Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1601.

Solve : Backdoor.Win32.Bifrose.cwlo?

Answer»

I RECENTLY replaced Avast with Kaspersky Internet Security 2011 and after LEAVING the PC for a while Kaspersky flagged that it had found Backdoor.Win32.Bifrose.cwlo
Quote

Detected (1)   
06/11/2010 17:32:39   Detected   Trojan program Backdoor.Win32.Bifrose.cwlo   C:\Documents and Settings\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cache\f_003f43/POLE.EXE   High   

When I press to disinfect nothing appears to happen and the entry STILL remains in the Active threats page yet it appears to have been deleted as it shows on the neutralised page too.
Quote
Deleted (2)   
06/11/2010 17:32:21   Deleted   Trojan program Backdoor.Win32.Bifrose.cwlo   C:\Documents and Settings\Cameron\Local Settings\Google\Chrome\User Data\Default\Cache\f_003f43   High   
06/11/2010 17:32:21   Deleted   Trojan program Backdoor.Win32.Bifrose.cwlo   C:\Documents and Settings\Cameron\Local Settings\Google\Chrome\User Data\Default\Cache\f_003f43/POLE.EXE   High   

The files above do not appear to exist when I navigate to the folders.  I'm running Windows 7 Professional 64bitHJT Log:
Code: [Select]Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:47:18, on 06/11/2010
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files (x86)\Scrybe\scrybe.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Lenovo\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Cameron\Desktop\Bob.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.MSN.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O3 - Toolbar: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O4 - HKLM\..\Run: [DockingDetection] C:\PROGRA~2\Lenovo\LENOVO~1\DOCKIN~1.EXE
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Message Center Plus] C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe /start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Cameron\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %PROGRAMFILES%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Scrybe.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:  ,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: AcPrfMgrSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
O23 - Service: AcSvc - Lenovo - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
O23 - Service: %SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: %SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: %systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: %SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: %systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: %systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: %SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Scrybe Updater (ScrybeUpdater) - Synaptics, Inc. - C:\Program Files (x86)\Scrybe\Service\ScrybeUpdater.exe
O23 - Service: %SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: %systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: %SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: %SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: %SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: %SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: %systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - C:\Program Files (x86)\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - C:\Program Files (x86)\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
O23 - Service: %SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: %systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: %Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - C:\Windows\system32\ZuneWlanCfgSvc.exe (file missing)

--
End of file - 14721 bytes
MBAM Log:

Code: [Select]Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5062

Windows 6.1.7600
Internet Explorer 9.0.7930.16406

06/11/2010 19:40:54
mbam-log-2010-11-06 (19-40-54).txt

Scan type: Quick scan
Objects scanned: 171379
Time elapsed: 20 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Also since this appears to be within one of the Google Chrome Cache files, is it likely that my PC is infected or is it a case that chrome has cached it but it is in no way a danger.SAS Log
[code]SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/06/2010 at 09:25 PM

Application Version : 4.45.1000

Core Rules Database Version : 5758
Trace Rules Database Version: 3570

Scan type       : Complete Scan
Total Scan Time : 02:05:20

Memory items scanned      : 725
Memory threats detected   : 0
Registry items scanned    : 17229
Registry threats detected : 0
File items scanned        : 49102
File threats detected     : 756

Adware.Tracking Cookie
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Cameron\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ad.uk.doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .microsoftsto.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   uk.sitestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   uk.sitestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ru4.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ru4.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .dmtracker.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   in.getclicky.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .xiti.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adxpose.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .msnportal.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adinterax.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .microsoftoffice.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ads.audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cisco.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kantarmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .paypal.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .w3counter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adserver.adtechus.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ext-us.bestofmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   my.stats2.com.re.getclicky.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .247realmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .canoe.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .discountelectronicsstore.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   counter.hitslink.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .spylog.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .apmebf.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .videoegg.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .vdwp.solution.weborama.fr [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .nextag.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .nextag.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .antistat.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .antistat.co.uk [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cneteurope.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .uk.at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.linuxquestions.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ad-emea.doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   server.lon.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   webstats.plus.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clickteam.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clickteam.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .sfcglobalgateway.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cubestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cubestat.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .viacom.adbureau.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   counter.sc [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   dc.tremormedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .trackalyzer.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .stats.paypal.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adfarm1.adition.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad3.adfarm1.adition.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ww251.smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   user.lucidmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revenue.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .247realmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tracker.xilo.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tracker.xilo.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .yieldmanager.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   s3.trafficmaxx.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wnkispdziho.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wjmyghdjchp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   *Blocked Russian URL* [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .shop.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .shop.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmediapeople.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmediapeople.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tracking.foxnews.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tracking.foxnews.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adinterax.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virilion.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pro-market.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .commission-junction.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .commission-junction.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediacollege.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wnmigmc5cdo.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wfk4sgdzkhq.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6aekyohdzico.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   stats.cihar.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .w3counter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .192com.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .f2network.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .associatedcontent.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kantarmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bs.serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adviva.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wjkoenazskp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .gostats.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .doubleclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6waliolajgkp.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .medicaldevicelink.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtechus.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   adserver1.backbeatmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .eyewonder.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.burstbeacon.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstbeacon.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .technoratimedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .chitika.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .harrenmedianetwork.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   stats.blogcatalog.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.mediaconverter.org [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ehg-techtarget.hitbox.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ads.audience2media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .sonyeurope.112.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wfloggc5ifq.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adecn.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .apmebf.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnetads.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnetads.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .e-2dj6wjk4gidpgho.stats.esomniture.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   advancedsearch.virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .virginmedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.qsstats.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   t4.trackalyzer.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adviva.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .myroitracking.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaplex.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adtech.de [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clickfuse.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .legolas-media.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .questionmarket.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .questionmarket.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .statcounter.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kaspersky.122.2o7.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   statse.webtrendslive.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   server.iad.liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .liveperson.net [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bs.serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   statse.webtrendslive.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .doubleclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tribalfusion.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .apmebf.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .microsoftsto.112.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adxpose.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .chitika.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adviva.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adviva.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   in.getclicky.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   tracking.dc-storm.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   tracking.dc-storm.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .roiservice.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .www.burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .bs.serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   www.burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   stats1.clicktracks.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .texasinstrument.122.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .ehg-ti.hitbox.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .xiti.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   www.googleadservices.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .atwola.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .dmtracker.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adtech.de [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .tradedoubler.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adserver.adtechus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .cmp.112.2o7.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .i7media.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   www.googleadservices.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   server.iad.liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.disqus.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   ads.neudesicmediagroup.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   secure.arixmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .mustardseedmedia.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .revsci.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .yieldmanager.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   www.qsstats.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   www.qsstats.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .liveperson.net [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\Profiles\pt43y8te.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Cameron\AppData\Roaming\Mozilla\Firefox\ProfilIt seems to have been a false positive. - Marking as solved
1602.

Solve : Virus? Pop up guard/Security Analysis?

Answer»

Ok. Let's do some cleanup.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type commy /uninstall in the runbox
* Make sure there's a space between commy and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file EXTENSIONS, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
*********************************
Clean out your temporary internet files and TEMP files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and SCROLL down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running MOZILLA based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and MALWARE
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

1603.

Solve : sound goes out, yadaying running, Downloader.Tiny.BB, Help!!!?

Answer»

