SUBSYS_72671462&REV_02\3&11583659&0&10
Service:

==== System Restore Points ===================

RP447: 6/20/2009 6:49:05 PM - System Checkpoint
RP448: 6/21/2009 7:17:25 PM - System Checkpoint
RP449: 6/22/2009 9:50:19 PM - System Checkpoint
RP450: 6/23/2009 10:20:39 PM - System Checkpoint
RP451: 6/24/2009 9:08:42 AM - Avg8 Update
RP452: 6/25/2009 3:17:57 PM - System Checkpoint
RP453: 6/26/2009 4:09:27 PM - System Checkpoint
RP454: 6/27/2009 5:08:49 PM - System Checkpoint
RP455: 6/28/2009 5:55:33 PM - System Checkpoint
RP456: 6/29/2009 6:00:27 PM - System Checkpoint
RP457: 7/2/2009 10:09:17 AM - System Checkpoint
RP458: 7/3/2009 10:32:42 AM - System Checkpoint
RP459: 7/4/2009 10:40:31 AM - System Checkpoint
RP460: 7/6/2009 11:33:35 PM - System Checkpoint
RP461: 7/9/2009 6:59:11 PM - System Checkpoint
RP462: 7/10/2009 7:26:10 PM - System Checkpoint
RP463: 7/11/2009 9:30:41 PM - System Checkpoint
RP464: 7/12/2009 10:00:49 PM - System Checkpoint
RP465: 7/14/2009 9:50:43 AM - System Checkpoint
RP466: 7/15/2009 3:12:29 PM - System Checkpoint
RP467: 7/16/2009 1:15:10 AM - Software Distribution Service 3.0
RP468: 7/17/2009 10:12:00 AM - System Checkpoint
RP469: 7/18/2009 10:44:54 AM - System Checkpoint
RP470: 7/20/2009 11:23:18 AM - Avg8 Update
RP471: 7/20/2009 11:24:23 AM - Avg8 Update
RP472: 7/22/2009 3:22:41 PM - System Checkpoint
RP473: 7/23/2009 2:16:42 PM - Software Distribution Service 3.0
RP474: 7/24/2009 2:29:48 PM - System Checkpoint
RP475: 7/25/2009 2:39:28 PM - System Checkpoint
RP476: 7/26/2009 10:22:52 PM - System Checkpoint
RP477: 7/27/2009 10:05:38 PM - Removed Nero 7 Essentials
RP478: 7/27/2009 10:39:03 PM - Installed Nero 7 Essentials
RP479: 7/29/2009 10:10:33 AM - Software Distribution Service 3.0
RP480: 7/31/2009 10:54:36 AM - Software Distribution Service 3.0
RP481: 8/1/2009 11:42:05 AM - System Checkpoint
RP482: 8/2/2009 2:48:18 PM - System Checkpoint
RP483: 8/3/2009 5:14:40 PM - System Checkpoint
RP484: 8/4/2009 5:45:44 PM - System Checkpoint
RP485: 8/5/2009 5:52:53 PM - System Checkpoint
RP486: 8/6/2009 6:48:44 PM - System Checkpoint
RP487: 8/7/2009 8:24:22 PM - System Checkpoint
RP488: 8/8/2009 10:15:54 PM - System Checkpoint
RP489: 8/9/2009 12:46:26 AM - Software Distribution Service 3.0
RP490: 8/9/2009 8:58:07 AM - Printer Driver Microsoft XPS Document Writer Installed
RP491: 8/9/2009 10:15:43 AM - Software Distribution Service 3.0
RP492: 8/11/2009 9:21:19 AM - System Checkpoint
RP493: 8/13/2009 12:23:27 AM - Software Distribution Service 3.0
RP494: 8/14/2009 2:04:48 PM - System Checkpoint
RP495: 8/15/2009 2:15:37 PM - System Checkpoint
RP496: 8/16/2009 9:00:22 AM - Avg8 Update
RP497: 8/16/2009 9:01:43 AM - Avg8 Update
RP498: 8/17/2009 3:24:54 PM - System Checkpoint
RP499: 8/19/2009 8:22:34 AM - System Checkpoint
RP500: 8/19/2009 8:56:16 PM - Installed USB PC Camera(ZS0211)
RP501: 8/19/2009 9:01:50 PM - Unsigned driver install
RP502: 8/21/2009 12:57:30 AM - System Checkpoint
RP503: 8/22/2009 1:30:52 AM - System Checkpoint
RP504: 8/23/2009 4:03:11 PM - System Checkpoint
RP505: 8/24/2009 4:14:02 PM - System Checkpoint
RP506: 8/25/2009 4:22:14 PM - System Checkpoint
RP507: 8/26/2009 5:19:19 PM - System Checkpoint
RP508: 8/27/2009 12:47:15 AM - Software Distribution Service 3.0
RP509: 8/28/2009 2:28:04 PM - System Checkpoint
RP510: 8/29/2009 3:18:54 PM - System Checkpoint
RP511: 8/30/2009 4:05:41 PM - System Checkpoint
RP512: 8/31/2009 11:01:39 PM - System Checkpoint
RP513: 9/2/2009 10:30:45 AM - Software Distribution Service 3.0
RP514: 9/4/2009 9:34:58 AM - System Checkpoint
RP515: 9/5/2009 9:52:21 AM - System Checkpoint
RP516: 9/6/2009 10:28:36 AM - System Checkpoint
RP517: 9/7/2009 2:31:52 PM - System Checkpoint
RP518: 9/8/2009 3:01:30 PM - System Checkpoint
RP519: 9/9/2009 10:28:31 AM - Software Distribution Service 3.0
RP520: 9/10/2009 3:08:55 PM - System Checkpoint
RP521: 9/11/2009 7:24:46 PM - System Checkpoint
RP522: 9/13/2009 9:35:01 AM - System Checkpoint
RP523: 9/15/2009 8:45:02 AM - System Checkpoint
RP524: 9/16/2009 3:14:11 PM - System Checkpoint
RP525: 9/18/2009 11:28:27 AM - System Checkpoint
RP526: 9/18/2009 1:29:02 PM - Installed Google SketchUp Pro 7
RP527: 9/18/2009 1:37:50 PM - Removed Google SketchUp Pro 7
RP528: 9/18/2009 1:39:24 PM - Removed Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
RP529: 9/18/2009 2:02:31 PM - Removed Microsoft Visual C++ 2005 Redistributable
RP530: 9/18/2009 2:03:13 PM - Removed Microsoft SQL Server Compact 3.5 ENU
RP531: 9/18/2009 2:21:12 PM - Configured AVG 8.5
RP532: 9/18/2009 2:29:45 PM - Configured AVG 8.5
RP533: 9/18/2009 2:42:32 PM - Configured AVG 8.5
RP534: 9/18/2009 2:45:46 PM - Removed AVG 8.5
RP535: 9/18/2009 2:46:42 PM - Installed AVG 8.5
RP536: 9/18/2009 3:20:18 PM - Installed AVG 8.5
RP537: 9/18/2009 3:31:01 PM - Installed AVG 8.5