18424 09:15:45 (0) ** WMIDiag v2.0 started on Tuesday, September 14, 2010 at 09:11.
18425 09:15:45 (0) **
18426 09:15:45 (0) ** Copyright (c) Microsoft Corporation. All rights reserved - January 2007.
18427 09:15:45 (0) **
18428 09:15:45 (0) ** This script is not supported under any Microsoft standard support program or service.
18429 09:15:45 (0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
18430 09:15:45 (0) ** implied warranties including, without limitation, any implied warranties of merchantability
18431 09:15:45 (0) ** or of fitness for a particular purpose. The entire risk arising out of the use or PERFORMANCE
18432 09:15:45 (0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
18433 09:15:45 (0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
18434 09:15:45 (0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
18435 09:15:45 (0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
18436 09:15:45 (0) ** the use of or inability to use the script or documentation, EVEN if Microsoft has been advised
18437 09:15:45 (0) ** of the possibility of such damages.
18438 09:15:45 (0) **
18439 09:15:45 (0) **
18440 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18441 09:15:45 (0) ** ----------------------------------------------------- WMI REPORT: BEGIN ----------------------------------------------------------
18442 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18443 09:15:45 (0) **
18444 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18445 09:15:45 (0) ** Windows XP - No service pack - 32-bit (2600) - User 'D2PGV571\BRETT' on computer 'D2PGV571'.
18446 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18447 09:15:45 (0) ** Environment: ... OK..
18448 09:15:45 (0) ** System drive: ... C: (Disk #0 Partition #1).
18449 09:15:45 (0) ** Drive type: ... IDE (Maxtor 6Y080M0).
18450 09:15:45 (0) ** There are no missing WMI system files: ....................................... ....................................... OK.
18451 09:15:45 (0) ** There are no missing WMI repository files: ....................................... ................................... OK.
18452 09:15:45 (0) ** WMI repository state: ....................................... ....................................... ................. N/A.
18453 09:15:45 (0) ** BEFORE running WMIDiag:
18454 09:15:45 (0) ** The WMI repository has a size of: ....................................... ....................................... ..... 12 MB.
18455 09:15:45 (0) ** - Disk FREE space on 'C:': ....................................... ....................................... ............ 29517 MB.
18456 09:15:45 (0) **   - INDEX.BTR,                     1826816 bytes,      9/14/2010 9:10:23 AM
18457 09:15:45 (0) **   - INDEX.MAP,                     940 bytes,          9/14/2010 9:10:23 AM
18458 09:15:45 (0) **   - OBJECTS.DATA,                  10575872 bytes,     9/14/2010 9:10:23 AM
18459 09:15:45 (0) **   - OBJECTS.MAP,                   5208 bytes,         9/14/2010 9:10:24 AM
18460 09:15:45 (0) ** AFTER running WMIDiag:
18461 09:15:45 (0) ** The WMI repository has a size of: ....................................... ....................................... ..... 12 MB.
18462 09:15:45 (0) ** - Disk free space on 'C:': ....................................... ....................................... ............ 29512 MB.
18463 09:15:45 (0) **   - INDEX.BTR,                     1826816 bytes,      9/14/2010 9:10:23 AM
18464 09:15:45 (0) **   - INDEX.MAP,                     940 bytes,          9/14/2010 9:10:23 AM
18465 09:15:45 (0) **   - OBJECTS.DATA,                  10575872 bytes,     9/14/2010 9:10:23 AM
18466 09:15:45 (0) **   - OBJECTS.MAP,                   5208 bytes,         9/14/2010 9:10:24 AM
18467 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18468 09:15:45 (0) ** Windows Firewall: ....................................... ....................................... ..................... NOT INSTALLED.
18469 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18470 09:15:45 (0) ** DCOM Status: ... OK.
18471 09:15:45 (0) ** WMI registry setup: ....................................... ....................................... ................... OK.
18472 09:15:45 (0) ** WMI Service has no dependents: ....................................... ....................................... ........ OK.
18473 09:15:45 (0) ** RPCSS service: ... OK (Already started).
18474 09:15:45 (0) ** WINMGMT service: ... OK (Already started).
18475 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18476 09:15:45 (0) ** WMI service DCOM setup: ....................................... ....................................... ............... OK.
18477 09:15:45 (2) !! WARNING: WMI DCOM components registration is missing for the following EXE/DLLs: .................................... 6 WARNING(S)!
18478 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL (\CLSID\{7A0227F6-7108-11D1-AD90-00C04FD8FDFF}\InProcServer32)
18479 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL (\CLSID\{D71EE747-F455-4804-9DF6-2ED81025F2C1}\InProcServer32)
18480 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\FASTPROX.DLL (\CLSID\{ED51D12E-511F-4999-8DCD-C2BAC91BE86E}\InProcServer32)
18481 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL (\CLSID\{4C6055D8-84B9-4111-A7D3-6623894EEDB3}\InProcServer32)
18482 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL (\CLSID\{A1044801-8F7E-11D1-9E7C-00C04FC324A8}\InProcServer32)
18483 09:15:45 (0) ** - C:\WINDOWS\SYSTEM32\WBEM\WBEMPROX.DLL (\CLSID\{F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}\InProcServer32)
18484 09:15:45 (0) ** => WMI System components are not properly registered as COM objects, which COULD make WMI to
18485 09:15:45 (0) **    fail depending on the operation requested.
18486 09:15:45 (0) ** => For a .DLL, you can correct the DCOM configuration by executing the 'REGSVR32.EXE ' command.
18487 09:15:45 (0) **
18488 09:15:45 (0) ** WMI ProgID registrations: ....................................... ....................................... ............. OK.
18489 09:15:45 (0) ** WMI provider DCOM registrations: ....................................... ....................................... ...... OK.
18490 09:15:45 (2) !! WARNING: WMI provider CIM registrations missing for the following provider(s): ...................................... 3 WARNING(S)!
18491 09:15:45 (0) ** - ROOT/INTELNCS, NcsEvent (i.e. WMI Class 'IANet_802dot3VlanEvent')
18492 09:15:45 (0) **   MOF Registration: 'WMI information not available (This could be the case for an external application or a third party WMI provider)'
18493 09:15:45 (0) ** - ROOT/INTELNCS, NcsEvent (i.e. WMI Class 'IANet_802dot3TeamEvent')
18494 09:15:45 (0) **   MOF Registration: 'WMI information not available (This could be the case for an external application or a third party WMI provider)'
18495 09:15:45 (0) ** - ROOT/INTELNCS, NcsEvent (i.e. WMI Class 'IANet_802dot3AdapterEvent')
18496 09:15:45 (0) **   MOF Registration: 'WMI information not available (This could be the case for an external application or a third party WMI provider)'
18497 09:15:45 (0) ** => This is an issue because there are still some WMI classes referencing this list of providers
18498 09:15:45 (0) **    while the CIM registration is wrong or missing. This can be due to:
18499 09:15:45 (0) **    - a de-installation of the software.
18500 09:15:45 (0) **    - a deletion of some CIM registration information.
18501 09:15:45 (0) ** => You can correct the CIM configuration by:
18502 09:15:45 (0) **    - Manually recompiling the MOF file(s) with the 'MOFCOMP ' command.
18503 09:15:45 (0) **    Note: You can build a list of classes in relation with their WMI provider and MOF file with WMIDiag.
18504 09:15:45 (0) **          (This list can be built on a similar and working WMI Windows installation)
18505 09:15:45 (0) **          The following command line must be used:
18506 09:15:45 (0) **          i.e. 'WMIDiag CorrelateClassAndProvider'
18507 09:15:45 (0) **    - Re-installing the software.
18508 09:15:45 (0) ** => If the software has been de-installed intentionally, then this information must be
18509 09:15:45 (0) **    removed from the WMI repository. You can use the 'WMIC.EXE' command to remove the provider
18510 09:15:45 (0) **    registration data and its set of associated classes.
18511 09:15:45 (0) **    i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\INTELNCS path __Win32Provider Where Name='NcsEvent' DELETE'
18512 09:15:45 (0) **    i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\INTELNCS Class IANet_802dot3AdapterEvent DELETE'
18513 09:15:45 (0) ** => If the namespace was ENTIRELY dedicated to the intentionally de-installed software,
18514 09:15:45 (0) **    the namespace and ALL its content can be ENTIRELY deleted.
18515 09:15:45 (0) **    i.e. 'WMIC.EXE /NAMESPACE:\\ROOT path __NAMESPACE Where Name='INTELNCS' DELETE'
18516 09:15:45 (0) **
18517 09:15:45 (0) ** WMI provider CLSIDs: ....................................... ....................................... .................. OK.
18518 09:15:45 (0) ** WMI providers EXE/DLL availability: ....................................... ....................................... ... OK.
18519 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18520 09:15:45 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
18521 09:15:45 (1) !! ERROR: Default trustee 'BUILTIN\ADMINISTRATORS' has been REMOVED!
18522 09:15:45 (0) **        - REMOVED ACE:
18523 09:15:45 (0) **          ACEType:  &h0
18524 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18525 09:15:45 (0) **          ACEFlags: &h0
18526 09:15:45 (0) **          ACEMask:  &h1
18527 09:15:45 (0) **                    DCOM_RIGHT_EXECUTE
18528 09:15:45 (0) **
18529 09:15:45 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
18530 09:15:45 (0) **    Removing default security will cause some operations to fail!
18531 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
18532 09:15:45 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
18533 09:15:45 (0) **
18534 09:15:45 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
18535 09:15:45 (1) !! ERROR: Default trustee 'NT AUTHORITY\INTERACTIVE' has been REMOVED!
18536 09:15:45 (0) **        - REMOVED ACE:
18537 09:15:45 (0) **          ACEType:  &h0
18538 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18539 09:15:45 (0) **          ACEFlags: &h0
18540 09:15:45 (0) **          ACEMask:  &h1
18541 09:15:45 (0) **                    DCOM_RIGHT_EXECUTE
18542 09:15:45 (0) **
18543 09:15:45 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
18544 09:15:45 (0) **    Removing default security will cause some operations to fail!
18545 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
18546 09:15:45 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
18547 09:15:45 (0) **
18548 09:15:45 (0) ** DCOM security for 'Microsoft WBEM UnSecured Apartment' (Launch & Activation Permissions): ........................... MODIFIED.
18549 09:15:45 (1) !! ERROR: Default trustee 'NT AUTHORITY\SYSTEM' has been REMOVED!
18550 09:15:45 (0) **        - REMOVED ACE:
18551 09:15:45 (0) **          ACEType:  &h0
18552 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18553 09:15:45 (0) **          ACEFlags: &h0
18554 09:15:45 (0) **          ACEMask:  &h1
18555 09:15:45 (0) **                    DCOM_RIGHT_EXECUTE
18556 09:15:45 (0) **
18557 09:15:45 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
18558 09:15:45 (0) **    Removing default security will cause some operations to fail!
18559 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
18560 09:15:45 (0) **    For DCOM objects, this can be done with 'DCOMCNFG.EXE'.
18561 09:15:45 (0) **
18562 09:15:45 (0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ....................................... .............................. MODIFIED.
18563 09:15:45 (1) !! ERROR: Actual trustee 'NT AUTHORITY\NETWORK SERVICE' DOES NOT match corresponding expected trustee rights (Actual->Default)
18564 09:15:45 (0) **        - ACTUAL ACE:
18565 09:15:45 (0) **          ACEType:  &h0
18566 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18567 09:15:45 (0) **          ACEFlags: &h2
18568 09:15:45 (0) **                    CONTAINER_INHERIT_ACE
18569 09:15:45 (0) **          ACEMask:  &h1
18570 09:15:45 (0) **                    WBEM_ENABLE
18571 09:15:45 (0) **        - EXPECTED ACE:
18572 09:15:45 (0) **          ACEType:  &h0
18573 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18574 09:15:45 (0) **          ACEFlags: &h12
18575 09:15:45 (0) **                    CONTAINER_INHERIT_ACE
18576 09:15:45 (0) **                    INHERITED_ACE
18577 09:15:45 (0) **          ACEMask:  &h13
18578 09:15:45 (0) **                    WBEM_ENABLE
18579 09:15:45 (0) **                    WBEM_METHOD_EXECUTE
18580 09:15:45 (0) **                    WBEM_WRITE_PROVIDER
18581 09:15:45 (0) **
18582 09:15:45 (0) ** => The actual ACE has the right(s) '&h12 WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
18583 09:15:45 (0) **    This will cause some operations to fail!
18584 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the removed right.
18585 09:15:45 (0) **    For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
18586 09:15:45 (0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
18587 09:15:45 (0) **       The security diagnostic is based on the WMI namespace expected defaults.
18588 09:15:45 (0) **       A specific WMI application can always require a security setup different
18589 09:15:45 (0) **       than the WMI security defaults.
18590 09:15:45 (0) **
18591 09:15:45 (0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ....................................... .............................. MODIFIED.
18592 09:15:45 (1) !! ERROR: Actual trustee 'NT AUTHORITY\LOCAL SERVICE' DOES NOT match corresponding expected trustee rights (Actual->Default)
18593 09:15:45 (0) **        - ACTUAL ACE:
18594 09:15:45 (0) **          ACEType:  &h0
18595 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18596 09:15:45 (0) **          ACEFlags: &h2
18597 09:15:45 (0) **                    CONTAINER_INHERIT_ACE
18598 09:15:45 (0) **          ACEMask:  &h1
18599 09:15:45 (0) **                    WBEM_ENABLE
18600 09:15:45 (0) **        - EXPECTED ACE:
18601 09:15:45 (0) **          ACEType:  &h0
18602 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18603 09:15:45 (0) **          ACEFlags: &h12
18604 09:15:45 (0) **                    CONTAINER_INHERIT_ACE
18605 09:15:45 (0) **                    INHERITED_ACE
18606 09:15:45 (0) **          ACEMask:  &h13
18607 09:15:45 (0) **                    WBEM_ENABLE
18608 09:15:45 (0) **                    WBEM_METHOD_EXECUTE
18609 09:15:45 (0) **                    WBEM_WRITE_PROVIDER
18610 09:15:45 (0) **
18611 09:15:45 (0) ** => The actual ACE has the right(s) '&h12 WBEM_METHOD_EXECUTE WBEM_WRITE_PROVIDER' removed!
18612 09:15:45 (0) **    This will cause some operations to fail!
18613 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the removed right.
18614 09:15:45 (0) **    For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
18615 09:15:45 (0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
18616 09:15:45 (0) **       The security diagnostic is based on the WMI namespace expected defaults.
18617 09:15:45 (0) **       A specific WMI application can always require a security setup different
18618 09:15:45 (0) **       than the WMI security defaults.
18619 09:15:45 (0) **
18620 09:15:45 (0) ** WMI namespace security for 'ROOT/SERVICEMODEL': ....................................... .............................. MODIFIED.
18621 09:15:45 (1) !! ERROR: Default trustee 'EVERYONE' has been REMOVED!
18622 09:15:45 (0) **        - REMOVED ACE:
18623 09:15:45 (0) **          ACEType:  &h0
18624 09:15:45 (0) **                    ACCESS_ALLOWED_ACE_TYPE
18625 09:15:45 (0) **          ACEFlags: &h12
18626 09:15:45 (0) **                    CONTAINER_INHERIT_ACE
18627 09:15:45 (0) **                    INHERITED_ACE
18628 09:15:45 (0) **          ACEMask:  &h13
18629 09:15:45 (0) **                    WBEM_ENABLE
18630 09:15:45 (0) **                    WBEM_METHOD_EXECUTE
18631 09:15:45 (0) **                    WBEM_WRITE_PROVIDER
18632 09:15:45 (0) **
18633 09:15:45 (0) ** => The REMOVED ACE was part of the DEFAULT setup for the trustee.
18634 09:15:45 (0) **    Removing default security will cause some operations to fail!
18635 09:15:45 (0) **    It is possible to fix this issue by editing the security descriptor and adding the ACE.
18636 09:15:45 (0) **    For WMI namespaces, this can be done with 'WMIMGMT.MSC'.
18637 09:15:45 (0) ** Note: WMIDiag has no specific knowledge of this WMI namespace.
18638 09:15:45 (0) **       The security diagnostic is based on the WMI namespace expected defaults.
18639 09:15:45 (0) **       A specific WMI application can always require a security setup different
18640 09:15:45 (0) **       than the WMI security defaults.
18641 09:15:45 (0) **
18642 09:15:45 (0) **
18643 09:15:45 (0) ** DCOM security warning(s) detected: ....................................... ....................................... .... 0.
18644 09:15:45 (0) ** DCOM security error(s) detected: ....................................... ....................................... ...... 3.
18645 09:15:45 (0) ** WMI security warning(s) detected: ....................................... ....................................... ..... 0.
18646 09:15:45 (0) ** WMI security error(s) detected: ....................................... ....................................... ....... 3.
18647 09:15:45 (0) **
18648 09:15:45 (1) !! ERROR: Overall DCOM security status: ....................................... ....................................... .. ERROR!
18649 09:15:45 (1) !! ERROR: Overall WMI security status: ....................................... ....................................... ... ERROR!
18650 09:15:45 (0) ** - Started at 'Root' --------------------------------------------------------------------------------------------------------------
18651 09:15:45 (0) ** INFO: WMI permanent SUBSCRIPTION(S): ....................................... ....................................... .. 2.
18652 09:15:45 (0) ** - ROOT/SUBSCRIPTION, MSFT_UCScenarioControl.Name="Microsoft WMI Updating Consumer Scenario Control".
18653 09:15:45 (0) **   'SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'MSFT_UCScenario''
18654 09:15:45 (0) ** - ROOT/SUBSCRIPTION, NTEventLogEventConsumer.Name="SCM Event Log Consumer".
18655 09:15:45 (0) **   'select * from MSFT_SCMEventLogEvent'
18656 09:15:45 (0) **
18657 09:15:45 (0) ** WMI TIMER instruction(s): ....................................... ....................................... ............. NONE.
18658 09:15:45 (0) ** INFO: WMI ADAP status: ....................................... ....................................... ................ 1.
18659 09:15:45 (0) ** => The WMI ADAP process is currently running (1).
18660 09:15:45 (0) **    Some WMI performance classes could be missing at the time WMIDiag was executed.
18661 09:15:45 (0) ** INFO: WMI namespace(s) requiring PACKET PRIVACY: ....................................... ............................. 1 NAMESPACE(S)!
18662 09:15:45 (0) ** - ROOT/SERVICEMODEL.
18663 09:15:45 (0) ** => When remotely connecting, the namespace(s) listed require(s) the WMI client to
18664 09:15:45 (0) **    use an encrypted connection by specifying the PACKET PRIVACY authentication level.
18665 09:15:45 (0) **    (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy flags)
18666 09:15:45 (0) **    i.e. 'WMIC.EXE /NODE:"D2PGV571" /AUTHLEVEL:Pktprivacy /NAMESPACE:\\ROOT\SERVICEMODEL Class __SystemSecurity'
18667 09:15:45 (0) **
18668 09:15:45 (0) ** WMI MONIKER CONNECTIONS: ....................................... ....................................... .............. OK.
18669 09:15:45 (0) ** WMI CONNECTIONS: ... OK.
18670 09:15:45 (0) ** WMI GET operations: ....................................... ....................................... ................... OK.
18671 09:15:45 (0) ** WMI MOF representations: ....................................... ....................................... .............. OK.
18672 09:15:45 (0) ** WMI QUALIFIER access operations: ....................................... ....................................... ...... OK.
18673 09:15:45 (0) ** WMI ENUMERATION operations: ....................................... ....................................... ........... OK.
18674 09:15:45 (0) ** WMI EXECQUERY operations: ....................................... ....................................... ............. OK.
18675 09:15:45 (0) ** WMI GET VALUE operations: ....................................... ....................................... ............. OK.
18676 09:15:45 (0) ** WMI WRITE operations: ....................................... ....................................... ................. NOT TESTED.
18677 09:15:45 (0) ** WMI PUT operations: ....................................... ....................................... ................... NOT TESTED.
18678 09:15:45 (0) ** WMI DELETE operations: ....................................... ....................................... ................ NOT TESTED.
18679 09:15:45 (0) ** WMI static instances retrieved: ....................................... ....................................... ....... 604.
18680 09:15:45 (0) ** WMI dynamic instances retrieved: ....................................... ....................................... ...... 0.
18681 09:15:45 (0) ** WMI instance request cancellations (to limit performance impact): ....................................... ............ 0.
18682 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18683 09:15:45 (0) ** # of Event Log events BEFORE WMIDiag execution since the last 20 day(s):
18684 09:15:45 (0) **   DCOM: ... 0.
18685 09:15:45 (0) **   WINMGMT: ... 0.
18686 09:15:45 (0) **   WMIADAPTER: ... 0.
18687 09:15:45 (0) **
18688 09:15:45 (0) ** # of additional Event Log events AFTER WMIDiag execution:
18689 09:15:45 (0) **   DCOM: ... 0.
18690 09:15:45 (0) **   WINMGMT: ... 0.
18691 09:15:45 (0) **   WMIADAPTER: ... 0.
18692 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18693 09:15:45 (0) ** WMI Registry key setup: ....................................... ....................................... ............... OK.
18694 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18695 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18696 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18697 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18698 09:15:45 (0) **
18699 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18700 09:15:45 (0) ** ------------------------------------------------------ WMI REPORT: END -----------------------------------------------------------
18701 09:15:45 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
18702 09:15:45 (0) **
18703 09:15:45 (0) ** ERROR: WMIDiag detected issues that could prevent WMI to work properly!.  Check 'C:\DOCUMENTS AND SETTINGS\BRETT\LOCAL SETTINGS\TEMP\WMIDIAG-V2.0_XP___.CLI.RTM.32_D2PGV571_2010.09.14_09.11.33.LOG' for details.
18704 09:15:45 (0) **
18705 09:15:45 (0) ** WMIDiag v2.0 ended on Tuesday, September 14, 2010 at 09:15 (W:87 E:26 S:1).
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
Code: [Select]:filefind
FASTPROX.DLL
WBEMPROX.DLL
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the RESULTS of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txtSystemLook 04.09.10 by jpshortstuff
Log created at 19:47 on 04/10/2010 by Brett
Administrator - Elevation successful

========== filefind ==========

Searching for "FASTPROX.DLL"
C:\Documents and Settings\Deborah\Desktop\i386\fastprox.dll   --a---- 472064 bytes   [02:08 22/04/2005]   [10:00 04/08/2004] C28500101BC66FDABD830F8DE51A59A0
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\fastprox.dll   --a---- 473600 bytes   [03:14 17/04/2009]   [10:56 09/02/2009] 600519339671DCFA3DD20216A19817BB
C:\WINDOWS\$NtServicePackUninstall$\fastprox.dll   -----c- 472064 bytes   [23:00 05/10/2008]   [10:00 04/08/2004] C28500101BC66FDABD830F8DE51A59A0
C:\WINDOWS\$NtUninstallKB956572$\fastprox.dll   -----c- 472064 bytes   [04:58 17/04/2009]   [00:11 14/04/2008] 60027BEA3E76D7DD8D96C02432BFDE82
C:\WINDOWS\ServicePackFiles\i386\fastprox.dll   ------- 472064 bytes   [16:47 04/09/2008]   [00:11 14/04/2008] 60027BEA3E76D7DD8D96C02432BFDE82
C:\WINDOWS\system32\dllcache\fastprox.dll   ------- 473600 bytes   [03:14 17/04/2009]   [12:10 09/02/2009] 378A0AEFB11D8B0DC8C27B9F7604B88D
C:\WINDOWS\system32\wbem\fastprox.dll   --a---- 473600 bytes   [18:01 10/08/2004]   [12:10 09/02/2009] 378A0AEFB11D8B0DC8C27B9F7604B88D

Searching for "WBEMPROX.DLL"
C:\Documents and Settings\Deborah\Desktop\i386\wbemprox.dll   --a---- 18944 bytes   [02:08 22/04/2005]   [10:00 04/08/2004] 851547797C2A7F8A04841644C471A567
C:\WINDOWS\$NtServicePackUninstall$\wbemprox.dll   -----c- 18944 bytes   [23:00 05/10/2008]   [10:00 04/08/2004] 851547797C2A7F8A04841644C471A567
C:\WINDOWS\ServicePackFiles\i386\wbemprox.dll   ------- 18944 bytes   [16:49 04/09/2008]   [00:12 14/04/2008] 205ADD80FF8099B1A8101EB490B933D1
C:\WINDOWS\system32\wbem\wbemprox.dll   --a---- 18944 bytes   [18:01 10/08/2004]   [00:12 14/04/2008] 205ADD80FF8099B1A8101EB490B933D1

-= EOF =- Quote from: DragonMaster Jay on July 07, 2010, 07:27:43 PM
Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.

Thanks for sharing the link!Before we can continue, I need to know how your computer is running, Mr Hopeless.It's making these ticking noises, they usually start after I turn on the modem.  The sound works okay.  Internet speed seems to be okay, no internet popups, etc.  I'm getting those windows about the WMI change noted above.What I highly recommend now is a reformat and a reinstallation of Windows XP.

Please let me know if you are prepared to do so.


So, with that said, do you have your Windows XP CD?

Guides for format and reinstall: http://www.geekpolice.net/tutorials-guides-f13/how-to-reformat-and-reinstall-your-operating-system-t15119.htm#95115

http://www.helpmyos.com/tutorials-software-alternatives-to-proprietary-f19/how-to-reformat-and-reinstall-your-operating-system-the-easy-way-t1307.htm#3143I have reinstalled Windows.  Thanks for the effort.  This thread can be closed.
1604.

Solve : question about "learning" - evilfantasy?

Answer» HELLO evilfantasy,

in an earlier post by LINUX, Re..........,
another poster also asked why they couldn't offer HELP.

your response was (in blue) that "there are different levels of learning."  the subject being, virus, malware, trojans, etc. removal.
where does one find the subject to LEARN it ?  sites, books, school ?

i've been to your site and there is SO much you offer people and you do not ask for payment (that i saw).  BHAW !!!

i have a he!l of alot of respect for you and thank you for all the help you've given me and others.  You can CHECK out this site for more information.
1605.

Solve : C:\windows\system32\sshnas21.dll?

Answer»

Quote from: PuB_Evo on October 29, 2010, 07:11:31 PM

I went into MSCONFIG to try and disable UAC, however when I went tools>UAC SETTINGS>launch, it said access denied. I tried doing it through Control Panel>user accounts but it wouldn't save the settings, once I clicked OK, nothing would happen, and if I left it, then went back to it, the setting would then get reverted. My friend said my Administrative privledges are probably corrupt or something similar.

The above is still the same and i do not have admin rights yet, i am assuming the edited registry isn't helping.
I also cannot get Adobe to D/L like before even adding it to the exceptions list on Firefox.
Internet EXPLORER was able to play videos fine.Did you try updating Adobe through Internet Explorer?

Here is the error popping twice when i try to update Adobe Flash Player 10.1 via Internet Explorer. Everything that happen was just very wrong and weird. LOOKS like its a nasty one.  Just realized that all adobe softwares are affected and asking for licensing. These include the Adobe reader +  my Adobe design premium CS4 package.
Online PDF files still works fine in Internet Explorer though, just not for Firefox and the software itself.If this is paid for version of Adobe, perhaps you should consult them about this problem. Please let me know what you find.Nothing helps at all, i reformatted.

Can you suggestion some(Win7 64bits OS) good free browsing softwares that protects and a decent free firewall? Im currently using only Avast Anti-virus.I prefer MicroSoft Security ESSENTIALS. No registration req'd, high efficiency and not a resource hog.

Before we continue download and install a free antivirus.

Remember to only install one antivirus!
 
1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
*****************************************

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to USE only one firewall at the same time.
**************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1606.

Solve : poor start up. and slow?

Answer»

Ok. Please re-enable your emulations drivers as per instructions in Reply # 27.
How is your computer running now?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your NEXT reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt

dave ran the file .said there was no infections .but i didn't get a log file sorry. can run again and try to get one ..things seem better then they were . thanksSometimes when there are no infections, a report doesn't show up. Are you having any other problems with your computer?everything else seems good except when i close my broswer the screen closes real slow from top to bottom. instead of just closing out. if you know what i mean.. anyway thanks dave seems like you cleared up a lot of things. Quote
when i close my broswer the screen closes real slow from top to bottom. instead of just closing out. if you know what i mean..
That sounds like a software or hardware problem than a malware-induced problem. You could try starting a new thread on one of the software or hardware forums to get some help for that. Let's do some clean-up.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
********************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***************************************
To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.
This should give you a new, clean Restore Point.