==== Installed Programs ======================

AAC Decoder
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
AutoUpdate
BookScan&Whiteboard Suite
Brother MFL-Pro Suite MFC-250C
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
Critical Update for Windows Media Player 11 (KB959772)
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
FaceFilter Studio Brother Edition
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
H.264 Decoder
Highlight Viewer (Windows Live Toolbar)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Image Zone Express
Java(TM) 6 Update 5
Java(TM) 6 Update 7
LightScribe  1.4.124.1
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft SQL Server Compact 3.5 Design Tools ENU
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Mozilla Firefox (2.0.0.16)
MSI Live Update 3
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6 Service Pack 2 (KB954459)
Need2Find Bar
Nero 7 Essentials
neroxml
OctopUI Loader
OLYMPUS Master 2
OLYMPUS muvee theaterPack
PaperPort Image Printer
Picasa 3
PokerStars
QuickTime
Realtek High Definition Audio Driver
ScanSoft PaperPort 11
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Skype™ 4.0
Smart Menus (Windows Live Toolbar)
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
USB PC Camera(ZS0211)
VC80CRTRedist - 8.0.50727.762
VLC media player 1.0.1
WebFldrs XP
Windows GENUINE Advantage Notifications (KB905474)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Favorites for Windows Live Toolbar
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
WinZip 11.1
XML Paper Specification Shared Components Pack 1.0
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar
YouSendIt Express

==== Event Viewer Messages From Past Week ========

9/18/2009 2:08:33 PM, error: SideBySide [59]  - Generate Activation Context failed for C:\Program Files\AVG\AVG8\avglvex.dll. Reference error message: The operation completed successfully. .
9/18/2009 2:08:18 PM, error: SideBySide [59]  - Generate Activation Context failed for C:\Program Files\AVG\AVG8\avgtray.exe. Reference error message: The operation completed successfully. .
9/18/2009 2:06:05 PM, error: SideBySide [59]  - Resolve Partial Assembly failed for Microsoft.VC80.MFC. Reference error message: The referenced assembly is not installed on your system. .
9/18/2009 2:06:05 PM, error: SideBySide [59]  - Generate Activation Context failed for C:\Program Files\AVG\AVG8\avgui.exe. Reference error message: The operation completed successfully. .
9/18/2009 2:06:05 PM, error: SideBySide [32]  - Dependent Assembly Microsoft.VC80.MFC could not be found and Last Error was The referenced assembly is not installed on your system.

==== End Of File ===========================
also attaching logs requested

[attachment deleted by admin]There's really not much going on in your logs.  Nothing I would be too concerned about.  However, I would suggest removing this entry via HijackThis:
O8 - Extra context menu item: &Search - hxxp://kl.bar.need2find.com/KL/menusearch.html?p=KL

Many people consider it to be malicious.  Simply locate it in HijackThis, close all other windows (especially Internet Explorer), and click on Fix Checked.


Although a useful program, AVG can be very finnicky sometimes and it does not like to uninstall properly, which causes problems when reinstalling it.  Try downloading and running AVG Remover:
http://www.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

That should remove all AVG files from your computer and registry.  Once the process is complete, try installing AVG again and see if it works.

1346.

Solve : Slowed to a Halt?

Answer»

Ok, yesterday I was on my computer when I noticed it started to slow. Now this is very odd as I have 4gbytes of RAM and a quad core running a 2.83GH/z. So thinking it just needed a good old shutdown I let if rest for the night. Now today on start-up my system froze/wouldn't respond on simple tasks like opening Task Manager, or calling the search function, oddly though calling Internet Explorer/Mozilla Firefox booted fast and smoothly, same with any process running to view or folders but anything that needs to use power or do anything to the system it would bog down. I'm running Windows Vista x32. I figured it was something small so I tried a bunch of the standard stuff, clearing temp, attempting to defrag, removing all of my third party start-up stuff, stopping all secondary services. The weird thing is that it start's up in ruffly 2-3min, but any task past that causes it to slow to a screeching halt, I waited five minutes just to get to the "CTRL ALT DEL" screen and then another five or more just to get up Task Manager. So any and all help is GREATLY appreciated. Also I noticed that the process "CMDAGENT.exe"(A process used by my firewall/antivirus Comodo) is using 50% of my processor power I have seen this before on another computer but never had the chance to fully investigate it before the hard drive was wiped, it did appear to be a virus as the cause. If you don't know what Comodo is it's a firewall/real time scanning antivirus. Please any help is welcomed! Thanks in advance!

Edit: Well I seem to have found the issue, the issue was cmdagent.exe, it was using all of my system resources. After stopping it from auto starting my system ran smooth, issue is now that I've done some searching and it seems that it can either mess up on it's own or a malware can do it. Trojan found "Trojan.Agent/Gen-PennyStockChaser". Along with a Malware.Packer that infected Comodo. So if you ever have this issue this is most likely the cause.

~~WARNING~~ This "fix" caused windows to blue screen on restart, restarting again how ever will "fix" the issue. Not sure why it does this.

Edit again: Well the underlying issue isn't resolved, Comodo(Firewall) will cause me to freeze. Also, it seems SuperANTISpyware &AMP; Malware Bytes cant update, they both return an error so I believe I'm still infected. Help would be appreciated!I would go into safemode delete everything that sas antispyware and MALWAREBYTES go into control panel and delete the two and reinstall them.

you COULD try these to speed it up so you can try to fix it faster you already did defrag just do the quick stuff
all the things i listed is for xp but i think some of it will work for vista but i wouldn't know were to look because i don't have vista


then run the antiviruses after this

1 disk defragment go to start then accessories then diskdefragment you can see if you need one before you do it by clicking the analyze

2 same place in start accesories then disk cleanup I usually check everything

3 go to all of your internet browsers and delete everything mosty just the cookies,      will speed it up like internet explorer it's tools then delete browsing HISTORY and in there you can delete cookies are whatever you want,  I will usually check everything

4 Ok xp has alot of visual effects that slows it down alot more than you might think this speeded up my computer quit a bit even after i did the stuff above ok to do this go to start all programs left click on my computer then properties then advanced then under performence click on settings then click on adjust for best performece don't worry NOTHING bad will happen
and uncheck everything
but your your computer will lose it's settings so your computer will look like windows 95 are 98 but you can change it afterwards but i don't i'll gladly sacrifice fancy looks for some more speed anyday but just going back to the xp look by left clicking on the desktop then properties shouldn't slow it down to much

5 ok now make sure everything on your computer you don't want is deleted

6 ok now some antiviruses with live protection can slow down a computer alot more than you think try avira and turn off live protection also download
malwarebytes and superantispyware these are good

7 there are some other things you could try besides antispyware and malware programs like registry cleaners try tweaknow regcleaner and eusing free registry cleaner from cnet you could also download smart defrag

8 ok go to run type in msconfig and under services and startup uncheck everything you don't want becarefull there are some things in there you want to have for your computer to run properly like in startup i can uncheck with my computer superantispyware  avgnt  readersl  teatimer realschred
qttask now in services you could also uncheck alot of things like with mine i can uncheck google updater service   windows cardspace  java quick starter
windows media player n  (sucurity center optional but i din't want it) also
avira antivir shceduler avira antivir guard google software updater and there are many more i have unchecked make sure you unchech all the things you don't want and not uncheck everything you need some of these things for windows to run properly on the internet if you don't know what each thing is google it and it will tell you what it is.



9 ok in mycomputer left click on c then properties and uncheck indexing service to index this disk for fast file searching this doesn't help for a faster computer and don't compress the disk to save space then click apply then ok

10 in my computer click on tools then folder options then view then uncheck automaticly search for network folders and printers



Thanks for the help, but I said screw it and decided to just install Windows 7. Everything is working beautifully now. Thanks anyways! Good luck to any one else that has this issue, I've read that installing a latter version of Comodo fixes this, but I never tried.

1347.

Solve : Have Virus or trojan need help.?

Answer»

I have spent the last several days trying to fix this and have even reinstalled windows but the problem is recurring.  It originally was the windows police pro virus but it seems to be worse.  Can anybody please help.  I will paste my LOGS below.

Also, when I first got the virus there were three porntube and nudetube icons that would appear on the desktop.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/06/2009 at 03:16 PM

Application Version : 4.26.1004

Core Rules Database Version : 3910
Trace Rules Database Version: 1854

Scan type       : Custom Scan
Total Scan Time : 02:00:54

Memory items scanned      : 490
Memory threats detected   : 0
Registry items scanned    : 5553
Registry threats detected : 0
File items scanned        : 262144
File threats detected     : 81

Adware.Tracking Cookie
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][2].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][2].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][2].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][2].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][2].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim\Cookies\[email protected][1].txt
   C:\Documents and Settings\Tim Brooks\Cookies\tim [email protected][2].txt
   C:\Documents and Settings\Tim Brooks\Cookies\tim [email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][3].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][3].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][4].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][3].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][3].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][4].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][2].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][8].txt
   C:\Program Files\Documents and Settings\Tim Brooks\Cookies\[email protected][9].txt
   C:\Program Files\Tim windows stuff\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Tim windows stuff\Tim Brooks\Cookies\[email protected][1].txt
   C:\Program Files\Tim windows stuff\Tim Brooks\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][3].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt
   C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt

Unclassified.Unknown Origin
   C:\DOCUMENTS AND SETTINGS\TIM\MY DOCUMENTS\TORRENT DOWNLOADS\CUCUSOFT MPEG MOV RM VB DIV XAVI TO DVD VCD SVCD CONVERTER PRO 7.07\KEYGEN.NFO

Trojan.Dropper/Gen
   C:\PROGRAM FILES\DOCUMENTS AND SETTINGS\TIM BROOKS\LOCAL SETTINGS\TEMP\~.EXE

Trojan.Dropper/SVCHost-Fake
   C:\PROGRAM FILES\TIM WINDOWS STUFF\TIM BROOKS\LOCAL SETTINGS\TEMP\SVCHOST.EXE

Trojan.Agent/Gen-NumTemp
   C:\WINDOWS\SYSTEM32\9.TMP


Malwarebytes' Anti-Malware 1.41
Database version: 2910
Windows 5.1.2600 Service Pack 2