*****************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything LISTED.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
1607.

Solve : notebook broken!!AHHHHH!!?

Answer»

Hi! Finally back! I called asus tech & asked about recovery console & he took me to the bios to disable BOOT booster, then hit f9 but after about 5 tries & just kept loading windows, he said my partition was gone & needed recovery disc,(which they want 30.for!) can`t believe I didnt get one when I bought it! grrrr! So whaddya think now? Thnx!!It would appear that they have you over a barrel but it would be $30 well-spent.
Hi hun! Yes, they do!lol Well, I guess I don`t have much choice but to order it! That`s how my luck rolls anyway, gettin pretty used to it! lol Thnx again & I guess I`ll be back! Wish I could be of help to someone else but I`m pretty computer stupid! ttys!I'm sorry to hear about that. Didn't you say that your computer doesn't have a disk drive. How is a recovery disk going to help you? Before you leave I would like to give you some information which, I think, will be helpful once you get your computer reformatted.

Remember to only install one antivirus!
 
1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false VIRUS alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
******************************************
Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com OPTIONS if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************
Use the Secunia Software Inspector to check for out-of-date software.

•Click Start Now

•Check the BOX next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the LATEST Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
Good Luck!  Hi SD!! WOW! Thanks for all that info! Will definately do that! I DO have another question though just out of curiousity?? Before I have to order the disc from them, I decided to try something so I`m not throwing away 30. (not that its much, but still,lol!) Being as I have no disc drive, I put a copy of recovery disc from the computer I`m on now, (my desktop) different brands,etc. but same os. onto my flashdrive. I went back to notebook,went to the bios & set it to boot from usb. Was just curious if it would read anything or if its gonna work if i get disc?? I`m so confused!!lol Anyway, it didnt work! I`m trying to do test runs first. Is there something I did wrong? I even disabled 2nd & 3rd boot hoping to just read from usb but dumb thing just keeps loading windows??grrrrr Just thought I`d ask!!hehe I`m gonna give you a headache soon, I drove murf nuts with my dads i think but God bless him!!ttys! thnx again!Are you sure that you're saving the changes in the BIOS? Does your BIOS have the option to boot from the usb drive?hi! sorry, been so busy, haven`t been on. Yes, I hit F10 to save all changes after I set it to boot from usb but all it does is flash the cursor? nothing else. My one friend said u cant boot from usb on these computers but I wouldn`t know why if you`re able to set it to do so?? WOW, how confusing! thnx babes!Since you have no disk drive I can't think of any other way the OS could be installed on the computer. You may be able to do a network installation. Your best bet would be to contact the maker of your computer and ask them those questions.

1608.

Solve : will you run this one for me, too ??

Answer»

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:37:13 PM, on 10/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRAM Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1264797502\ee\AOLSoftware.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol toolbar\aoltbServer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AOL Toolbar Loader - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1264797502\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /M "Stylus Photo R200" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [SWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1010011 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1010011 (User 'Default user')
O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - TRUSTED Zone: http://*.mcafee.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265487941250
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5885/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, INC. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8884 bytes

THANK YOU !!!You can check it yourself by going to this site.

1609.

Solve : Please help! Can't access my email and keep crashing because of a virus??

Answer»

Quote

It found 3 viruses and it cleaned it. Is it really gone from my computer and could there possibly be more?
I would say your computer is clean. If there are no other issues, it's time for some cleanup.BTW, the picture of your kitten looks exactly like ours when she was young.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type commy.exe /uninstall in the runbox
* Make sure there's a space between commy.exe and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and FOLDERS.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

****************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all PROGRAMS when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

**********************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and MALICIOUS intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to ENABLE thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Hi SuperDave. I did all the cleaning up and updating. Thank you SO much for helping me and others!!
You guys are awesome!

And yeah I was looking for a picture and found the kitten picture! I absolutely love cats; I have a black cat at home.

Thank you again
1610.

Solve : Running Duplicate Programs?

Answer»

Should I disable Windows Essentials AntiVirus and Firewall if I run a 3rd party software? I have Windows XP. I added SuperAntiVirius, ONLINE Armour and Malwarebytes awhle back after I got attacked with MALWARE. This FORUM got me SQUARED away on what to do. Recently I had some issues with OLA so I uninstalled it. I just CHECKED my Windows Security Center and it has firewall and antivirus enabled.

Should I disable the antivirus since I have SuperAntivirus? Could the problem I had with OLA be a result of the Window's firewall being enabled? Thanks.  Where did you get SuperAntiVirius?  Why did you install it when you already had Windows Essentials AntiVirus?  I followed the advice I got here and used a link from here to get SuperAntivirus. I'll have to go back and review the thread to remember the deatils.

1611.

Solve : SCAN LOGS............?

Answer»

I have come on this forum to submit scan logs, have been on XP forum, (Polecat.)  Have done Steps A and B. 1, 2, (not the REGISTRY), 3,4 and 5*.  Am now trying to download HijackThis.msi, but it will not download for me. Therefore I am sending logs of Step3 and STEP4 now. Will keep trying to download HijackThis and will send log if I succeed.

*JAVA is downloaded, but appears not fully so. (will redownload it).


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/02/2010 at 02:06 AM

Application Version : 4.45.1000

Core Rules Database Version : 5794
Trace Rules Database Version: 3606

Scan type       : Complete Scan
Total Scan Time : 01:04:52

Memory items scanned      : 538
Memory threats detected   : 0
Registry items scanned    : 5946
Registry threats detected : 10
File items scanned        : 61479
File threats detected     : 0

Adware.MyWebSearch/FunWebProducts
   HKU\S-1-5-21-3848972102-916346316-1962185885-1006\SOFTWARE\FunWebProducts
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE#NextInstance
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Service
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Legacy
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ConfigFlags
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Class
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ClassGUID
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#DeviceDesc




Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5025

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

02/11/2010 22:05:59
mbam-log-2010-11-02 (22-05-59).txt

Scan type: Quick scan
Objects scanned: 516407
Time elapsed: 14 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
I have now downloaded JAVA correctly and removed older versions and run CCleaner.
Have also downloaded HijackThis and renamed it to sniper.exe.
Carried out system scan and have enclosed  the log. 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:29, on 03/11/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\COMODO\COMODO BackUp\COSService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO BackUp\SynchronizationService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\Explorer.EXE
C:\apps\ABoard\ABoard.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\HiJackThis\sniper.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra BUTTON: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} - file://C:\DRIVERS\snapsys\HDDDiag\bin\npseatools.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{209D9EED-D3DF-4C32-B518-950CEBF198EB}: NameServer = 212.139.132.105 212.139.132.107
O17 - HKLM\System\CS1\Services\Tcpip\..\{209D9EED-D3DF-4C32-B518-950CEBF198EB}: NameServer = 212.139.132.105 212.139.132.107
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: Comodo Online Storage Service (COSService.exe) - Unknown owner - C:\Program Files\COMODO\COMODO BackUp\COSService.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
O23 - Service: LexBce Server (LexBceS) - LEXMARK International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Comodo BackUp Service (SynchronizationService.exe) - Unknown owner - C:\Program Files\COMODO\COMODO BackUp\SynchronizationService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 10007 bytes

1612.

Solve : svchost.exe and windows update?

Answer»

The ROOT DIRECTORY of DRIVE C is C:\ - not "the DESKTOP".

1613.

Solve : Virus question?

Answer»

How long does it take a virus to corrupt a computer?No such thing. Depends on the virus and what it does. Some can cause major DAMAGE immediately, some trojans will cause problems down the road. Is there a purpose behind the question?Is there a way to protect websites on shared servers when virus protection is not given by the hosting company?  I seem to be continuously hit by them.  Thank you.Lawyer, should start your own topic. But to answer your question quickly it depends on the type of webserver you're using. It's more than likely that the server is getting compromised then getting INFECTED from an outside source. I'd make sure to CHANGE all your passwords and if it happens again send an e-mail to your webserver indicating that there is a security breach on the server and that it should be fixed.

If all else fails switch hosting companies, there are thousands out there that will PROVIDE you with better service.

1614.

Solve : computer infected : NEED HELPP !!!?

Answer»

You can obviously ignore the above post.This is the log from ESETscan ...

I updated my java , and removed the old versions... but i was unable to download the newest version of Adobe Reader .

____________________________

C:\System Volume Information\SystemRestore\FRStaging\Program Files\Hotbar\bin\11.0.78.0\CoreSrv.dll   Win32/Adware.HotBar.E application   cleaned by deleting - quarantined
C:\System Volume Information\SystemRestore\FRStaging\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll   Win32/Adware.HotBar.E application   cleaned by deleting - quarantined
C:\System Volume Information\SystemRestore\FRStaging\Program Files\Hotbar\bin\11.0.78.0\HostOL.dll   Win32/Adware.HotBar.E application   cleaned by deleting - quarantined
C:\Users\HP User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\1dd6a40c-51cdfff9   Java/TrojanDownloader.Agent.NBK trojan   deleted - quarantined
C:\Users\HP User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\475ee9f-2a566eb7   multiple threats   deleted - quarantined
C:\Users\HP User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\3c071b2a-51ca90db   multiple threats   deleted - quarantined
C:\Users\HP User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\1eff1eb1-4fb5b306   Java/TrojanDownloader.Agent.NBL trojan   deleted - quarantined
C:\Users\HP User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\42441975-57cca50e   Java/TrojanDownloader.Agent.NBM trojan   deleted - quarantined
C:\Users\HP User\Documents\LimeWire\Incomplete\T-5905209-incomplete jyshoun original studio version.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\3lw - ocean.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\about time cassie.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\be next to ya KRYSS ivory.mp3   WMA/TrojanDownloader.GetCodec.C trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\belly no banga.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\cassie about time.wma   WMA/TrojanDownloader.Wimad.N trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\Come with me - Sammie.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\Day 26 Favorite Girl.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\envy nicki minaj.wma   probably a variant of Win32/TrojanDownloader.Agent.IIYTTCE trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\feel like *censored* plies.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\frankee im leaving.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\incomplete jyshoun [club mix].mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\inessa mad in love with you - greatest hits.wma   WMA/TrojanDownloader.Wimad.N trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\inessa mad in love with you.mp3   WMA/TrojanDownloader.GetCodec.C trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\Isley Brothers feat Ronald Isley aka Mr Biggs - Contagious.mp3   WMA/TrojanDownloader.GetCodec.C trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\karina pasian the love we got - greatest hits.wma   WMA/TrojanDownloader.Wimad.N trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\karina pasian the love we got.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\Keyshia Cole - A Different Me - 04 - *censored*.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\kryss ivory next to ya (256k 44800).mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\kryss ivory next to ya.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\let go megan rochell.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\lil wayne colorful clothes [cd rip].mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\lol smiley FACE - ttrey songz new single.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\mad in love with you.mp3   WMA/TrojanDownloader.GetCodec.C trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\make a movie plies.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\mario - directions.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\mary j. blige- missing you.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\memories trina.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\next to ya kryss ivory.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\niki minaj click clack.wma   WMA/TrojanDownloader.Wimad.N trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\questions blaque original studio version.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\questions brandi willams [new album].au   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\street love plies.mp3   WMA/TrojanDownloader.GetCodec.C trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\that aint love myxx - high quality.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\that aint love myxx.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\tlc - greatest hits.wma   WMA/TrojanDownloader.Wimad.N trojan   cleaned by deleting - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\trina Patch.zip   Win32/Delf.NWU trojan   deleted - quarantined
C:\Users\HP User\Documents\LimeWire\Saved\usher - simple things.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan   cleaned - quarantined
I was able to download the new version of Adobe Reader.As you can see most of your infections came from downloading with Limewire. I hope that you uninstalled it from your computer.

How's your computer working now?yes i did see that ... and i did uninstall it a long while ago ...

it's running fine now ... the internet is freezing up a little bit ... do you think it would help to update my browser ? Quote

do you think it would help to update my browser
Any program that is out-of-date is susceptible to infections. Let's do some cleanup.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type commy /uninstall in the runbox
* Make SURE there's a space between commy and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
********************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
****************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the SCAN to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations ALWAYS update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

Edited.
1615.

Solve : Think Point Virus?

Answer» I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart INSTALLER. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can TAKE some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Hi! Dave,
After a few attempts, i finally succeeded to download the ESET.
I unchecked the box "remove found threats", because i was not sure you wanted it that way. You didn't mention if i needded to keep it on not.
Here is the results of the scan:
C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll   Win32/Adware.Toolbar.Dealio application
C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe   Win32/Adware.Toolbar.Dealio application
C:\Program Files\YouTube Downloader Toolbar\WidgiHelper.exe   Win32/Adware.Toolbar.Dealio application
C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll   Win32/Adware.Toolbar.Dealio application
C:\Windows\Installer\6bcc6a.msi   Win32/Adware.Toolbar.Dealio application
Operating memory   Win32/Adware.Toolbar.Dealio application
Waiting your intructions eagerly.
Regards,
Yves
Please run it again and check "remove found threats".Hi! Dave,
Here is the results:
C:\Program Files\YouTube Downloader Toolbar\SearchSettings.dll   Win32/Adware.Toolbar.Dealio application   cleaned by deleting (after the next restart) - quarantined
C:\Program Files\YouTube Downloader Toolbar\SearchSettings.exe   Win32/Adware.Toolbar.Dealio application   cleaned by deleting - quarantined
C:\Program Files\YouTube Downloader Toolbar\WidgiHelper.exe   Win32/Adware.Toolbar.Dealio application   cleaned by deleting - quarantined
C:\Program Files\YouTube Downloader Toolbar\IE\1.0\youtubedownloaderToolbarIE.dll   Win32/Adware.Toolbar.Dealio application   cleaned by deleting - quarantined
C:\Users\Yves\AppData\Local\Temp\NOD349B.tmp   Win32/Adware.Toolbar.Dealio application   cleaned by deleting (after the next restart) - quarantined
C:\Windows\Installer\6bcc6a.msi   Win32/Adware.Toolbar.Dealio application   deleted - quarantined

Regards, YvesHow's your computer running now?. Any issues?Hi! Dave,
My PC seem to be O.K, but how can i make sure there is nothing left from that" Think Point" on it?
There is still some names of files on the "Windows Task Manager", how can i get rid of them? See additional.    atiedxx.exe, csrss.exe, winlogon.exe 
Regards, Yveshere is the additional

[recovering disk space - old attachment deleted by admin] Quote
atiedxx.exe
This is a file for your video card.

Quote
csrss.exe
The Microsoft Client Server Runtime Server subsystem utilizes the process csrss.exe for managing the majority of the graphical instruction sets under the Microsoft Windows operating system.

Quote
winlogon.exe 
winlogon.exe is a process belonging to the Windows login manager. It handles the login and logout procedures on your system. This program is important for the stable and secure running of your computer and should not be terminated.

You can google all those files to find out what are their functions .
Let's see if you can run ComboFix again as OUTLINED in Reply #9

Hi! Dave,
O.K , i run the ComboFix and here is the results:
ComboFix 10-11-09.01 - Yves 10/11/2010   5:47.1.2 - x86
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.61.1033.18.3070.2010 [GMT 10:00]
Running from: c:\users\Yves\Desktop\commy.exe
Command switches used :: /stepdel
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\arp.exe
G:\Autorun.inf

c:\windows\system32\userinit.exe . . . is infected!!

.
(((((((((((((((((((((((((   Files Created from 2010-10-09 to 2010-11-09  )))))))))))))))))))))))))))))))
.