10/6/2009 4:19:13 PM
mbam-log-2009-10-06 (16-19-13).txt

Scan type: Quick Scan
Objects scanned: 162852
Time ELAPSED: 4 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 6
Registry Values Infected: 6
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\BtwSrv32.dll (Backdoor.Bot) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BtwSrv (Trojan.Agent) -> QUARANTINED and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_BTWSRV (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetLogin (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\isasdk (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\btwsrv (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\btwsrv (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mfa (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\9.tmp (Trojan.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\isasdk.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\BRC50AH0\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\E00BW7U3\w[1].bin (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Tim\Local Settings\Temporary Internet Files\Content.IE5\772GOXBO\ssv[1].txt (Trojan.Banker) -> Quarantined and deleted successfully.
C:\WINDOWS\sv3.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\isvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\BtwSrv32.dll (Backdoor.Bot) -> Delete on reboot.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:28 PM, on 10/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\FastNetSrv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SMCWUSB-G 802.11g Wireless USB Utility.lnk = C:\Program Files\SMC\SMCWUSB-G 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&END to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: fastnetsrv  Service (fastnetsrv) - Sigma Designs In - C:\WINDOWS\system32\FastNetSrv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Net Login (NetLogin) - Unknown owner - C:\WINDOWS\svchost.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe

--
End of file - 6496 bytes
what anti-virus have you got Super Anti Spyware, malware bytes, Spyware Dr. they are not anti-virus do you have any of the one's below

avast
avira
avg
comodo
mcafee
norton
panda
kasperky


if you do not have , d/load one from below and run


http://www.free-av.com/ , avira is free

http://www.avast.com/ , avast is free


=============================================

also remove spyware dr , you have the best with Super Anti Spyware , you do not need 2






I am afraid you might have a virus called virut, virut is a very bad virus that modifies everything running. you might have to reformat your pc. I am going to contact evil for confirmation. http://www.threatexpert.com/report.aspx?md5=36629ac4a97cf577fb4bb8f7a3c8d8ea Quote from: cat-bomb on October 07, 2009, 02:49:46 PM

I am afraid you might have a virus called virut, virut is a very bad virus that modifies everything running. you might have to reformat your pc. I am going to contact evil for confirmation. http://www.threatexpert.com/report.aspx?md5=36629ac4a97cf577fb4bb8f7a3c8d8ea

please tell me what makes you think thatO23 - Service: Net Login (NetLogin) - Unknown owner - C:\WINDOWS\svchost.exe
http://www.systemlookup.com/O23/2068-svchost_exe_k_NetLogon.htmli have been looking for a site like that , thank you , do you know any more
1348.

Solve : Laptop still running slowly - rootkit??

Answer»

Hey,

 I realised I had a problem when I attempted to start Windows Vista, but I couldn't get past the 'welcome' screen. The screen hadn't frozen (the loading circle was still spinning) but after waiting for some time it wouldn't start. I ran in safe mode, ran avast and showed I had a rootkit win32:Alureon-CY in my operating memory, so I ran a boot time scan.

 It supposedly got rid of it, but since my laptop has still been running a lot slower, so I followed your guidelines (which were by far the most useful I could find online - thanks!) and have the copies of the three logs below. Please advise, I'd be extremely grateful for any help!

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/18/2009 at 12:35 PM

Application Version : 4.28.1010

Core Rules Database Version : 4107
Trace Rules Database Version: 2047

Scan type       : Custom Scan
Total Scan Time : 17:45:25

Memory items scanned      : 965
Memory threats detected   : 0
Registry items scanned    : 6865
Registry threats detected : 10
File items scanned        : 2210718
File threats detected     : 2

Trojan.Agent/Gen-Downloader[Packed]
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}\InprocServer32
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}\InprocServer32#ThreadingModel
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}\ProgID
   HKCR\CLSID\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}\TypeLib
   HKCR\glok
   HKCR\TypeLib\{1ABA6D39-508C-483C-8466-9A9E69BC708F}
   C:\WINDOWS\SYSTEM32\YXHL0.DLL
   HKU\S-1-5-21-3356350433-2492298019-641508283-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3D409DF-0316-4FC0-89E2-DBDD885232A0}
   YXHL0.DLL


--------------------


Malwarebytes' Anti-Malware 1.41
Database version: 2819
Windows 6.0.6001 Service Pack 1

18/09/2009 12:58:07
mbam-log-2009-09-18 (12-58-07).txt

Scan type: Quick Scan
Objects scanned: 84657
Time elapsed: 2 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\kt_bho.KettleBho (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\BN (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D1 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D2 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D3 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\gd (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\pr (Trojan.Ambler) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\gasfkybxoqqocc.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\gasfkyvphklrci.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\gasfkyxxwuqpig.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\gasfkytevcynvs.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Windows\System32\gasfkyuijvmetw.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.


---------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:13:53, on 18/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Sony\VAIO Reminder\VAIOReminder.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: TWAP - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\TWAP.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: VAIO ENTERTAINMENT TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: WPLJQNI - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\WPLJQNI.exe (file missing)

--
End of file - 10599 bytes

You've got a fun one...

First, do the following...
Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

  • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
  • Then search for TDSSserv.sys
  • Let me know if you find this or not.
  • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
  • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.



Then follow these steps...
Please print these instructions as they will be needed later when Internet access is not available.
 
Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/156236231/SDFix.exe.html

When using this tool, you must use the Administrator's account or an account with Administrative rights

  • Double-click SDFix.exe and it will extract the files to %systemdrive% (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears), press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double-click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished.  Press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply.
Thanks for looking at the logs and advising - it's appreciated.