2010-11-09 20:47 . 2010-11-09 20:47   --------   d-----w-   c:\users\Default\AppData\Local\temp
2010-11-09 08:06 . 2010-10-07 23:21   6146896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{44CDFD57-B753-47D5-9915-893F16DBC98A}\mpengine.dll
2010-11-09 04:26 . 2010-11-09 04:26   --------   d-----w-   c:\program files\Vodafone
2010-11-03 04:36 . 2010-11-03 04:36   --------   d-----w-   c:\program files\Common Files\Java
2010-11-03 04:35 . 2010-11-03 04:35   --------   d-----w-   c:\program files\Sun
2010-11-03 04:32 . 2010-11-03 04:34   --------   d-----w-   c:\program files\Java
2010-11-03 02:59 . 2010-11-03 02:59   --------   d-----w-   c:\users\Yves\AppData\Roaming\Malwarebytes
2010-11-03 02:59 . 2010-11-08 23:32   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2010-11-03 02:59 . 2010-11-03 02:59   --------   d-----w-   c:\programdata\Malwarebytes
2010-11-02 23:16 . 2010-11-02 23:16   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2010-10-26 20:45 . 2010-08-04 06:18   641536   ----a-w-   c:\windows\system32\CPFilters.dll
2010-10-26 20:45 . 2010-08-04 06:17   417792   ----a-w-   c:\windows\system32\msdri.dll
2010-10-26 20:45 . 2010-08-04 06:15   204288   ----a-w-   c:\windows\system32\MSNP.ax
2010-10-26 20:45 . 2010-08-04 06:15   199680   ----a-w-   c:\windows\system32\mpg2splt.ax
2010-10-26 20:39 . 2010-07-13 05:22   26504   ----a-w-   c:\windows\system32\drivers\Diskdump.sys
2010-10-23 11:36 . 2010-10-23 11:36   --------   d-----w-   c:\programdata\5D
2010-10-23 10:25 . 2010-10-23 11:28   --------   d-----w-   c:\users\Yves\AppData\Local\BearShare
2010-10-23 10:18 . 2010-10-23 20:49   --------   dc-h--w-   c:\programdata\~0
2010-10-23 10:18 . 2010-10-23 10:18   --------   d-----w-   c:\users\Yves\AppData\Local\PackageAware
2010-10-20 14:18 . 2010-10-20 14:18   --------   d-----w-   c:\windows\en
2010-10-20 14:18 . 2010-10-20 14:18   --------   dc----w-   c:\windows\system32\DRVSTORE
2010-10-20 14:18 . 2010-09-22 14:21   39272   ----a-w-   c:\windows\system32\drivers\fssfltr.sys
2010-10-20 14:13 . 2010-10-20 14:13   --------   d-----w-   c:\program files\MSN Toolbar
2010-10-20 14:13 . 2010-10-20 14:14   --------   d-----w-   c:\program files\Bing Bar Installer
2010-10-20 14:13 . 2009-09-04 07:44   69464   ----a-w-   c:\windows\system32\XAPOFX1_3.dll
2010-10-20 14:13 . 2009-09-04 07:44   515416   ----a-w-   c:\windows\system32\XAudio2_5.dll
2010-10-20 14:13 . 2009-09-04 07:29   453456   ----a-w-   c:\windows\system32\d3dx10_42.dll
2010-10-20 14:12 . 2010-10-20 14:12   469256   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c76b1f1e1cb70602b\InstallManager_WLE_WLE.exe
2010-10-20 14:11 . 2010-10-20 14:11   15712   ----a-w-   c:\program files\Common Files\Windows Live\.cache\b5d373971cb706020\MeshBetaRemover.exe
2010-10-20 14:11 . 2010-10-20 14:11   94040   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\DSETUP.dll
2010-10-20 14:11 . 2010-10-20 14:11   525656   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\DXSETUP.exe
2010-10-20 14:11 . 2010-10-20 14:11   1691480   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a5a337da1cb706018\dsetup32.dll
2010-10-20 14:11 . 2010-10-20 14:11   525656   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\DXSETUP.exe
2010-10-20 14:11 . 2010-10-20 14:11   1691480   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\dsetup32.dll
2010-10-20 14:11 . 2010-10-20 14:11   94040   ----a-w-   c:\program files\Common Files\Windows Live\.cache\a40e8dec1cb706017\DSETUP.dll
2010-10-20 14:09 . 2010-11-06 03:26   --------   d-----w-   c:\users\Yves\AppData\Local\Windows Live
2010-10-20 14:09 . 2010-05-23 10:15   1619456   ----a-w-   c:\windows\system32\WMVDECOD.DLL
2010-10-20 14:09 . 2010-05-23 10:11   196608   ----a-w-   c:\windows\system32\mfreadwrite.dll
2010-10-20 14:09 . 2010-05-23 10:11   3181568   ----a-w-   c:\windows\system32\mf.dll
2010-10-15 21:34 . 2010-05-05 06:46   363520   ----a-w-   c:\windows\system32\StructuredQuery.dll
2010-10-15 21:03 . 2010-08-21 05:36   738816   ----a-w-   c:\windows\system32\wmpmde.dll
2010-10-15 21:01 . 2010-09-01 04:26   164864   ----a-w-   c:\program files\Windows Media Player\wmplayer.exe
2010-10-15 21:01 . 2010-09-01 04:23   12625408   ----a-w-   c:\windows\system32\wmploc.DLL
2010-10-15 21:01 . 2010-09-01 02:34   2327552   ----a-w-   c:\windows\system32\win32k.sys
2010-10-15 21:01 . 2010-08-27 05:46   168448   ----a-w-   c:\windows\system32\srvsvc.dll
2010-10-15 21:01 . 2010-08-27 03:31   310784   ----a-w-   c:\windows\system32\drivers\srv.sys
2010-10-15 21:01 . 2010-08-27 03:30   308736   ----a-w-   c:\windows\system32\drivers\srv2.sys
2010-10-15 21:01 . 2010-08-27 03:30   113664   ----a-w-   c:\windows\system32\drivers\srvnet.sys

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-03 04:35 . 2010-07-27 22:47   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2010-10-19 01:41 . 2010-07-26 23:48   222080   ------w-   c:\windows\system32\MpSigStub.exe
2010-09-22 14:47 . 2010-09-22 14:47   49016   ----a-w-   c:\windows\system32\sirenacm.dll
2010-09-22 14:32 . 2010-09-22 14:32   301936   ----a-w-   c:\windows\WLXPGSS.SCR
2010-09-21 04:03 . 2010-09-21 04:03   208768   ----a-w-   c:\windows\system32\LIVESSP.DLL
2010-08-25 20:48 . 2010-08-25 20:48   53248   ----a-r-   c:\users\Yves\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-08-21 05:32 . 2010-09-15 06:16   316928   ----a-w-   c:\windows\system32\spoolsv.exe
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-09-29 2942856]
"AnyTime Organizer"="c:\program files\AnyTime Organizer Premier\AtDem.exe" [2007-11-21 29696]
"E09AXLRD_2727443"="c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE" [2008-06-03 351000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-07-20 1038848]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-06-25 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^AnyTime.lnk]
path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AnyTime.lnk
backup=c:\windows\pss\AnyTime.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^FastStone Capture.lnk]
path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FastStone Capture.lnk
backup=c:\windows\pss\FastStone Capture.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Yves^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Yves\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2010-03-27 06:07   362232   ----a-w-   c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adm_tray.exe]
2010-06-04 08:49   530768   ----a-w-   c:\program files\Acronis\DriveMonitor\adm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 13:07   932288   ----a-r-   c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-22 18:47   35760   ----a-w-   c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-05 17:44   500208   ------w-   c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-07-22 12:10   402432   ----a-w-   c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyTime Organizer]
2007-11-21 03:45   29696   ----a-w-   c:\progra~1\ANYTIM~1\AtDem.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
2010-09-29 05:30   2942856   ----a-w-   c:\program files\DU Meter\DUMeter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_15580131]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2163780]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2494237]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_2519946]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_25437101]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_31464294]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_5542044]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_5633040]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_582850]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_6173833]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_6696436]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_738477]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_8550430]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_9218411]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E09AXLRD_969171]
2008-06-03 10:05   351000   ----a-w-   c:\program files\Microsoft Encarta\Encarta Premium DVD 2009\EDICT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 06:13   54576   ----a-w-   c:\program files\HP\HP Software Update\hpwuschd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2010-10-22 20:47   353736   ----a-w-   c:\program files\IncrediMail\Bin\IncMail.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2010-07-21 06:52   1797008   ----a-w-   c:\program files\Microsoft IntelliPoint\ipoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2010-07-21 07:07   1778064   ----a-w-   c:\program files\Microsoft IntelliType Pro\itype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
2010-05-11 06:43   6061400   ----a-w-   c:\program files\Logitech\Vid\Vid.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid HD]
2010-05-11 06:43   6061400   ----a-w-   c:\program files\Logitech\Vid\Vid.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2010-05-07 08:35   165208   ----a-w-   c:\program files\Logitech\LWS\Webcam Software\LWS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 00:17   5252408   ----a-w-   c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileBroadband]
2010-06-25 02:57   253952   ----a-w-   c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RESTART_STICKY_NOTES]
2009-07-14 01:14   354304   ----a-w-   c:\windows\System32\StikyNot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 01:44   248552   ----a-w-   c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 03:37   517096   ----a-w-   c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2010-03-27 06:06   5107232   ----a-w-   c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorldTime2006]
2007-10-21 07:17   1486848   ----a-w-   c:\program files\AnyTime Organizer Premier\WorldTime.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-09-29 18576]
R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [2010-06-15 35568]
R3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\DRIVERS\massfilter.sys [2010-06-10 9216]
R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 20992]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-27 1343400]
R3 zgwhsdiag;ZTE WCDMA Handset Diagnostic Port;c:\windows\system32\DRIVERS\zgwhsdiag.sys [2009-10-28 105216]
R3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\DRIVERS\zgwhsmdm.sys [2009-10-28 105216]
R3 zgwhsnmea;WCDMA Handset NMEA Port;c:\windows\system32\DRIVERS\zgwhsnmea.sys [2009-10-28 105216]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\DRIVERS\tdrpm258.sys [2010-07-27 911680]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-07-27 2480048]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-03 176128]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-02-19 380928]
S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-09-29 1412488]
S2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2010-06-15 26352]
S2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2010-06-15 493032]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-06-25 9216]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-07-27 160704]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-03 6096384]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-03 214016]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2010-07-07 44432]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [2010-03-01 61952]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2010-04-30 105856]
S3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\DRIVERS\ZTEusbwwan.sys [2010-06-10 194048]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
nosGetPlusHelper   REG_MULTI_SZ      nosGetPlusHelper
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
TCP: {E481D8DE-43C8-4878-B42D-DD2FAEC18884} = 202.124.65.22 202.124.65.18
.
- - - - ORPHANS REMOVED - - - -

BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll
Toolbar-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - c:\progra~1\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll
HKLM-Run-atr.exe - (no file)
MSConfigStartUp-DATAMNGR - c:\progra~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE
MSConfigStartUp-SearchSettings - c:\program files\YouTube Downloader Toolbar\SearchSettings.exe
AddRemove-Hoadley Options Strategy Evaluation Tool_is1 - c:\program files\HoadleyOptions\unins000.exe



[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
Denied: (A) (Users)
Denied: (A) (Everyone)
Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3860)
c:\program files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
c:\program files\Common Files\Microsoft Shared\Encarta Search Bar\A\ESBRes.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Acronis\DriveMonitor\adm.exe
.
**************************************************************************
.
Completion time: 2010-11-10  07:20:44 - machine was rebooted
ComboFix-quarantined-files.txt  2010-11-09 21:20

Pre-Run: 313,216,090,112 bytes free
Post-Run: 313,234,837,504 bytes free

- - End Of File - - 15DBDB942C9E623E8AA909342BBEF4BF
Look a pretty long one and very impressive. Please, explain to me the results!
Should i delete "ComboFix" from my PC?
Best regards, YvesPlease download SystemLook from one of the links below and save it to your desktop.

Link # 1
Link # 2

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double-click SystemLook.exe to run it.

Copy the contents of the following codebox into the main textfield.
Code: [Select]:filefind
userinit.exe
Click the Look button to start the scan.

Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).

When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt

******************************
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel HOOKS << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was

extracted to. Open the text file and copy/paste the log here.
[/list]
Hi! Dave,
Here are the results of the scan with " SystemLook".
Regards,
Yves
SystemLook 04.09.10 by jpshortstuff
Log created at 09:23 on 11/11/2010 by Yves
Administrator - Elevation successful

========== filefind ==========

Searching for "userinit.exe "
C:\Windows\ERDNT\cache\userinit.exe   --a---- 26112 bytes   [21:08 09/11/2010]   [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\System32\userinit.exe   --a---- 26112 bytes   [23:34 13/07/2009]   [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe   --a---- 26112 bytes   [23:34 13/07/2009]   [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175

-= EOF =-Hi! Dave,
Here are the results with the scan    SysProtAntirootkit   
SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
No Hidden Kernel Modules found

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
No hidden files/folders found
I am happy with the results.
Regards,
YvesOk. Let's see if we can fix that corrupted/infected file.

Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    Quote
    KillAll::

    FCopy::
    C:\Windows\ERDNT\cache\userinit.exe | c:\windows\system32\userinit.exe

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
Hi! Dave,
Here i am not sure....
I got the "commy.exe" and it is this one i have to use and drag "CFScript.txt" in it.
Or re-download the original ComboFix?
Regards, YvesYes, use the one you have on your desktop.
1616.

Solve : AV8? antimalwarelist pop up while surfing?

Answer»

Hi,
I have a client with a computer (Dell Vista 32 bit) that was very infected.
I've gone thru the CH process (see attached logs). SAS and MBAM found and cleaned several infections. I believe all is well now except that while surfing to some sites (Adobe downloads for example) both Chrome and IE get redirected to/by "antimalwarelist" showing a screen of a cop with a stop sign and 2 options.
I have not clicked on either option which I know will REINSTALL the Trojans again.
Any help in getting rid of this re-director WOULD be appreciated.

[recovering disk space - old attachment deleted by admin]Sorry. I have just READ the new INSTRUCTIONS on where and how to post logs.
I will post there.
Vlogg5No problem. I'll LOCK this thread.

1617.

Solve : Please help, being hijacked while web surfing...?

Answer»

Hey, I'm starting to get the hang of this computer stuff. I was able to disable StopZilla at startup and tried the ComboFix again. It ran the very first time! This is the log it produced...


ComboFix 10-10-12.03 - Wayne 10/14/2010  17:38:26.4.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2031.1262 [GMT -5:00]
Running from: c:\documents and settings\Wayne\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Wayne\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\TEMP\q6m3suwq.vbt
.
---- Previous Run -------
.
c:\windows\system32\ccrpTmr6.dll

.
(((((((((((((((((((((((((   Files Created from 2010-09-14 to 2010-10-14  )))))))))))))))))))))))))))))))
.

2010-10-10 19:10 . 2010-10-10 20:26   --------   d-----w-   c:\documents and settings\Wayne\Local Settings\Application Data\Temp
2010-10-07 00:41 . 2010-10-07 00:41   --------   d-----w-   c:\program files\7-Zip
2010-10-05 18:22 . 2010-10-05 18:22   --------   d-----w-   c:\documents and settings\Wayne\Application Data\Foxit Software
2010-09-29 19:13 . 2010-10-14 22:17   --------   d-----w-   c:\program files\Mozilla Thunderbird
2010-09-26 20:50 . 2010-09-26 20:51   --------   d-----w-   c:\documents and settings\Wayne\Application Data\PCToolsFirewallPlus
2010-09-26 20:46 . 2009-11-23 18:54   88040   ----a-w-   c:\windows\system32\drivers\PCTAppEvent.sys
2010-09-26 20:46 . 2009-11-09 16:20   207792   ----a-w-   c:\windows\system32\drivers\PCTCore.sys
2010-09-26 20:45 . 2010-01-07 17:40   233136   ----a-w-   c:\windows\system32\drivers\pctgntdi.sys
2010-09-26 20:44 . 2010-09-26 20:46   --------   d-----w-   c:\program files\Common Files\PC Tools
2010-09-26 20:44 . 2010-01-12 14:34   70664   ----a-w-   c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-09-26 20:44 . 2010-01-07 16:35   58816   ----a-w-   c:\windows\system32\drivers\pctNdis.sys
2010-09-26 20:44 . 2010-01-07 16:35   32680   ----a-w-   c:\windows\system32\drivers\pctNdis-DNS.sys
2010-09-26 20:44 . 2010-01-13 13:59   115216   ----a-w-   c:\windows\system32\drivers\pctplfw.sys
2010-09-26 20:44 . 2010-09-28 03:24   --------   d-----w-   c:\program files\PC Tools Firewall Plus
2010-09-26 09:53 . 2010-09-26 09:54   --------   d-----w-   c:\program files\CCleaner
2010-09-25 15:42 . 2010-09-25 15:42   --------   d-----w-   c:\program files\STOPzilla!
2010-09-25 15:42 . 2010-10-14 22:55   --------   d-----w-   c:\documents and settings\All Users\Application Data\STOPzilla!
2010-09-25 15:42 . 2010-09-25 15:42   --------   d-----w-   c:\program files\Common Files\iS3
2010-09-25 05:00 . 2010-09-25 05:00   --------   d-----w-   C:\671feffc3b70b88a397bd6f620fbac40
2010-09-24 16:25 . 2010-09-25 19:46   --------   d-----w-   c:\program files\UnHackMe
2010-09-24 15:57 . 2010-09-24 16:26   2   --shatr-   c:\windows\winstart.bat
2010-09-24 01:33 . 2010-09-24 01:33   12872   ----a-w-   c:\windows\system32\bootdelete.exe
2010-09-24 01:26 . 2010-10-12 00:34   16968   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
2010-09-24 01:23 . 2010-09-24 01:33   --------   d-----w-   c:\documents and settings\All Users\Application Data\Hitman Pro
2010-09-24 01:23 . 2010-09-24 01:23   --------   d-----w-   c:\program files\Hitman Pro 3.5
2010-09-21 06:28 . 2010-10-07 22:26   --------   d-----w-   c:\program files\ESET
2010-09-20 23:08 . 2010-09-20 23:08   546256   ----a-r-   c:\windows\system32\SZComp5.dll
2010-09-20 23:08 . 2010-09-20 23:08   22992   ----a-r-   c:\windows\system32\SZIO5.dll
2010-09-20 23:08 . 2010-09-20 23:08   132560   ----a-r-   c:\windows\system32\IS3HTUI5.dll
2010-09-20 23:08 . 2010-09-20 23:08   99792   ----a-r-   c:\windows\system32\IS3Svc5.dll
2010-09-20 23:08 . 2010-09-20 23:08   67024   ----a-r-   c:\windows\system32\IS3Hks5.dll
2010-09-20 23:08 . 2010-09-20 23:08   452048   ----a-r-   c:\windows\system32\SZBase5.dll
2010-09-20 23:08 . 2010-09-20 23:08   398800   ----a-r-   c:\windows\system32\IS3DBA5.dll
2010-09-20 23:08 . 2010-09-20 23:08   28624   ----a-r-   c:\windows\system32\IS3XDat5.dll
2010-09-20 23:08 . 2010-09-20 23:08   99792   ----a-r-   c:\windows\system32\IS3Inet5.dll
2010-09-20 23:08 . 2010-09-20 23:08   738768   ----a-r-   c:\windows\system32\IS3Base5.dll
2010-09-20 23:08 . 2010-09-20 23:08   390608   ----a-r-   c:\windows\system32\IS3UI5.dll
2010-09-20 23:08 . 2010-09-20 23:08   230864   ----a-r-   c:\windows\system32\IS3Win325.dll
2010-09-16 00:51 . 2010-09-16 00:51   --------   d-----w-   c:\program files\WinPcap