I tried the first step and searched for TDSSserv.sys but it didn't appear. I the started with the second steps, but when I try to run SDFix.exe in safe mode it just flashes open then closes again. I had a look at the readme, and it suggests that SDFix only works with Windows 2000/XP, but I'm running Vista.

Could catchme work instead?

Right, I don't use SDFix as often lately, so it slipped my mind that it doesn't work for Vista.  Sorry about that.  I was holding off on using ComboFix (which includes Catchme), but because you've already put such a large dent in TDSServ, there shouldn't be any conflict.

Before following my steps, you may need to disable UAC.  If you don't know how to do this, read STEP 2 on this page:
http://forums.majorgeeks.com/showthread.php?t=139681

Then download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.OK followed all the steps. Here we go, hopefully we're making some PROGRESS!

Combofix log:

ComboFix 09-09-18.02 - Andrew 20/09/2009 14:52.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.44.1033.18.3038.1809 [GMT 1:00]
Running from: c:\users\Andrew\Desktop\ComboFix.exe
FW: Outpost Firewall *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3982674394-68895260-2756340350-500
c:\$recycle.bin\S-1-5-21-769387424-2473901706-93561034-500

.
(((((((((((((((((((((((((   Files Created from 2009-08-20 to 2009-09-20  )))))))))))))))))))))))))))))))
.

2009-09-20 14:02 . 2009-09-20 14:03   --------   d-----w-   c:\users\Andrew\AppData\Local\temp
2009-09-20 14:02 . 2009-09-20 14:02   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-09-20 10:00 . 2008-10-16 11:17   --------   d-----w-   C:\SDFix
2009-09-19 11:28 . 2009-09-19 11:28   --------   d-----w-   C:\Sandbox
2009-09-19 11:25 . 2009-09-19 11:25   --------   d-----w-   c:\program files\Sandboxie
2009-09-19 11:21 . 2006-11-30 21:24   86016   ----a-w-   c:\windows\system32\custmon32.dll
2009-09-19 11:21 . 2009-09-19 11:21   --------   dc-h--w-   c:\programdata\{2A28C3FB-FC79-4677-A128-0D87F28F7084}
2009-09-19 11:21 . 2009-09-19 11:21   --------   d-----w-   c:\program files\Capsoft
2009-09-19 11:21 . 2009-09-19 11:21   --------   d-----w-   c:\program files\PDF Creator
2009-09-19 00:28 . 2009-04-06 10:37   704384   ----a-w-   c:\windows\system32\drivers\SandBox.sys
2009-09-19 00:27 . 2009-02-10 15:12   307224   ----a-w-   c:\windows\system32\drivers\afwcore.sys
2009-09-19 00:25 . 2009-02-18 16:27   29208   ----a-w-   c:\windows\system32\drivers\afw.sys
2009-09-19 00:25 . 2009-09-19 00:25   --------   d-----w-   c:\program files\Agnitum
2009-09-19 00:24 . 2009-09-19 00:24   --------   d-----w-   c:\programdata\Agnitum
2009-09-18 13:13 . 2009-09-20 13:42   --------   d-----w-   c:\users\Andrew\Tracing
2009-09-18 12:10 . 2009-09-18 12:10   --------   d-----w-   c:\program files\Trend Micro
2009-09-18 11:52 . 2009-09-18 11:52   --------   d-----w-   c:\users\Andrew\AppData\Roaming\Malwarebytes
2009-09-18 11:52 . 2009-09-10 13:54   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-18 11:52 . 2009-09-18 11:52   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-09-18 11:52 . 2009-09-18 11:52   --------   d-----w-   c:\programdata\Malwarebytes
2009-09-18 11:52 . 2009-09-10 13:53   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-09-17 17:37 . 2009-09-17 17:37   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2009-09-17 17:37 . 2009-09-18 11:42   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-09-17 17:37 . 2009-09-17 17:37   --------   d-----w-   c:\users\Andrew\AppData\Roaming\SUPERAntiSpyware.com
2009-09-17 17:36 . 2009-09-17 17:36   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-09-17 16:15 . 2009-09-17 16:15   --------   d-----w-   c:\program files\CCleaner
2009-09-17 15:24 . 2009-09-17 15:24   --------   d-----w-   c:\users\Andrew\Pavark
2009-09-17 15:15 . 2009-09-17 15:15   --------   d-----w-   c:\users\Andrew\AppData\Roaming\AVG8
2009-09-15 23:41 . 2009-09-15 23:41   --------   d-----w-   c:\programdata\ArcSoft
2009-09-15 23:40 . 2009-09-15 23:41   --------   d-----w-   c:\users\Andrew\AppData\Roaming\ArcSoft
2009-09-15 19:34 . 2009-09-15 19:37   --------   d-----w-   c:\users\Andrew\AppData\Local\Adobe
2009-09-15 14:04 . 2009-09-15 14:04   --------   d-----w-   c:\program files\YouTube Downloader
2009-09-15 13:04 . 2009-09-20 12:33   --------   d-----w-   c:\users\Andrew\AppData\Roaming\skypePM
2009-09-15 13:04 . 2009-08-17 16:04   51376   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
2009-09-15 13:04 . 2009-08-17 16:04   23152   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
2009-09-15 13:04 . 2009-08-17 16:02   97480   ----a-w-   c:\windows\system32\AvastSS.scr
2009-09-15 13:04 . 2009-08-17 16:05   114768   ----a-w-   c:\windows\system32\drivers\aswSP.sys
2009-09-15 13:04 . 2009-08-17 16:05   20560   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
2009-09-15 13:03 . 2009-08-17 16:10   1279456   ----a-w-   c:\windows\system32\aswBoot.exe
2009-09-15 13:03 . 2009-08-17 16:05   53328   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
2009-09-15 13:03 . 2009-09-15 13:03   --------   d-----w-   c:\program files\Alwil Software
2009-09-15 13:03 . 2009-06-22 10:22   2048   ----a-w-   c:\windows\system32\tzres.dll
2009-09-15 13:02 . 2009-09-20 13:40   --------   d-----w-   c:\users\Andrew\AppData\Roaming\Skype
2009-09-15 13:02 . 2009-09-15 13:02   --------   d-----w-   c:\program files\Common Files\Skype
2009-09-15 13:02 . 2009-09-15 13:02   --------   d-----r-   c:\program files\Skype
2009-09-15 12:59 . 2009-09-15 12:59   --------   d-----w-   C:\VAIO Entertainment
2009-09-15 10:36 . 2009-09-15 10:36   --------   d-----w-   c:\programdata\Azureus
2009-09-15 10:35 . 2008-06-20 01:14   97800   ----a-w-   c:\windows\system32\infocardapi.dll
2009-09-15 10:35 . 2009-09-20 11:34   --------   d-----w-   c:\users\Andrew\AppData\Roaming\Azureus
2009-09-15 10:35 . 2008-06-20 01:14   105016   ----a-w-   c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-09-15 10:35 . 2008-06-20 01:14   622080   ----a-w-   c:\windows\system32\icardagt.exe
2009-09-15 10:35 . 2008-06-20 01:14   43544   ----a-w-   c:\windows\system32\PresentationHostProxy.dll
2009-09-15 10:35 . 2008-06-20 01:14   11264   ----a-w-   c:\windows\system32\icardres.dll
2009-09-15 10:35 . 2008-06-20 01:14   781344   ----a-w-   c:\windows\system32\PresentationNative_v0300.dll
2009-09-15 10:35 . 2008-06-20 01:14   326160   ----a-w-   c:\windows\system32\PresentationHost.exe
2009-09-15 10:34 . 2009-09-15 10:34   --------   d-----w-   c:\program files\Vuze
2009-09-15 10:29 . 2008-07-27 18:03   96760   ----a-w-   c:\windows\system32\dfshim.dll
2009-09-15 10:29 . 2008-07-27 18:03   282112   ----a-w-   c:\windows\system32\mscoree.dll
2009-09-15 10:29 . 2008-07-27 18:03   41984   ----a-w-   c:\windows\system32\netfxperf.dll
2009-09-15 10:28 . 2008-07-27 18:03   158720   ----a-w-   c:\windows\system32\mscorier.dll
2009-09-15 10:28 . 2008-07-27 18:03   83968   ----a-w-   c:\windows\system32\mscories.dll
2009-09-15 10:26 . 2009-06-15 15:24   156672   ----a-w-   c:\windows\system32\t2embed.dll
2009-09-15 10:26 . 2009-06-15 15:20   72704   ----a-w-   c:\windows\system32\fontsub.dll
2009-09-15 10:26 . 2009-06-15 15:20   10240   ----a-w-   c:\windows\system32\dciman32.dll
2009-09-15 10:26 . 2009-06-15 12:52   289792   ----a-w-   c:\windows\system32\atmfd.dll
2009-09-15 10:26 . 2009-04-23 12:42   636928   ----a-w-   c:\windows\system32\localspl.dll
2009-09-15 10:26 . 2008-10-22 03:57   241152   ----a-w-   c:\windows\system32\PortableDeviceApi.dll
2009-09-15 10:26 . 2009-04-23 12:43   784896   ----a-w-   c:\windows\system32\rpcrt4.dll
2009-09-15 10:22 . 2009-04-30 12:37   428544   ----a-w-   c:\windows\system32\EncDec.dll
2009-09-15 10:21 . 2009-07-17 14:35   71680   ----a-w-   c:\windows\system32\atl.dll
2009-09-15 10:16 . 2009-09-19 20:52   --------   d-----w-   c:\users\Andrew\AppData\Local\Apple Computer
2009-09-15 10:16 . 2009-09-15 10:18   --------   d-----w-   c:\users\Andrew\AppData\Roaming\Apple Computer
2009-09-15 10:16 . 2009-09-15 10:16   --------   dc----w-   c:\windows\system32\DRVSTORE
2009-09-15 10:16 . 2009-05-18 13:17   26600   ----a-w-   c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-15 10:16 . 2008-04-17 12:12   107368   ----a-w-   c:\windows\system32\GEARAspi.dll
2009-09-15 10:15 . 2009-09-15 10:15   --------   d-----w-   c:\program files\iPod
2009-09-15 10:15 . 2009-09-15 10:16   --------   d-----w-   c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-15 10:15 . 2009-09-15 10:16   --------   d-----w-   c:\program files\iTunes
2009-09-15 10:14 . 2009-09-15 10:14   --------   d-----w-   c:\program files\Bonjour
2009-09-15 10:13 . 2009-09-15 10:14   --------   d-----w-   c:\program files\QuickTime
2009-09-15 10:13 . 2009-09-15 10:15   --------   d-----w-   c:\programdata\Apple Computer
2009-09-15 10:12 . 2009-09-15 10:12   --------   d-----w-   c:\users\Andrew\AppData\Local\Apple
2009-09-15 10:12 . 2009-09-15 10:12   --------   d-----w-   c:\program files\Apple Software Update
2009-09-15 10:10 . 2009-09-15 10:15   --------   d-----w-   c:\program files\Common Files\Apple
2009-09-15 10:10 . 2009-09-15 10:10   --------   d-----w-   c:\programdata\Apple
2009-09-15 10:04 . 2008-10-16 21:13   1809944   ----a-w-   c:\windows\system32\wuaueng.dll
2009-09-15 10:04 . 2008-10-16 21:09   51224   ----a-w-   c:\windows\system32\wuauclt.exe
2009-09-15 10:04 . 2008-10-16 21:09   43544   ----a-w-   c:\windows\system32\wups2.dll
2009-09-15 10:04 . 2008-10-16 20:56   1524736   ----a-w-   c:\windows\system32\wucltux.dll
2009-09-15 10:04 . 2008-10-16 21:12   561688   ----a-w-   c:\windows\system32\wuapi.dll
2009-09-15 10:04 . 2008-10-16 21:08   34328   ----a-w-   c:\windows\system32\wups.dll
2009-09-15 10:04 . 2008-10-16 20:55   83456   ----a-w-   c:\windows\system32\wudriver.dll
2009-09-15 10:04 . 2008-10-16 13:08   162064   ----a-w-   c:\windows\system32\wuwebv.dll
2009-09-15 10:04 . 2008-10-16 12:56   31232   ----a-w-   c:\windows\system32\wuapp.exe
2009-09-15 09:51 . 2009-09-15 09:51   --------   d-----w-   c:\users\Andrew\AppData\Local\Sony_Corporation
2009-09-15 09:51 . 2009-09-15 09:51   --------   d-----w-   c:\users\Andrew\AppData\Roaming\ATI
2009-09-15 09:51 . 2009-09-15 09:51   --------   d-----w-   c:\users\Andrew\AppData\Local\ATI
2009-09-15 09:51 . 2009-09-15 09:51   --------   d-----w-   c:\users\Andrew\AppData\Local\Broadcom
2009-09-15 09:51 . 2009-09-18 23:58   --------   d-----w-   c:\users\Andrew\AppData\Local\Google
2009-09-15 09:51 . 2009-09-15 10:40   --------   d-----w-   c:\users\Andrew\AppData\Roaming\Sony Corporation
2009-09-15 09:50 . 2009-09-17 15:10   --------   d-----w-   c:\users\Andrew\AppData\Local\VirtualStore