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 19:43 . 2008-09-06 19:16   67688   ----a-w-   c:\program files\mozilla firefox\components\jar50.dll
2008-12-21 19:43 . 2008-09-06 19:16   54368   ----a-w-   c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-21 19:43 . 2008-09-06 19:16   34944   ----a-w-   c:\program files\mozilla firefox\components\myspell.dll
2008-12-21 19:43 . 2008-09-06 19:16   46712   ----a-w-   c:\program files\mozilla firefox\components\spellchk.dll
2008-12-21 19:43 . 2008-09-06 19:16   172136   ----a-w-   c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GOOGLE Update"="c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-10-10 136176]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-10-11 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"VTPreset"="VTPreset.exe" [2004-02-25 45056]
"BtcMaestro"="c:\program files\KMaestro\KMaestro.exe" [2004-05-05 237568]
"EssSpkPhone"="essspk.exe" [2002-05-31 167936]
"basicsmssmenu"="c:\program files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe" [2007-10-09 169328]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-04 2067808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-05-20 86016]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-08-09 45056]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-19 805392]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-7-25 114688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2009-10-08 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-19 00:47   12536   ----a-w-   c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42   72208   ----a-w-   c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cloudmark SpamNet for OE.lnk]
backup=c:\windows\pss\Cloudmark SpamNet for OE.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dpcstart.lnk]
backup=c:\windows\pss\dpcstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Wayne^Start Menu^Programs^Startup^ClickTray Calendar.lnk]
backup=c:\windows\pss\ClickTray Calendar.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2c\\RpcAgentSrv.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2c\\WNt500x86\\RpcSandraSrv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [12/7/2009 5:59 PM 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [5/12/2010 6:01 PM 59280]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/27/2008 11:57 PM 216400]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/27/2008 11:57 PM 243024]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [9/26/2010 3:45 PM 233136]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/29/2008 4:03 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/29/2008 4:03 PM 67656]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [7/18/2010 7:46 PM 921440]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/18/2010 7:47 PM 308136]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [5/29/2010 8:14 PM 20072]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [9/26/2010 3:46 PM 88040]
R2 SnapTHN;SnapTHN;c:\windows\system32\drivers\SNAPTHN.SYS [2/23/1998 5:56 PM 31104]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [9/26/2010 3:44 PM 70664]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [9/26/2010 3:44 PM 58816]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [9/26/2010 3:44 PM 115216]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [12/7/2009 5:59 PM 61328]
S3 Dual Mode;Dual Mode Video Capture;c:\windows\system32\DRIVERS\CoachVc.sys --> c:\windows\system32\DRIVERS\CoachVc.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 3:22 PM 34064]
S3 nuvaudio;Hauppauge WinTV USB Pro Audio Service;c:\windows\system32\DRIVERS\nuvaudio.sys --> c:\windows\system32\DRIVERS\nuvaudio.sys [?]
S3 NuVision;Hauppauge WinTV USB Live Pro;c:\windows\system32\drivers\Nuvision.sys [12/19/2002 3:56 PM 260144]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 4:51 PM 12872]
S3 USBNDIS;%USBNDIS.Service.DispName%;c:\windows\system32\DRIVERS\usbndis.sys --> c:\windows\system32\DRIVERS\usbndis.sys [?]
S4 DPCUSB;Satellite Receiver USB Driver;c:\windows\system32\Drivers\DPCUSB.sys --> c:\windows\system32\Drivers\DPCUSB.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-10-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-10-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006Core.job
- c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-10 19:10]

2010-10-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006UA.job
- c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-10 19:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.canoe.ca/
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=localhost:8080
IE: Refresh Pa≥ with Full Quality - c:\program files\MTS Accelerator\pac-page.html
IE: Refresh Pi&cture with Full Quality - c:\program files\MTS Accelerator\pac-image.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\
FF - prefs.js: browser.startup.homepage - hxxp://en.canoe.ca/home.html
FF - prefs.js: keyword.URL - hxxp://www.veerboo.com/results.php?q=
FF - component: c:\documents and settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\extensions\[email protected]\components\PACMozComponent.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
- - - - ORPHANS REMOVED - - - -

Notify-TPSvc - TPSvc.dll
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
AddRemove-{E1E502E2-C006-49DB-9C0C-F2196E51826F}_is1 - c:\documents and settings\Wayne\Desktop\RkU3.8.388.590\MustBeRandomlyNamed\unins000.exe


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8F7EC739-D5DE-8DF0-851B2E09AF27478A}\{9DB8FF8F-3E0D-CA6E-8233451919EA27FD}\{89229253-B827-099C-CFFB852028D69EA1}*]
"WE6X3HNHJXRI2CPMH2OUMP32VF1"=hex:01,00,01,00,00,00,00,00,6d,db,9e,e2,89,b8,a5,
   65,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\program files\KMaestro\HidKeybd.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\iS3\Anti-Spyware\SZServer.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\System32\locator.exe
c:\program files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\essspk.exe
c:\documents and settings\Wayne\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\STOPzilla!\STOPzilla.exe
.
**************************************************************************
.
COMPLETION time: 2010-10-14  18:09:12 - machine was rebooted
ComboFix-quarantined-files.txt  2010-10-14 23:08

Pre-Run: 275,573,174,272 bytes free
Post-Run: 275,562,561,536 bytes free

- - End Of File - - DB88A25472011ED62CAB7C60CB122CBB
Jacked again. Ran the OTL scan (Minimal Output, LOP & Purity checked)

OTL logfile created on: 10/14/2010 10:15:19 PM - Run 9
OTL by OldTimer - Version 3.2.15.1     Folder = C:\Documents and Settings\Wayne\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 360 720 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 256.63 Gb Free Space | 86.09% Space Free | Partition Type: NTFS
 
Computer Name: OWNER-X35LSKRDA | User Name: Wayne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Documents and Settings\Wayne\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Wayne\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
PRC - C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
PRC - C:\Program Files\MTS Accelerator\PropelAC.exe (Propel Software Corporation)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe (SiSoftware)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe (Maxtor Corporation)
PRC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe (Seagate Technology LLC)
PRC - C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
PRC - C:\Program Files\KMaestro\Kmaestro.exe (BTC)
PRC - C:\WINDOWS\essspk.exe ()
PRC - C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Documents and Settings\Wayne\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)
MOD - C:\WINDOWS\system32\hid.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\KMaestro\HidKeybd.dll (BTC)
 
 
========== Win32 Services (SafeList) ==========
 
SRV - (AppMgmt) -- C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (szserver) -- C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) -- C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (PCToolsFirewallPlus) -- C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
SRV - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (SandraAgentSrv) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\RpcAgentSrv.exe (SiSoftware)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (Basics Service) -- C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe (Seagate Technology LLC)
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (USBNDIS) -- C:\WINDOWS\System32\DRIVERS\usbndis.sys File not found
DRV - (nuvaudio) -- C:\WINDOWS\System32\DRIVERS\nuvaudio.sys File not found
DRV - (LMouKE) -- C:\WINDOWS\System32\Drivers\LMouKE.sys File not found
DRV - (LHidUsbK) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys File not found
DRV - (Dual Mode) -- C:\WINDOWS\System32\DRIVERS\CoachVc.sys File not found
DRV - (DPCUSB) -- C:\WINDOWS\System32\Drivers\DPCUSB.sys File not found
DRV - (CoachUsb) -- C:\WINDOWS\System32\DRIVERS\CoachUsb.sys File not found
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AvgTdiX) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (szkgfs) -- C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (cpuz133) -- C:\WINDOWS\system32\drivers\cpuz133_x32.sys (Windows (R) Win 7 DDK provider)
DRV - (pctplfw) -- C:\WINDOWS\system32\drivers\pctplfw.sys (PC Tools)
DRV - (PCTFW-PacketFilter) -- C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys (PC Tools)
DRV - (pctgntdi) -- C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctNDIS) -- C:\WINDOWS\system32\drivers\pctNdis.sys (PC Tools)
DRV - (szkg5) -- C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) -- C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (PCTAppEvent) -- C:\WINDOWS\system32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (FiltUSBEMPIA) -- C:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) -- C:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (DCamUSBEMPIA) -- C:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (SANDRA) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP2c\WNt500x86\sandra.sys (SiSoftware)
DRV - (LUsbFilt) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (L8042Kbd) -- C:\WINDOWS\system32\drivers\L8042Kbd.sys (Logitech, Inc.)
DRV - (USB28xxBGA) -- C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) -- C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (emAudio) -- C:\WINDOWS\system32\drivers\emAudio.sys (eMPIA Technology, Inc.)
DRV - (Afc) -- C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (videX32) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) -- C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (NuVision) -- C:\WINDOWS\system32\drivers\Nuvision.sys (Hauppauge Computer Works)
DRV - (S3Psddr) -- C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Edspport) -- C:\WINDOWS\system32\drivers\es56hpi.sys (ESS Technology, Inc.)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (viaagp1) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (VIAPFD) -- C:\WINDOWS\System32\Drivers\VIAPFD.SYS (VIA Technologies. Inc.)
DRV - (ViaIde) -- C:\WINDOWS\System32\DRIVERS\viaidexp.sys (VIA Technologies, Inc.)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (SnapTHN) -- C:\WINDOWS\System32\drivers\SNAPTHN.SYS (Play Incorporated)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.canoe.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:8080
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginen ame: "www.google-feed.net"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en.canoe.ca/home.html"
FF - prefs.js..extensions.enabledItems: {34274bf4-1d97-a289-e984-17e546307e4f}:0.5.3.043
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.0
FF - prefs.js..extensions.enabledItems: {1d5287d1-8a92-0001-1f31-1cec198018d8}:2.0.20080718
FF - prefs.js..extensions.enabledItems: {F8CC37C3-CBEB-4A00-8CBF-26A88693F0C5}:2.2008.5.13
FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:1.6.4
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:3.13
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.3.1
FF - prefs.js..keyword.URL: "http://www.veerboo.com/results.php?q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/09/24 19:05:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/30 23:33:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/30 23:33:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/09/29 14:13:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/10/05 13:21:09 | 000,000,000 | ---D | M]
 
[2010/09/22 13:59:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Extensions
[2010/09/22 13:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/14 21:53:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\extensions
[2008/09/07 19:21:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\extensions\[email protected]
[2010/09/15 19:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\extensions\SearchHelper
[2008/05/27 22:59:05 | 000,001,162 | ---- | M] () -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\searchplugins\dictionary.xml
[2010/09/15 19:51:59 | 000,000,003 | ---- | M] () -- C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\d1lib2qr.default\searchplugins\GoogleFeed.xml
[2010/10/14 21:53:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 00:24:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/21 02:47:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2008/12/20 00:22:20 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2008/12/21 14:43:06 | 000,067,688 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jar50.dll
[2008/12/21 14:43:06 | 000,054,368 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2008/12/21 14:43:06 | 000,034,944 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\myspell.dll
[2008/12/21 14:43:06 | 000,046,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2008/12/21 14:43:07 | 000,172,136 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/10/05 13:18:11 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
 
O1 HOSTS File: ([2010/10/14 17:53:21 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Accelerator Plugin) - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\MTS Accelerator\prpl_IePopupBlocker.dll (Propel Software Corporation)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [basicsmssmenu] C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe (Maxtor Corporation)
O4 - HKLM..\Run: [BtcMaestro] C:\Program Files\KMaestro\Kmaestro.exe (BTC)
O4 - HKLM..\Run: [CXMon] C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [EssSpkPhone] C:\WINDOWS\essspk.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
O4 - HKLM..\Run: [VTPreset] C:\WINDOWS\System32\VTPreset.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Refresh Pa≥ with Full Quality - C:\Program Files\MTS Accelerator\pac-page.html ()
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\MTS Accelerator\pac-image.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {33363249-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/i263_32.cab (Reg Error: Key error.)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37623.4285648148 (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\aptera.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\aptera.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/10/08 09:25:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [ = ComFile] -- "%1" %*
O37 - HKLM\...exe [ = exefile] -- "%1" %*
O37 - HKCU\...exe [ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010/10/14 18:21:35 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/10/14 17:49:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/10/14 17:35:58 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/10/13 20:52:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/10/13 20:35:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/10/11 23:42:12 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Wayne\Desktop\OTL.exe
[2010/10/10 14:10:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Local Settings\Application Data\Temp
[2010/10/10 00:52:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Art Stuff
[2010/10/10 00:50:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Desktop Nudes
[2010/10/10 00:44:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Fixed Folder
[2010/10/10 00:21:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\MyStuff
[2010/10/10 00:16:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Recipes
[2010/10/10 00:15:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Temp Pics
[2010/10/10 00:10:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Video Editing
[2010/10/10 00:10:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Desktop\Desktop
[2010/10/06 19:41:15 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010/10/05 13:22:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Application Data\Foxit Software
[2010/10/03 23:37:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/10/03 23:13:33 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/10/03 23:13:33 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/10/03 22:48:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\My Documents\New Folder
[2010/09/30 20:34:29 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Wayne\Recent
[2010/09/29 14:13:05 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2010/09/26 15:50:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\Application Data\PCToolsFirewallPlus
[2010/09/26 15:46:02 | 000,207,792 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/09/26 15:46:02 | 000,088,040 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/09/26 15:45:54 | 000,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/09/26 15:44:31 | 000,070,664 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.sys
[2010/09/26 15:44:31 | 000,058,816 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis.sys
[2010/09/26 15:44:31 | 000,032,680 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctNdis-DNS.sys
[2010/09/26 15:44:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/09/26 15:44:28 | 000,115,216 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplfw.sys
[2010/09/26 15:44:25 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Firewall Plus
[2010/09/26 04:53:45 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/09/25 10:42:24 | 000,000,000 | ---D | C] -- C:\Program Files\STOPzilla!
[2010/09/25 10:42:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/09/25 10:42:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2010/09/25 00:00:27 | 000,000,000 | ---D | C] -- C:\671feffc3b70b88a397bd6f620fbac40
[2010/09/24 11:25:08 | 000,000,000 | ---D | C] -- C:\Program Files\UnHackMe
[2010/09/24 10:54:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wayne\My Documents\RegRun2
[2010/09/23 20:33:42 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/09/23 20:23:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/09/23 20:23:20 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5
[2010/09/21 01:28:15 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/09/20 18:08:16 | 000,546,256 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZComp5.dll
[2010/09/20 18:08:16 | 000,132,560 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3HTUI5.dll
[2010/09/20 18:08:16 | 000,022,992 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZIO5.dll
[2010/09/20 18:08:14 | 000,452,048 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\SZBase5.dll
[2010/09/20 18:08:14 | 000,398,800 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3DBA5.dll
[2010/09/20 18:08:14 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Svc5.dll
[2010/09/20 18:08:14 | 000,067,024 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Hks5.dll
[2010/09/20 18:08:14 | 000,028,624 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3XDat5.dll
[2010/09/20 18:08:12 | 000,738,768 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Base5.dll
[2010/09/20 18:08:12 | 000,390,608 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3UI5.dll
[2010/09/20 18:08:12 | 000,230,864 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Win325.dll
[2010/09/20 18:08:12 | 000,099,792 | R--- | C] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Inet5.dll
[2010/09/15 19:51:20 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap
[2010/05/26 00:21:38 | 000,121,344 | ---- | C] ( ) -- C:\WINDOWS\System32\lagarith.dll
[2001/07/06 16:59:54 | 000,372,736 | ---- | C] (Ed Halley - http://www.halley.cc/stuff/) -- C:\Program Files\Dragnifier.exe
[24 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[126 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2010/10/14 22:15:10 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006UA.job
[2010/10/14 22:04:38 | 000,000,303 | ---- | M] () -- C:\WINDOWS\vuepro32.ini
[2010/10/14 22:03:51 | 000,100,660 | ---- | M] () -- C:\Documents and Settings\Wayne\Desktop\Puppy.jpg
[2010/10/14 18:18:39 | 066,317,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/14 18:10:29 | 000,000,520 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/10/14 17:54:22 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/10/14 17:53:21 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/14 17:52:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/14 14:15:01 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006Core.job
[2010/10/14 01:23:39 | 001,066,274 | ---- | M] () -- C:\WINDOWS\aptera.bmp
[2010/10/13 20:12:07 | 003,878,092 | R--- | M] () -- C:\Documents and Settings\Wayne\Desktop\ComboFix.exe
[2010/10/12 15:25:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/12 00:58:10 | 000,001,257 | ---- | M] () -- C:\WINDOWS\goldwave.ini
[2010/10/11 23:43:37 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Wayne\Desktop\OTL.exe
[2010/10/11 19:34:34 | 000,016,968 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/10/10 15:26:55 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Wayne\Desktop\Google Chrome.lnk
[2010/10/10 15:26:55 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/10 13:33:15 | 000,736,854 | ---- | M] () -- C:\WINDOWS\CNorris.bmp
[2010/10/09 23:20:30 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Preponvue2.bmp
[2010/10/08 00:49:40 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Preponvue.bmp
[2010/10/07 18:05:51 | 000,736,854 | ---- | M] () -- C:\WINDOWS\EmmaB.bmp
[2010/10/07 14:39:21 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Alicia2.bmp
[2010/10/07 00:23:32 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Abbyvue2.bmp
[2010/10/06 13:06:11 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Abbyvue.bmp
[2010/10/05 17:46:40 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Nikkivue2.bmp
[2010/10/05 14:22:00 | 000,736,854 | ---- | M] () -- C:\WINDOWS\Nikkivue.bmp
[2010/10/05 13:21:29 | 000,000,901 | ---- | M] () -- C:\Documents and Settings\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/10/03 23:37:58 | 000,000,337 | RHS- | M] () -- C:\boot.ini
[2010/10/01 23:35:41 | 000,960,054 | ---- | M] () -- C:\WINDOWS\Bugatti.bmp
[2010/10/01 14:35:35 | 000,000,657 | ---- | M] () -- C:\Documents and Settings\Wayne\Desktop\Shortcut to PropelAC.exe.lnk
[2010/09/30 17:48:29 | 000,979,254 | ---- | M] () -- C:\WINDOWS\ssc-ultimate-aero.bmp
[2010/09/30 11:42:57 | 001,274,454 | ---- | M] () -- C:\WINDOWS\Roadster2.bmp
[2010/09/30 10:31:47 | 001,200,054 | ---- | M] () -- C:\WINDOWS\Saleen_S7.bmp
[2010/09/30 08:43:24 | 001,440,054 | ---- | M] () -- C:\WINDOWS\car0.bmp
[2010/09/29 14:13:10 | 000,001,686 | ---- | M] () -- C:\Documents and Settings\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2010/09/24 11:26:37 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/09/24 11:26:37 | 000,001,688 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010/09/24 11:26:37 | 000,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat
[2010/09/23 20:33:42 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/09/23 17:00:03 | 001,440,998 | ---- | M] () -- C:\WINDOWS\car00.bmp
[2010/09/20 18:08:16 | 000,546,256 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZComp5.dll
[2010/09/20 18:08:16 | 000,132,560 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3HTUI5.dll
[2010/09/20 18:08:16 | 000,022,992 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZIO5.dll
[2010/09/20 18:08:14 | 000,452,048 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\SZBase5.dll
[2010/09/20 18:08:14 | 000,398,800 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3DBA5.dll
[2010/09/20 18:08:14 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Svc5.dll
[2010/09/20 18:08:14 | 000,067,024 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Hks5.dll
[2010/09/20 18:08:14 | 000,028,624 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3XDat5.dll
[2010/09/20 18:08:12 | 000,738,768 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Base5.dll
[2010/09/20 18:08:12 | 000,390,608 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3UI5.dll
[2010/09/20 18:08:12 | 000,230,864 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Win325.dll
[2010/09/20 18:08:12 | 000,099,792 | R--- | M] (iS3, Inc.) -- C:\WINDOWS\System32\IS3Inet5.dll
[2010/09/20 17:17:05 | 001,296,998 | ---- | M] () -- C:\WINDOWS\car10.bmp
[2010/09/20 14:56:40 | 001,440,998 | ---- | M] () -- C:\WINDOWS\Pagani-Zonda-Roadster.bmp
[2010/09/19 14:45:35 | 000,016,826 | -H-- | M] () -- C:\WINDOWS\vuepro32.GID
[2010/09/18 15:12:24 | 001,121,798 | ---- | M] () -- C:\WINDOWS\Bugatti Veyron2.bmp
[2010/09/18 14:45:20 | 000,896,198 | ---- | M] () -- C:\WINDOWS\Bugatti Veyron.bmp
[2010/09/18 02:11:51 | 001,356,054 | ---- | M] () -- C:\WINDOWS\McLaren2.bmp
[2010/09/18 01:39:44 | 001,083,398 | ---- | M] () -- C:\WINDOWS\McLaren3.bmp
[126 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2010/10/14 18:09:48 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/10/14 17:35:59 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/10/14 17:35:58 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/10/13 19:52:30 | 003,878,092 | R--- | C] () -- C:\Documents and Settings\Wayne\Desktop\ComboFix.exe
[2010/10/13 16:13:31 | 001,066,274 | ---- | C] () -- C:\WINDOWS\aptera.bmp
[2010/10/10 15:26:55 | 000,002,262 | ---- | C] () -- C:\Documents and Settings\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/10 15:26:54 | 000,002,284 | ---- | C] () -- C:\Documents and Settings\Wayne\Desktop\Google Chrome.lnk
[2010/10/10 14:10:50 | 000,000,978 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006UA.job
[2010/10/10 14:10:50 | 000,000,926 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3025990876-1698683601-3399203189-1006Core.job
[2010/10/10 13:29:25 | 000,736,854 | ---- | C] () -- C:\WINDOWS\CNorris.bmp
[2010/10/08 01:02:05 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Preponvue2.bmp
[2010/10/07 14:50:51 | 000,736,854 | ---- | C] () -- C:\WINDOWS\EmmaB.bmp
[2010/10/07 14:18:08 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Alicia2.bmp
[2010/10/07 00:23:32 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Abbyvue2.bmp
[2010/10/05 22:03:47 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Abbyvue.bmp
[2010/10/05 18:59:39 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Preponvue.bmp
[2010/10/04 19:47:56 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Nikkivue2.bmp
[2010/10/03 23:37:52 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/10/03 23:13:33 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/10/03 23:13:33 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/10/03 23:13:33 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/10/03 03:02:05 | 000,736,854 | ---- | C] () -- C:\WINDOWS\Nikkivue.bmp
[2010/10/01 14:35:35 | 000,000,657 | ---- | C] () -- C:\Documents and Settings\Wayne\Desktop\Shortcut to PropelAC.exe.lnk
[2010/09/28 18:29:34 | 001,274,454 | ---- | C] () -- C:\WINDOWS\Roadster2.bmp
[2010/09/26 15:46:02 | 000,007,412 | ---- | C] () -- C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/09/26 15:46:02 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2010/09/26 15:45:54 | 000,007,387 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/09/26 15:44:31 | 000,007,435 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctNdis-PacketFilter.cat
[2010/09/26 15:44:31 | 000,007,399 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctNdis-DNS.cat
[2010/09/26 15:44:28 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctplfw.cat
[2010/09/24 10:57:40 | 000,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat
[2010/09/23 20:26:06 | 000,016,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/09/23 17:00:03 | 001,440,998 | ---- | C] () -- C:\WINDOWS\car00.bmp
[2010/09/22 12:54:42 | 001,440,054 | ---- | C] () -- C:\WINDOWS\car0.bmp
[2010/09/20 17:17:05 | 001,296,998 | ---- | C] () -- C:\WINDOWS\car10.bmp
[2010/09/20 14:56:40 | 001,440,998 | ---- | C] () -- C:\WINDOWS\Pagani-Zonda-Roadster.bmp
[2010/09/18 15:12:25 | 001,121,798 | ---- | C] () -- C:\WINDOWS\Bugatti Veyron2.bmp
[2010/09/18 14:45:20 | 000,896,198 | ---- | C] () -- C:\WINDOWS\Bugatti Veyron.bmp
[2010/09/18 01:39:44 | 001,083,398 | ---- | C] () -- C:\WINDOWS\McLaren3.bmp
[2010/09/18 01:06:40 | 001,356,054 | ---- | C] () -- C:\WINDOWS\McLaren2.bmp
[2010/05/26 00:36:35 | 000,000,085 | ---- | C] () -- C:\WINDOWS\lagarith.ini
[2010/05/10 22:47:00 | 000,000,090 | ---- | C] () -- C:\WINDOWS\huffyuv.ini
[2010/04/21 22:46:50 | 000,000,568 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2010/01/17 03:44:57 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/01/17 03:44:57 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/01/17 03:44:54 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/01/17 03:44:54 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/01/17 03:44:51 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/12/15 00:38:54 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2009/08/01 20:55:29 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2009/08/01 20:55:29 | 000,038,912 | ---- | C] () -- C:\WINDOWS\System32\KPSYS32.DLL
[2008/05/30 13:31:47 | 007,151,616 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\sandra.mda
[2007/11/06 15:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/02/11 16:39:25 | 000,004,535 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/07 00:58:00 | 000,000,846 | ---- | C] () -- C:\WINDOWS\xxclone.ini
[2005/05/20 13:25:42 | 000,000,303 | ---- | C] () -- C:\WINDOWS\vuepro32.ini
[2005/05/16 19:40:23 | 000,000,433 | ---- | C] () -- C:\WINDOWS\System32\imgdatwin.dll
[2005/05/16 19:40:22 | 000,000,052 | ---- | C] () -- C:\WINDOWS\System32\imgstpath.dll
[2005/05/16 19:39:28 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\LtDlgRes14n.dll
[2005/05/08 19:17:22 | 000,024,575 | ---- | C] () -- C:\WINDOWS\System32\Winapppiobas50.dll
[2005/05/08 19:16:02 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2005/05/08 19:16:01 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2004/09/30 18:23:07 | 000,000,052 | ---- | C] () -- C:\WINDOWS\Pex.INI
[2004/09/30 18:15:44 | 000,000,440 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2004/09/17 17:37:42 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2004/09/06 19:04:09 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2004/09/01 10:49:17 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/08/27 01:00:32 | 000,000,086 | ---- | C] () -- C:\WINDOWS\POSTER.INI
[2004/08/19 16:33:08 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2004/07/13 12:12:22 | 000,000,583 | ---- | C] () -- C:\WINDOWS\videoimp.ini
[2004/04/06 14:28:53 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Wayne\Application Data\sversion.ini
[2004/04/01 12:40:14 | 000,000,263 | ---- | C] () -- C:\WINDOWS\phedit.ini
[2004/03/24 15:52:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\jppc.INI
[2004/03/19 15:36:51 | 002,270,720 | ---- | C] () -- C:\WINDOWS\Mgxrdr32.dll
[2004/03/19 15:36:51 | 000,046,080 | ---- | C] () -- C:\WINDOWS\LFTIF60N.DLL
[2004/03/19 15:36:51 | 000,043,008 | ---- | C] () -- C:\WINDOWS\LTFIL60N.DLL
[2004/03/19 15:36:51 | 000,019,968 | ---- | C] () -- C:\WINDOWS\LFTGA60N.DLL
[2004/03/19 15:36:50 | 000,141,824 | ---- | C] () -- C:\WINDOWS\LFCMP60N.DLL
[2004/03/19 15:36:50 | 000,110,080 | ---- | C] () -- C:\WINDOWS\LFPNG60N.DLL
[2004/03/19 15:36:50 | 000,023,552 | ---- | C] () -- C:\WINDOWS\LFPCX60N.DLL
[2004/03/19 15:36:50 | 000,022,016 | ---- | C] () -- C:\WINDOWS\LFGIF60N.DLL
[2004/03/19 15:36:50 | 000,020,480 | ---- | C] () -- C:\WINDOWS\LFPSD60N.DLL
[2004/03/19 15:36:50 | 000,018,432 | ---- | C] () -- C:\WINDOWS\LFRAS60N.DLL
[2004/03/19 15:36:18 | 000,399,350 | ---- | C] () -- C:\WINDOWS\ACCUGLD5.DLL
[2004/03/19 15:36:18 | 000,026,233 | ---- | C] () -- C:\WINDOWS\ACCUIFGL.DLL
[2004/02/09 04:25:28 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/11/08 18:43:56 | 000,000,005 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DirectCDUserNameD.txt
[2003/07/12 14:19:54 | 000,000,107 | ---- | C] () -- C:\WINDOWS\WEBLINK.INI
[2003/05/14 21:48:41 | 000,000,300 | ---- | C] () -- C:\WINDOWS\vuesav32.ini
[2003/05/14 11:03:50 | 000,004,673 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2003/02/08 21:41:09 | 000,000,036 | ---- | C] () -- C:\WINDOWS\cosdtp.ini
[2003/01/07 00:06:48 | 000,000,026 | ---- | C] () -- C:\WINDOWS\Magic40.INI
[2003/01/01 22:39:36 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2002/12/23 17:11:27 | 000,001,056 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2002/12/23 17:11:26 | 000,000,090 | ---- | C] () -- C:\WINDOWS\calera.ini
[2002/12/22 20:46:27 | 000,006,592 | ---- | C] () -- C:\WINDOWS\gwpreset.ini
[2002/12/22 20:46:27 | 000,001,257 | ---- | C] () -- C:\WINDOWS\goldwave.ini
[2002/12/22 18:25:52 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
[2002/12/21 20:37:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTSTACK.INI
[2002/12/21 15:19:17 | 000,007,411 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2002/12/19 15:56:11 | 000,009,206 | ---- | C] () -- C:\WINDOWS\NTTuner.ini
[2002/12/19 15:04:25 | 000,269,312 | ---- | C] () -- C:\WINDOWS\System32\FPXIG.DLL
[2002/12/19 15:04:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\System32\IGFPX32P.DLL
[2002/12/19 15:04:25 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\JPEGACC.DLL
[2002/12/19 15:04:02 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\WELSOF32.DLL
[2002/12/19 00:52:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MusicEditor.INI
[2002/12/19 00:52:36 | 000,001,871 | ---- | C] () -- C:\WINDOWS\mp3maker.INI
[2002/12/19 00:50:45 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2002/12/18 15:13:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\dpcnav.INI
[2002/12/18 15:05:00 | 000,026,112 | ---- | C] () -- C:\WINDOWS\System32\inavevnt.dll
[2002/12/17 19:49:46 | 000,000,896 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI
[2002/12/17 19:49:46 | 000,000,027 | ---- | C] () -- C:\WINDOWS\ACROGRAF.INI
[2002/12/17 00:20:57 | 000,001,952 | ---- | C] () -- C:\WINDOWS\SCANFX.INI
[2002/12/15 20:17:09 | 000,173,056 | ---- | C] () -- C:\Documents and Settings\Wayne\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002/10/30 15:49:12 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2002/10/08 11:02:24 | 000,001,112 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2002/10/08 04:14:05 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002/09/10 10:10:05 | 000,495,616 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2001/07/06 23:47:50 | 000,003,149 | ---- | C] () -- C:\Program Files\ReadMe.txt
[1999/10/06 17:48:28 | 000,016,476 | ---- | C] () -- C:\WINDOWS\System32\Snapv16.drv
 
========== LOP Check ==========
 
[2009/11/18 12:51:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/08 16:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2010/09/23 20:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2009/01/08 23:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2009/07/20 23:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2008/05/31 14:07:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/07/03 20:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2010/10/14 22:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/10/14 17:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/03 14:59:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2004/09/30 18:25:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/08/08 16:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2006/11/27 21:24:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\101 Software
[2010/06/06 19:14:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\DeepBurner
[2008/08/08 16:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\eBay
[2008/02/19 17:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Forte
[2009/04/01 02:19:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Foxit
[2010/10/05 13:22:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Foxit Software
[2009/03/07 02:27:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\GrabPro
[2010/09/09 13:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\gtk-2.0
[2009/04/24 13:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\hott notes 4
[2010/02/18 22:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\ImTOO Software Studio
[2008/09/22 15:35:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\IrfanView
[2009/05/01 13:35:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\K-Meleon
[2010/07/31 10:29:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Leadertech
[2010/01/18 23:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Leawo
[2006/11/28 09:48:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\M8 Software
[2008/01/25 12:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\MP3Rocket
[2010/10/10 14:10:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Opera
[2009/03/07 03:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Orbit
[2010/09/26 15:51:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\PCToolsFirewallPlus
[2010/01/13 22:34:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Pegasys Inc
[2010/05/11 05:12:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\STOIK
[2010/09/22 13:59:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Thunderbird
[2010/05/03 17:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Trusteer
[2002/12/18 03:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\Ulead Systems
[2008/12/24 01:59:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wayne\Application Data\XnView
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6

< End of report >
I've sent a pm to my mentor to look at this problem but it may take a few days for him to respond.I hope this is not too much of an inconvience to you.
SuperDave, no inconvience at all. You have been more than patient. I can wait.

WayneYour comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.I would not insult the intelligence of the kind people on this site, who volunteer their precious time and knowledge, by not doing as much as possible, to remedy the problem myself, using the self help posted here.Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2

  • Ensure all Firefox browser windows are closed.
  • To run the tool, DOUBLE-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
.

Hi SuperDave, I'm think I may have accidentally cured this problem by experimenting with Firefox. I removed it from my computer completely to see if this bug would somehow migrate to another browser (Chrome). I used it for a few days, with no sign of any hijacking. I then loaded Firefox again, and have been using it for several hours without incident, again, knock on wood. Below is the log...

GooredFix by jpshortstuff (03.07.10.1)
Log created at 02:08 on 21/10/2010 (Wayne)
Firefox version 2.0.0.11 (en-US)

========== GooredScan ==========

(none)

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
[email protected] [06:31 21/10/2010]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [06:31 21/10/2010]

C:\Documents and Settings\Wayne\Application Data\Mozilla\Firefox\Profiles\qddlnzpx.default\extensions\
(none)

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(Key not found)

-=E.O.F=-Well, that's good news. Let's give it a few days. If it's fixed post back again and we'll do whatever cleanup is necessary.Hi SuperDave, well I've given it a week of constant surfing so far, and there is no evidence that the bug is still around. I have used three different browsers and found no problem. Thanks kindly for all your patience. You mentioned something about a cleanup?That's good news. We'll just do some cleanup.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
**********************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp BUTTON.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
**************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*****************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

1618.

Solve : Lost my Post here? Facebook gave me virus.?

Answer»

You need to use Notepad.
To open Notepad, click Start, point to All Programs, point to Accessories, and then click Notepad.    
Thanks SuperDave, I got the report into notepad so here GOES... OK.



[recovering disk SPACE - old attachment deleted by admin]I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download UPDATES for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the CONTENTS of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt

1619.

Solve : "your system is infected" virus and also 'windows cannot access specified..'?

Answer»

I don't know if it would've actually affected Combofix or not, but I wasn't able to really disable AVG. I tried following the appropriate steps but it wouldn't let me disable anything. So I tried uninstalling it but that just failed multiple times. So I tried just deleting it which didn't quite work either (1 file wasn't able to be deleted). Just thought I'd add that incase it was important.You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

* ViewMgr.exe - Useless
* Viewpoint to Plunge Into Adware

It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

* Viewpoint
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
* Viewpoint Experience Technology

************************************

Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and COPY/paste the text in the quotebox below into it:
    Quote
    KillAll::

    Driver::
    DFBCFDBA

  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.
***********************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the BLACK box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
**********************************
Please try running SuperAntiSpyware and MalwareBytes-Antimalware and post the logs if you're successful.Combo fix log:
ComboFix 10-10-21.05 - Ryan 23/10/2010  12:33:02.4.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.64.1033.18.1982.1082 [GMT 13:00]
Running from: c:\users\Ryan\Desktop\commy.exe
Command switches used :: c:\users\Ryan\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_DFBCFDBA


(((((((((((((((((((((((((   Files Created from 2010-09-22 to 2010-10-22  )))))))))))))))))))))))))))))))
.