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-20 13:40 . 2009-05-15 18:54   12   ----a-w-   c:\windows\bthservsdp.dat
2009-09-18 23:59 . 2009-06-17 16:25   --------   d-----w-   c:\program files\Google
2009-09-18 12:05 . 2009-05-15 21:18   411368   ----a-w-   c:\windows\system32\deploytk.dll
2009-09-15 15:25 . 2009-05-15 21:17   --------   d-----w-   c:\programdata\Sony Corporation
2009-09-15 14:00 . 2009-05-15 21:18   --------   d-----w-   c:\program files\Java
2009-09-15 13:52 . 2009-06-17 16:27   --------   d-----w-   c:\programdata\McAfee
2009-09-15 13:06 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-09-15 13:04 . 2009-09-15 13:04   56   ---ha-w-   c:\programdata\ezsidmv.dat
2009-09-15 13:02 . 2009-06-17 16:44   --------   d-----w-   c:\programdata\Skype
2009-09-15 09:49 . 2009-09-15 09:49   0   ---ha-r-   c:\windows\system32\drivers\104D_Sony_VGN-NW11SS.mrk
2009-09-15 09:47 . 2009-09-15 09:47   79096   ----a-w-   c:\users\Andrew\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-28 12:39 . 2009-09-15 10:22   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-15 10:22   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-14 17:07 . 2009-09-15 10:25   897608   ----a-w-   c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-15 10:25   104960   ----a-w-   c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-15 10:25   17920   ----a-w-   c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-15 10:25   9728   ----a-w-   c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-15 10:25   17920   ----a-w-   c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-15 10:25   11264   ----a-w-   c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-15 10:25   27136   ----a-w-   c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-15 10:25   19968   ----a-w-   c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-15 10:25   8704   ----a-w-   c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-15 10:25   10240   ----a-w-   c:\windows\system32\finger.exe
2009-07-18 16:06 . 2009-09-15 10:22   827904   ----a-w-   c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-09-15 10:22   78336   ----a-w-   c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-09-15 10:22   26624   ----a-w-   c:\windows\system32\ieUnatt.exe
2009-07-14 13:00 . 2009-09-15 10:21   313344   ----a-w-   c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-09-15 10:21   4096   ----a-w-   c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-09-15 10:21   7680   ----a-w-   c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-09-15 10:21   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
2009-07-11 19:32 . 2009-09-15 10:21   302592   ----a-w-   c:\windows\system32\wlansec.dll
2009-07-11 19:32 . 2009-09-15 10:21   293376   ----a-w-   c:\windows\system32\wlanmsm.dll
2009-07-11 19:32 . 2009-09-15 10:21   513024   ----a-w-   c:\windows\system32\wlansvc.dll
2009-07-11 19:29 . 2009-09-15 10:21   127488   ----a-w-   c:\windows\system32\L2SecHC.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not SHOWN
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2009-06-17 16:25   159728   ----a-w-   c:\programdata\Partner\partner.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-12-22 274432]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-17 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-05-28 380416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-06 6703648]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2009-04-13 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-12-18 317288]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-11 61440]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2009-06-17 26624]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-18 149280]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-3-2 789032]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21   548352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-01-19 19:49   98304   ----a-w-   c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{129514D1-4AC8-4E1F-BDFD-B21A5F0F9BEA}"= UDP:c:\program files\Microsoft OFFICE\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A1F59285-8068-48B7-AE07-A8E62975667B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ABB61563-A40C-4DD4-B816-166008DA01C3}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{06B6A460-D768-415D-B42B-3EB47FF36165}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D23146E0-9C53-41F9-8BF3-060E45152425}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F04AB291-7465-4283-9A83-8CDA902852BF}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B27D64D9-5B16-445D-BF86-FB9011C7A75B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{2FA59455-1B7B-4BE2-A7FB-20C7878FC43B}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{ACEEC3FD-2288-4FC5-939F-CE82CD3CB122}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus

R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\afw.sys [19/09/2009 01:25 29208]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [15/09/2009 14:04 114768]
R1 SandBox;SandBox;c:\windows\System32\drivers\SandBox.sys [19/09/2009 01:28 704384]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [04/09/2009 14:50 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [04/09/2009 14:49 74480]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [19/09/2009 01:25 1195008]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [15/09/2009 14:04 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [15/09/2009 14:03 53328]
R2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [17/06/2009 17:59 303104]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [18/04/2007 04:09 11032]
R2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService.exe [15/05/2009 19:34 109088]
R2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [17/06/2009 17:26 104960]
R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [15/05/2009 22:18 415592]
R2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [14/01/2009 21:38 5184872]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [17/06/2009 17:45 394536]
R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [21/01/2008 03:23 21504]
R3 afwcore;afwcore;c:\windows\System32\drivers\afwcore.sys [19/09/2009 01:27 307224]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\System32\drivers\ArcSoftKsUFilter.sys [17/06/2009 17:26 17920]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [15/05/2009 20:07 29736]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [29/08/2008 07:48 3664384]
R3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [28/05/2009 14:32 108032]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [15/05/2009 19:35 9344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/09/2009 00:58 133104]
S3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [17/06/2009 17:25 111088]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [04/09/2009 14:50 7408]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [17/06/2009 17:49 120104]
S3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [17/06/2009 17:49 70952]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Common Files\Sony Shared\SOHLib\SOHDms.exe [17/06/2009 17:49 390440]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Common Files\Sony Shared\SOHLib\SOHDs.exe [17/06/2009 17:49 75048]
S3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [17/06/2009 17:49 91432]
S3 TWAP;TWAP;c:\users\Andrew\AppData\Local\Temp\TWAP.exe --> c:\users\Andrew\AppData\Local\Temp\TWAP.exe [?]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [17/06/2009 17:45 83240]
S3 WPLJQNI;WPLJQNI;c:\users\Andrew\AppData\Local\Temp\WPLJQNI.exe --> c:\users\Andrew\AppData\Local\Temp\WPLJQNI.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
yksvcs   REG_MULTI_SZ      yksvc
.
Contents of the 'Scheduled Tasks' folder

2009-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-18 23:58]

2009-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-18 23:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=EU01
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYT&bmod=SNYT
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -

AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-20 15:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


c:\users\Andrew\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\msiserver]
"ImagePath"="%systemroot%\system32\msiexec /V"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
Denied: (A 2) (Everyone)
="FlashBroker"
"LocalizedString"="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
Denied: (A 2) (Everyone)
="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b4
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3240)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Completion time: 2009-09-20 15:06
ComboFix-quarantined-files.txt  2009-09-20 14:06

Pre-Run: 174,304,403,456 bytes free
Post-Run: 174,297,751,552 bytes free

308   --- E O F ---   2009-09-17 10:54


===================

Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:38:34, on 20/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Sony\VAIO Reminder\VAIOReminder.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" /dump:os_startup
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: TWAP - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\TWAP.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: WPLJQNI - Unknown owner - C:\Users\Andrew\AppData\Local\Temp\WPLJQNI.exe (file missing)

--
End of file - 10895 bytes


For the most part, your logs look clean.  The only issue I see is with this Partner software from Google.  Many people consider it to be spyware and they typically want to remove it.  If you would like to do so, open HijackThis and place checkmarks next to the following entries:
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe


Close all other windows (except for HijackThis) and click on Fix Checked.  That should take care of that.  You can then delete the folder C:\ProgramData\Partner if you wish.

Other than that, not much is going on.  Are you still having the same problems?  It appears that the TDSServ infection is gone, but it can be hard to kill sometimes, so I'd like to know if things are getting any better or not.
1349.

Solve : How to remove my spyware?

Answer»

I scan my spyware begone and i got 2 was FOUND, So how do i remove it for free n when i PLAY my movies from my hard drive it doesn't work well
Please HELP ASAPThere are many freeware applications. I google searched "Spyware REMOVAL Free" and I have the link below:
http://www.google.com/search?q=Spyware+Removal+Free&rls=com.microsoft:en-us&ie=UTF-8&oe=UTF-8&startIndex=&startPage=1The two best utilities are MalwareBytes and Super AntiSpyware - choose the free version of either (or both)

1350.

Solve : Why my Favourite sites are blocked??

Answer» DEAR All,
My favou
rite sites are blocked and I believe by Spybot. I installed it few days AGO. Before that everything was working fine. After I installed it, some of the sites (those on my favourite list) were blocked. I uninstalled it. I thought this would fix the problem out but I am having the same problem.
Has anyone any idea how this could be fix.

Thanks in Advance.
Regards
HI there,

if this is a MALWARE problem, first go here and post the three log requested.  An expert will see them and help you further.

(I have spybot, but didn't encounter this problem... maybe it's where you downloaded it from, or maybe it's the sites themselves that might have some sort of malware....)

Hope everything goes for the better,

Two-Eyes %if it worked before the d/load , go to add and remove , take it out and try itCheck your hosts file and if you see those sites listed remove them.What does the blocked page look like? Does it have a company name, REASON why it was blocked?Download HostsXpert
  • Unzip HostXpert to your Desktop
  • Open up the HostXpert program.
  • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
  • Click Create Back Up
  • Then click on Restore Microsoft's Host Files
  • Close the HostXpert program
.

Now go to http://windowsupdate.microsoft.com and get all critical updates.