2010-10-22 23:47 . 2010-10-22 23:54   --------   d-----w-   c:\users\Ryan\AppData\Local\temp
2010-10-22 23:47 . 2010-10-22 23:47   --------   d-----w-   c:\users\Public\AppData\Local\temp
2010-10-22 23:47 . 2010-10-22 23:47   --------   d-----w-   c:\users\Guest\AppData\Local\temp
2010-10-22 23:47 . 2010-10-22 23:47   --------   d-----w-   c:\users\Guest(56)\AppData\Local\temp
2010-10-22 23:47 . 2010-10-22 23:47   --------   d-----w-   c:\users\Default\AppData\Local\temp
2010-10-22 23:26 . 2010-10-22 23:29   --------   dc----r-   C:\32788R22FWJFW
2010-10-22 08:08 . 2010-10-07 23:21   6146896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{A15205D0-8851-4AAD-B675-A6BFC9825264}\mpengine.dll
2010-10-18 02:01 . 2010-04-29 02:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-18 02:01 . 2010-04-29 02:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2010-10-17 08:31 . 2010-10-17 08:41   11952   ----a-w-   c:\windows\system32\avgrsstx.dll
2010-10-17 08:31 . 2010-10-17 08:41   335240   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2010-10-17 08:30 . 2010-10-17 08:41   27784   ----a-w-   c:\windows\system32\drivers\avgmfx86.sys
2010-10-17 08:30 . 2010-10-17 08:43   --------   d-----w-   c:\windows\system32\drivers\Avg
2010-10-15 09:47 . 2010-09-13 13:56   168960   ----a-w-   c:\program files\Windows Media Player\wmplayer.exe
2010-10-15 09:47 . 2010-09-13 13:56   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
2010-10-15 09:47 . 2010-09-06 16:20   125952   ----a-w-   c:\windows\system32\srvsvc.dll
2010-10-15 09:47 . 2010-09-06 13:45   304128   ----a-w-   c:\windows\system32\drivers\srv.sys
2010-10-15 09:47 . 2010-09-06 13:45   145408   ----a-w-   c:\windows\system32\drivers\srv2.sys
2010-10-15 09:47 . 2010-09-06 13:45   102400   ----a-w-   c:\windows\system32\drivers\srvnet.sys
2010-10-15 09:47 . 2010-09-06 16:19   17920   ----a-w-   c:\windows\system32\netevent.dll
2010-10-14 10:29 . 2010-10-14 10:29   --------   d-----w-   c:\program files\Trend Micro
2010-10-10 02:38 . 2010-10-10 02:38   --------   d-----w-   c:\program files\Giant Crocodile
2010-10-08 08:58 . 2010-10-08 08:58   --------   dc----w-   C:\$AVG
2010-10-08 06:08 . 2010-10-08 06:08   --------   dc----w-   C:\AVG10
2010-10-08 06:06 . 2010-10-08 06:06   --------   d--h--w-   c:\programdata\Common Files
2010-10-08 06:03 . 2010-10-14 08:43   --------   d-----w-   c:\programdata\AVG10
2010-10-08 05:51 . 2010-10-08 06:01   --------   d-----w-   c:\programdata\MFAData
2010-10-08 05:39 . 2010-10-18 19:05   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2010-09-30 08:28 . 2010-09-30 08:28   --------   d-----w-   c:\windows\Profiles
2010-09-29 07:54 . 2010-06-22 13:30   2048   ----a-w-   c:\windows\system32\tzres.dll
2010-09-28 11:31 . 2010-09-28 11:31   --------   d-----w-   c:\program files\iPod
2010-09-28 11:24 . 2010-09-28 11:24   --------   d-----w-   c:\program files\Bonjour

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-18 22:41 . 2010-02-11 13:33   222080   ------w-   c:\windows\system32\MpSigStub.exe
2010-09-13 03:27 . 2010-09-13 03:27   25680   ----a-w-   c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-07 22:17 . 2010-09-07 22:17   94208   ----a-w-   c:\windows\system32\QuickTimeVR.qtx
2010-09-07 22:17 . 2010-09-07 22:17   69632   ----a-w-   c:\windows\system32\QuickTime.qts
2010-08-17 14:11 . 2010-09-16 08:10   128000   ----a-w-   c:\windows\system32\spoolsv.exe
2010-07-27 05:44 . 2010-07-27 05:44   91424   ----a-w-   c:\windows\system32\dnssd.dll
2010-07-27 05:44 . 2010-07-27 05:44   107808   ----a-w-   c:\windows\system32\dns-sd.exe
2009-01-27 01:34 . 2009-01-27 01:34   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-08-25 01:52 . 2008-06-05 11:59   300400   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-17 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160]
"Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys

R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104]
R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe

R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System;

R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys

R3 WPFFontCache_v0400;Windows Presentation FOUNDATION Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
HPService   REG_MULTI_SZ      HPSLPSVC
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]

2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(6024)
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng-us.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\Apoint2K\Apntex.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-10-23  13:02:20 - machine was rebooted
ComboFix-quarantined-files.txt  2010-10-23 00:02
ComboFix2.txt  2010-10-22 11:35

Pre-Run: 2,451,070,976 bytes free
Post-Run: 2,405,908,480 bytes free

- - End Of File - - 07875887ABC7EAB551A8CE336F04D7D3

security check log:

 Results of screen317's Security Check version 0.99.5 
 Windows Vista Service Pack 2 (UAC is disabled!)
 Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Disabled! 
 Antivirus 2010     
 Antivirus up to date! 
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 HijackThis 2.0.2   
 CCleaner     
 Java(TM) 6 Update 19 
 Out of date Java installed!
 Adobe Flash Player 10.0.45.2 
Adobe Reader 9.3.4
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Windows Defender MSASCui.exe
 Spybot Teatimer.exe is disabled!
 Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe 
````````````````````````````````
DNS Vulnerability Check:


``````````End of Log````````````
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.
4. Run CCleaner.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

Were you able to run SAS and MBAM?Ok so I updated Java, and I was indeed able to run SAS and MBAM. Here are the logs:

MBAM:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

24/10/2010 5:37:04 p.m.
mbam-log-2010-10-24 (17-37-04).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 388506
Time elapsed: 2 hour(s), 3 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Ryan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk (Rogue.AntiVirus) -> Quarantined and deleted successfully.





SAS:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/25/2010 at 03:32 AM

Application Version : 4.44.1000

Core Rules Database Version : 5610
Trace Rules Database Version: 3422

Scan type       : Complete Scan
Total Scan Time : 04:20:54

Memory items scanned      : 694
Memory threats detected   : 0
Registry items scanned    : 10461
Registry threats detected : 0
File items scanned        : 246934
File threats detected     : 165

Adware.Tracking Cookie
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][3].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   acvs.mediaonenetwork.net [ C:\Users\Guest(56)\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\4JC7KVSW ]
   C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Guest(56)\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .peertracking.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .*adult URL* [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .doubleclick.net [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .msnportal.112.2o7.net [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bs.serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   acvs.mediaonenetwork.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   api.firestormmedia.tv [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   banners.securedataimages.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   cdn2.themis-media.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   cdn4.specificclick.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   content.oddcast.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   core.insightexpressai.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   i.*adult URL* [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   ia.media-imdb.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   ictv-ic-ec.indieclicktv.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   indieclick.3janecdn.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   media.kyte.tv [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   media.mtvnservices.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   media.scanscout.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   media.socialvibe.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   media1.break.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   movies.hdteenmovs.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   msnbcmedia.msn.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   naiadsystems.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   objects.tremormedia.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   rmd.atdmt.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   s0.2mdn.net [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   secure-us.imrworldwide.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   www.naiadsystems.com [ C:\Users\Ryan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ZAKAE62E ]
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
   .warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   www.warez-bb.org [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .mediaonenetwork.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   imagevenue.advertserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   imagevenue.advertserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .ero-advertising.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .microsoftsto.112.2o7.net [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .*adult URL* [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   dc.tremormedia.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .adserver.adtechus.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   rts.pgmediaserve.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
   .partypoker.com [ C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\cookies.sqlite ]
Please download ComboFix from BleepingComputer.com

Alternate link: GeeksToGo.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
Click Start then copy paste the following command into the search box & hit enter: "%userprofile%\desktop\commy.exe" /stepdel
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install.
When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

If you have problems with ComboFix usage, see How to use ComboFixHi, sorry for taking so long to reply, been a bit busy with exams.
Heres the new combofix log:

ComboFix 10-10-31.04 - Ryan 01/11/2010  23:23:59.5.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.64.1033.18.1982.1020 [GMT 13:00]
Running from: c:\users\Ryan\Desktop\commy.exe
Command switches used :: /stepdel
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\arp.exe

.
(((((((((((((((((((((((((   Files Created from 2010-10-01 to 2010-11-01  )))))))))))))))))))))))))))))))
.

2010-11-01 10:33 . 2010-11-01 10:34   --------   d-----w-   c:\users\Ryan\AppData\Local\temp
2010-11-01 10:33 . 2010-11-01 10:33   --------   d-----w-   c:\users\Public\AppData\Local\temp
2010-11-01 10:33 . 2010-11-01 10:33   --------   d-----w-   c:\users\Guest\AppData\Local\temp
2010-11-01 10:33 . 2010-11-01 10:33   --------   d-----w-   c:\users\Guest(56)\AppData\Local\temp
2010-11-01 10:33 . 2010-11-01 10:33   --------   d-----w-   c:\users\Default\AppData\Local\temp
2010-10-31 08:11 . 2010-08-26 16:34   1696256   ----a-w-   c:\windows\system32\gameux.dll
2010-10-31 08:11 . 2010-08-26 16:33   28672   ----a-w-   c:\windows\system32\Apphlpdm.dll
2010-10-31 08:11 . 2010-08-26 14:23   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2010-10-31 08:11 . 2010-10-07 23:21   6146896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{A68C4A42-4035-43FD-A738-1CF0B1EDD3D0}\mpengine.dll
2010-10-28 05:38 . 2010-10-28 05:38   --------   d-----w-   c:\windows\en
2010-10-28 05:38 . 2010-09-22 11:21   39272   ----a-w-   c:\windows\system32\drivers\fssfltr.sys
2010-10-28 05:28 . 2009-09-04 04:44   69464   ----a-w-   c:\windows\system32\XAPOFX1_3.dll
2010-10-28 05:28 . 2009-09-04 04:44   515416   ----a-w-   c:\windows\system32\XAudio2_5.dll
2010-10-28 05:28 . 2009-09-04 04:29   453456   ----a-w-   c:\windows\system32\d3dx10_42.dll
2010-10-28 01:18 . 2010-10-28 01:18   469256   ----a-w-   c:\program files\Common Files\Windows Live\.cache\e31dd701cb763e2b\InstallManager_WLE_WLE.exe
2010-10-28 01:17 . 2010-10-28 01:17   15712   ----a-w-   c:\program files\Common Files\Windows Live\.cache\e6008ef01cb763d1f\MeshBetaRemover.exe
2010-10-28 01:16 . 2010-10-28 01:16   525656   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\DXSETUP.exe
2010-10-28 01:16 . 2010-10-28 01:16   94040   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\DSETUP.dll
2010-10-28 01:16 . 2010-10-28 01:16   1691480   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c9252b101cb763d18\dsetup32.dll
2010-10-28 01:16 . 2010-10-28 01:16   94040   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\DSETUP.dll
2010-10-28 01:16 . 2010-10-28 01:16   525656   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\DXSETUP.exe
2010-10-28 01:16 . 2010-10-28 01:16   1691480   ----a-w-   c:\program files\Common Files\Windows Live\.cache\c62001601cb763d17\dsetup32.dll
2010-10-28 01:14 . 2010-11-01 09:57   --------   d-----w-   c:\users\Ryan\AppData\Local\Windows Live
2010-10-28 01:12 . 2009-08-04 08:02   754688   ----a-w-   c:\windows\system32\webservices.dll
2010-10-25 05:24 . 2010-10-25 05:24   --------   d-----w-   c:\program files\Common Files\Java
2010-10-25 05:23 . 2010-09-14 15:50   472808   ----a-w-   c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-10-25 05:23 . 2010-09-14 15:50   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2010-10-24 10:09 . 2010-10-24 10:09   --------   d-----w-   c:\users\Ryan\AppData\Roaming\SUPERAntiSpyware.com
2010-10-18 02:01 . 2010-04-29 02:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-18 02:01 . 2010-04-29 02:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2010-10-17 08:31 . 2010-10-17 08:41   11952   ----a-w-   c:\windows\system32\avgrsstx.dll
2010-10-17 08:31 . 2010-10-17 08:41   335240   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2010-10-17 08:30 . 2010-10-17 08:41   27784   ----a-w-   c:\windows\system32\drivers\avgmfx86.sys
2010-10-17 08:30 . 2010-10-17 08:43   --------   d-----w-   c:\windows\system32\drivers\Avg
2010-10-15 09:47 . 2010-09-13 13:56   168960   ----a-w-   c:\program files\Windows Media Player\wmplayer.exe
2010-10-15 09:47 . 2010-09-13 13:56   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
2010-10-15 09:47 . 2010-09-06 16:20   125952   ----a-w-   c:\windows\system32\srvsvc.dll
2010-10-15 09:47 . 2010-09-06 13:45   304128   ----a-w-   c:\windows\system32\drivers\srv.sys
2010-10-15 09:47 . 2010-09-06 13:45   145408   ----a-w-   c:\windows\system32\drivers\srv2.sys
2010-10-15 09:47 . 2010-09-06 13:45   102400   ----a-w-   c:\windows\system32\drivers\srvnet.sys
2010-10-15 09:47 . 2010-09-06 16:19   17920   ----a-w-   c:\windows\system32\netevent.dll
2010-10-14 10:29 . 2010-10-14 10:29   --------   d-----w-   c:\program files\Trend Micro
2010-10-10 02:38 . 2010-10-10 02:38   --------   d-----w-   c:\program files\Giant Crocodile
2010-10-08 08:58 . 2010-10-08 08:58   --------   dc----w-   C:\$AVG
2010-10-08 06:06 . 2010-10-08 06:06   --------   d--h--w-   c:\programdata\Common Files
2010-10-08 06:03 . 2010-10-14 08:43   --------   d-----w-   c:\programdata\AVG10
2010-10-08 05:51 . 2010-10-08 06:01   --------   d-----w-   c:\programdata\MFAData
2010-10-08 05:39 . 2010-10-18 19:05   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-18 22:41 . 2010-02-11 13:33   222080   ------w-   c:\windows\system32\MpSigStub.exe
2010-09-22 11:47 . 2010-09-22 11:47   49016   ----a-w-   c:\windows\system32\sirenacm.dll
2010-09-22 11:32 . 2010-09-22 11:32   301936   ----a-w-   c:\windows\WLXPGSS.SCR
2010-09-13 03:27 . 2010-09-13 03:27   25680   ----a-w-   c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-07 22:17 . 2010-09-07 22:17   94208   ----a-w-   c:\windows\system32\QuickTimeVR.qtx
2010-09-07 22:17 . 2010-09-07 22:17   69632   ----a-w-   c:\windows\system32\QuickTime.qts
2010-08-26 16:33 . 2010-10-31 08:11   173056   ----a-w-   c:\windows\apppatch\AcXtrnal.dll
2010-08-26 16:33 . 2010-10-31 08:11   2159616   ----a-w-   c:\windows\apppatch\AcGenral.dll
2010-08-26 16:33 . 2010-10-31 08:11   458752   ----a-w-   c:\windows\apppatch\AcSpecfc.dll
2010-08-26 16:33 . 2010-10-31 08:11   542720   ----a-w-   c:\windows\apppatch\AcLayers.dll
2010-08-17 14:11 . 2010-09-16 08:10   128000   ----a-w-   c:\windows\system32\spoolsv.exe
2009-01-27 01:34 . 2009-01-27 01:34   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-08-25 01:52 . 2008-06-05 11:59   300400   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160]
"Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-13 248552]

c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys

R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104]
R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe

R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System;

R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
HPService   REG_MULTI_SZ      HPSLPSVC
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

2010-11-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

2010-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]

2010-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\
FF - prefs.js: network.proxy.ftp - proxy.student.otago.ac.nz
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.gopher - proxy.student.otago.ac.nz
FF - prefs.js: network.proxy.gopher_port - 3128
FF - prefs.js: network.proxy.http - proxy.student.otago.ac.nz
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - proxy.student.otago.ac.nz
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - proxy.student.otago.ac.nz
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-01 23:34
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-11-01  23:36:42
ComboFix-quarantined-files.txt  2010-11-01 10:36
ComboFix2.txt  2010-10-23 00:02
ComboFix3.txt  2010-10-22 11:35

Pre-Run: 1,443,819,520 bytes free
Post-Run: 1,573,527,552 bytes free

- - End Of File - - 7C743AE4BF11B6BBE5462453976BC3C7
Is your computer working any better?

SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.
  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.
    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected
  • At the bottom of the page
    • Hidden Objects Only << Selected
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was

extracted to. Open the text file and copy/paste the log here.
[/list]
My computer is definitely working a lot better than it was before, although there a still a few things happening that never really HAPPENED before. Sometimes programs like Internet Explorer or iTunes randomly decide to crash. Also, if I click the button on my mouse that brings up the magnifying glass tool, everything pauses and the screen goes black for about a second before going back to normal. Those small issues are the only ones I'm noticing though.
Here's the Sysprot Antirootkit log:

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: ---
Module Base: 8CFBD000
Module End: 8CFC8000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: 8CFC8000
Module End: 8CFD0000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwTerminateProcess
Address: 8CED9620
Driver Base: 8CECF000
Driver End: 8CEF1000
Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Object: C:\Users\Ryan\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{DAC71EAD-ED09-F966-DCD5-DFD0F8DB3CC1}\01\10-{DAC71EAD-ED09-F966-DCD5-DFD0F8DB3CC1}-v1-{DB34C54A-12AB-43EE-B476-02BEB35A910F
Status: Hidden

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl
Status: Access denied

Quote
Sometimes programs like Internet Explorer or iTunes randomly decide to crash. Also, if I click the button on my mouse that brings up the magnifying glass tool, everything pauses and the screen goes black for about a second before going back to normal. Those small issues are the only ones I'm noticing though.
Those sound like hardware or software problems. Let's continue.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Here is the log from the ESET online scan:

C:\Qoobox\Quarantine\C\Windows\PRAGMAyrtxnwrcjt\PRAGMAc.dll.vir   a variant of Win32/Kryptik.EXT trojan   cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Windows\System32\drivers\agp440.sys.vir   a variant of Win32/Rootkit.Kryptik.BS trojan   cleaned by deleting - quarantined
C:\SWSetup\AOLIMS\setup.exe   probably a variant of Win32/Agent.HZHBURL trojan   cleaned by deleting - quarantined
C:\Users\Ryan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\30cd253-2667789e   multiple threats   deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3G8ZRRT0\INSTALL[1]   Win32/Adware.Antivirus2010 application   cleaned by deleting - quarantined
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3G8ZRRT0\script[1]   Win32/Adware.Antivirus2010 application   cleaned by deleting - quarantined
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P4APQ21N\dialog_alert[1]   Win32/Adware.Antivirus2010 application   cleaned by deleting - quarantined
That looks good. If there are no other issues, let's do some cleanup.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type commy /uninstall in the runbox
* Make sure there's a space between commy and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
*********************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing! 

1620.

Solve : Due to this scan my PC is safe??

Answer»

Glad it GOT resolved.

When you see the error again, make SURE you STOP using the computer and come BACK here as it may be a SIGN that your hard drive is failing.

1621.

Solve : I hope I did this correct?

Answer»

Before doing this, could we try and understand what all this will be doing to the computer? Like those 3 things you say to put a checkmark by. We want to make sure this will not cause me to not be able to do certain things anymore with any of my accounts. Those are my useraccounts I use on Funtrivia. Funtrivia is a website that I make quizzes on. So, I want to make sure I wont be accidently removing any of my quizzes I've made.


Yes, I did report to you what is going on. The long list of problems is STILL happening. Sorry if we are misunderstanding something here.
Everyones computer is set up different so if I am asking you to do something that does not sound right then I don't mind you making sure I'm not going the wrong direction

Quote

# N3 - Netscape 7: user_pref(\"browser.startup.homepage\", \"http://www.funtrivia.com\"); (C:\Documents and Settings\AMYR\Application Data\Mozilla\Profiles\default\3c1q6q2g.slt\prefs.js)
# N3 - Netscape 7: user_pref(\"browser.search.defaultengine\", \"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src\"); (C:\Documents and Settings\AMYR\Application Data\Mozilla\Profiles\default\3c1q6q2g.slt\prefs.js)

I have never seen an entry in a HJT log like this. You can skip that part if you are sure it is needed but you do need to be sure to fix the other entry.

Quote
Fix This! -> F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I
Quote from: evilfantasy on May 16, 2009, 07:10:39 PM
Everyones computer is set up different so if I am asking you to do something that does not sound right then I don't mind you making sure I'm not going the wrong direction

I have never seen an entry in a HJT log like this. You can skip that part if you are sure it is needed but you do need to be sure to fix the other entry.


Is funtrivia.com the default homepage you have set your FIREFOX browser to? That's what it looks like to me ... when i saw that funtrivia.com thing. You sure that's a good site?

But in all honesty, evilfantasy's one of the masters of malware on ths board as far as I've seen I should have researched first before requesting that you fix it. You never can think you have learned all there is to know with HijackThis...

It's definitely legitimate. The prefs.js made me think it was a iFrame infection. OOPS

Quote
HijackThis N1, N2, N3, N4 Sections


These sections are for Netscape and Mozilla Browsers Start and default search pages.

These entries are stored in the prefs.js files stored in different places under the C:\Documents and Settings\YourUserName\Application Data folder. Netscape 4's entries are stored in the prefs.js file in the program directory which is generally, DriveLetter:\Program Files\Netscape\Users\default\prefs.js.

N1 corresponds to the Netscape 4's Startup Page and default search page.

N2 corresponds to the Netscape 6's Startup Page and default search page.

N3 corresponds to Netscape 7' Startup Page and default search page.

N4 corresponds to Mozilla's Startup Page and default search page.

Files Used: prefs.js
Sorry if I'm asking too much. Also, thank you again for all the help you all are giving too.
Before continuing on with things, just want to double check that I'm understanding the steps to do and do you still need the other logs 2. SUPERAntiSpyware Log
The only problem I'm having with the above is I did get the SuperAntiSpyware thing to work but only thing on that one is there are 2 logs I have for that one because noticed that I missed something on the Scanning Control tab thing the options, I accidently messed up with that one and had other things checked too. So, should I POST both logs? I noticed that one of the logs it found something that I'm now wondering if that is half my problems some program called- Adware.eXactAdvertising-Installer
I typed that in on my mom's computer to see if I could figure more out about what exactly it is. It mentioned something about CPU usage going up, and that is one of my problems I keep having problems with my CPU usage going up to 100% ever since switching from Earthlink Dialup to Bellsouth DSL.
3. Malwarebytes' Anti-Malware Log
I can't even get the Malwarebytes program to install at all on the computer. It keeps looking for the disc when I take it out.

Yes, funtrivia is what I have for my start page. I thought that we could put in anything we want?
Looks like it's a good thing I haven't done anything yet either since now looking like I don't need to do anything at all with those pref.js things.
I noticed you said you need to be sure though on the other one? I just asked my mom and she doesn't understand it either.
Also, thought we would mention that our computers are hooked up together. So, making sure some of what is being detected is stuff from her computer? Since my computer keeps getting infected with viruses and spyware so much, is one of the things my mom is afraid of that it can harm her computer somehow? See before with dialup internet we didn't have our computers hooked together.

The other thing, I'm trying to understand what all the Combofix does. One of the things I noticed it says Windows Vista, and I don't have Windows Vista. So, will it even work? I'm looking at the page to see if I understand what all it even is, and looks a little scary. Do I need to back anything up before doing this? Like save things to a disc in case it erases something important? We just get so worried about this happening especially since it has happend on so many occasions in the past with us not understanding things all the way. The very first time something happend was when a technician at Compaq had us do an FDisk and before doing it we asked if I need to back anything up? They said no. Which was wrong because it erased everything. Then when I talked to a friend in Michigan who knows alot on computers because he even builds computers said that is what an FDisk does. It reformats things. Which we didn't know that. Also, have had problems with other programs in the past like Ccleaner erasing important stuff because we didn't understand what exactly the files are.
Go back to This Post and follow through with those instructions.

Quote
The other thing, I'm trying to understand what all the Combofix does. One of the things I noticed it says Windows Vista, and I don't have Windows Vista. So, will it even work?

Read the instructions. It says "Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

You are not a Vista user so it doesn't apply.

Just follow the instructions. Everything you need to do will always be there.

Quote
Also, have had problems with other programs in the past like Ccleaner erasing important stuff because we didn't understand what exactly the files are.

Again, just follow the instructions in This Post. That's all I need for now.

sorry for all the questions too. but due to my health and disabilities is hard for me to understand and do things in life. I get confused really easily.
I'm reading back over things. Could you explain to me though what exactly that thing is? F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I
We did a search on the internet about it and sounds like it's a bug in the new HJT and someone says not to worry about it. Looking at the word REG sounds like it has something to do with the Registry, which we are a bit worried about doing things to the Registry since we don't understand it at all and the repairmen we have used in the past have all warned us too about not messing with the Registry. We are also wondering, why did the last repairman we had work on the computer right before Christmas not do anything about this file if it is something bad? Quote
Looking at the word REG sounds like it has something to do with the Registry, which we are a bit worried about doing things to the Registry since we don't understand it at all and the repairmen we have used in the past have all warned us too about not messing with the Registry.

HijackThis is a registry information and repair tool. You are going to have to trust that I know what I'm doing

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I <- This is a Serial Key Utility and it is a big security risk. I hope you're alright ... just take things slowly one step at a time and you'll be good soon. Just now get up to speed and evil's gonna help you out some more

Combofix is a really nice program to have when your pc is really sick once you know what it can do for you, at least it's successfully cured my pc of issues when I last used it Sorry that we are asking so many questions but we would like to understand all these computer stuff better and all. I hope you can understand why we want to understand everything going on due to all the problems over the years and technicians we have tried in the past who have told us things to do that cause worse problems, and then if you need to know everything that has been done on the computer so that you can give the next technicians all the details of what all has been done to the computer that may have caused the problems. Also, thought you said it was ok to ask too since especially the one thing too you didn't know about the default start pages for Mozilla and Netscape.
Only thing about the Serial Key thing is we do have to enter in a serial key for some of the products we use.
Oh HijackThis does have to do with the registry? Wasn't sure. See, this one repairman we used right before the one we used right before Christmas blamed us for doing something wrong when we called him after he was working on the computer and caused my scanner to BREAK and ever since then have not been able to get it working again. See we were getting him to help us with some of the stuff this other site was having us do to the computer after reading the HijackThis Log. Which we actually didn't do anything they said to do though since didn't know how to do some of the things anyways. He didn't agree on alot of what they said to do. So, we didn't do it. So, anyways, he was going to charge to come back out and help get the scanner working again.

First, trust Evilfantasy. He knows what he's doing. Why do you think he is a Malware Removal Specialist? He deals with HijackThis every day on dozens of computers.
Second, trust me for telling you to trust him.
Third, Everything you do involves the registry in some way. All HijackThis does is scan through the registry to look for potential security threats, which you can choose to eliminate.
If it's any consolation, I've used HiJackThis, and I run scans every few weeks to see if anything is out of line.


From where I see it, you have two choices. End this topic and keep your computer at risk of attack, or end your fussing and eliminate the security risk.Quote from: Carbon Dudeoxide on May 17, 2009, 01:17:46 AM
First, trust Evilfantasy. He knows what he's doing. Why do you think he is a Malware Removal Specialist? He deals with HijackThis every day on dozens of computers.
Second, trust me for telling you to trust him.
Third, Everything you do involves the registry in some way. All HijackThis does is scan through the registry to look for potential security threats, which you can choose to eliminate.
If it's any consolation, I've used HiJackThis, and I run scans every few weeks to see if anything is out of line.


From where I see it, you have two choices. End this topic and keep your computer at risk of attack, or end your fussing and eliminate the security risk.

I suggest you should follow the instructions, get the problems solved then afterwards you can go find out the reasons behind what you have done (unless you find something fishy while fixing then that's something else). At least your computer will be happier quicker which is what you want in the end anyway.

Quote from: Carbon Dudeoxide on May 17, 2009, 01:17:46 AM
From where I see it, you have two choices. End this topic and keep your computer at risk of attack, or end your fussing and eliminate the security risk.

Agreed. I don't mind answering questions but I learned everything I know the hard way and I'm not going to start teaching a class here. There comes a point when I have to ask the user.

Are you going to post the logs or not? If not then that's fine. If so then please do so.

Although we volunteer our time it is work for me having to read all of these long questions and they are not helping in a resolution.

Quote from: evilfantasy on May 16, 2009, 03:35:00 PM
Only report to me what problems you are having at this immediate moment, things that were happening does me no good.

Honestly, we could most likely have been done with this yesterday!

With all due respect, it's beginning to be a waste of my time.

P.S. You need to move away from using Netscape. It is no longer supported and very vulnerable to malware attack. It's a Java based browser and that is very insecure.This is Amy's mom writing. Sorry for all the questions and for misunderstanding anything here, Yes, we understand that he is a Malware Removal Specialist. But due to mistakes others have made in the past on our computers, that is why we want to make sure it is the right thing to do before doing it so that it doesn't cause any wore problems.
I don't understand why you are now SAYING that you don't need to know everything that is happening with the computer. From what we learned, whenever dealing with techs, they want to know the history in case it has to do with what is going on.
Plus since the stuff is still happening, isn't that important to know what all has been tried so far.
Also, my computer is hooked up with Amy's, where it wasn't in the past, and my Grandson who knows way more about computers than I do, has mentioned to be careful what people tell us to do because could mess mine up.

Yes, we know that Netscape isn't out there anymore, but have used it for years with no problems. Her Internet Explorer stopped working though years ago due to being attacked when downloading the AOL Instant Messanger for her class she had just signed up for and some MBKWBar Toolbar came through with the download and started causing popup ads to keep flooding and crash the computer. Which that is the first time we learned about spyware, adware, all that. We did know about viruses, but not the other. So, the repairman we used then said not to use IE anymore and never bothered to fix it. He did put Mozilla on. But now that is not on her computer anymore due to virus messing it up to where everything becomes distorted when trying to use it. So, it seems every browser out there is vulnerable. We also try and read all articles and stuff out there on computer stuff, and understand that its very complicated.
Again, sorry if we have caused any problems for you. Sounds like maybe this isn't the best place for us to get help. We understand this is alot of work for you and every other computer techs out there. See everytime we have called for tech support, they always want to know what all has been done so far on computer. Isn't that helpful so that you don't waste your time doing something again that has already been tried?
If we are now understanding this right, HiJackThis just has to do with security? Does it not find viruses or spyware?
Sounds like maybe this isn't the best place for us to get help.


your the first iv'e seen saying that on here , i think you should keep paying the

REPAIRMEN because it looks like you do not trust what you are

being told on here , harry 48


1622.

Solve : Privacy Center malware!!! =/?

Answer»

ComboFix 09-06-26.02 - XP User 06/27/2009 19:01.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.227 [GMT -4:00]
Running from: c:\documents and settings\XP User\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-06-27 )))))))))))))))))))))))))))))))
.

2009-06-27 02:41 . 2009-06-27 02:41--------d-----w-c:\documents and settings\XP User\WINDOWS
2009-06-26 08:25 . 2009-06-26 08:25--------d-----w-c:\documents and settings\LocalService\Application Data\SACore
2009-06-26 02:25 . 2009-06-26 02:25--------d-----w-c:\program files\Windows Doctor
2009-06-26 01:39 . 2009-06-26 01:39--------d-----w-c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-06-26 01:39 . 2009-06-26 01:39--------d-----w-c:\program files\SiteAdvisor
2009-06-26 01:31 . 2009-06-26 01:32--------d-----w-c:\program files\McAfee.com
2009-06-26 01:14 . 2009-06-27 02:39--------dc----w-c:\windows\system32\dllcache\cache
2009-06-25 23:26 . 2009-06-27 22:59--------d-----w-c:\windows\system32\CatRoot2
2009-06-25 22:28 . 2009-05-14 03:2540552----a-w-c:\windows\system32\DRIVERS\mfesmfk.sys
2009-06-25 22:28 . 2009-05-14 03:2579816----a-w-c:\windows\system32\drivers\mfeavfk.sys
2009-06-25 22:28 . 2009-05-14 03:2535272----a-w-c:\windows\system32\drivers\mfebopk.sys
2009-06-25 22:28 . 2009-04-09 18:23120136----a-w-c:\windows\system32\drivers\Mpfp.sys
2009-06-25 22:26 . 2009-06-26 01:32--------d-----w-c:\program files\Common Files\McAfee
2009-06-25 22:25 . 2009-06-26 01:38--------d-----w-c:\program files\McAfee
2009-06-25 22:24 . 2009-05-14 03:2434248----a-w-c:\windows\system32\drivers\mferkdk.sys
2009-06-25 22:21 . 2009-06-26 02:21--------d-----w-c:\documents and settings\All Users\Application Data\McAfee
2009-06-25 22:09 . 2009-06-25 22:09--------d-----w-c:\documents and settings\All Users\Application Data\Geek Squad

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 00:03 . 2008-07-13 02:27--------d-----w-c:\documents and settings\XP User\Application Data\LimeWire
2009-06-25 23:51 . 2008-07-13 02:02--------d-----w-c:\program files\Common Files\Symantec Shared
2009-06-25 23:50 . 2008-07-13 02:03--------d-----w-c:\program files\Symantec
2009-06-25 23:50 . 2008-07-13 02:02--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
2009-06-25 23:18 . 2008-08-23 14:53--------d-----w-c:\program files\iTunes
2009-05-14 03:25 . 2008-06-27 10:08214024----a-w-c:\windows\system32\drivers\mfehidk.sys
2009-05-07 15:44 . 2004-08-10 12:00344064----a-w-c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 12:00827392----a-w-c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 12:0078336----a-w-c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2004-08-10 12:001846656----a-w-c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-10 12:00584192----a-w-c:\windows\system32\rpcrt4.dll
2009-04-06 04:07 . 2008-07-12 20:4290112----a-w-c:\windows\DUMP62e0.tmp
.

((((((((((((((((((((((((((((( [emailprotected]_02.38.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-13 02:41 . 2007-11-30 12:3917272 c:\windows\system32\spmsg.dll
+ 2008-07-13 02:41 . 2008-07-09 07:3817272 c:\windows\system32\spmsg.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5644544 c:\windows\system32\pngfilt.dll
- 2004-08-10 12:00 . 2009-02-20 18:0944544 c:\windows\system32\pngfilt.dll
+ 2004-08-10 12:00 . 2009-06-27 22:5946450 c:\windows\system32\perfc009.dat
- 2004-08-10 12:00 . 2009-06-27 02:3246450 c:\windows\system32\perfc009.dat
- 2007-08-13 22:54 . 2009-02-20 18:0952224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 22:54 . 2009-04-29 04:5552224 c:\windows\system32\msfeedsbs.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5527648 c:\windows\system32\jsproxy.dll
- 2004-08-10 12:00 . 2009-02-20 18:0927648 c:\windows\system32\jsproxy.dll
+ 2007-08-13 22:39 . 2009-04-28 09:0513824 c:\windows\system32\ieudinit.exe
- 2007-08-13 22:39 . 2009-02-20 10:2013824 c:\windows\system32\ieudinit.exe
- 2004-08-10 12:00 . 2009-02-20 18:0944544 c:\windows\system32\iernonce.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5544544 c:\windows\system32\iernonce.dll
- 2004-08-10 12:00 . 2009-02-20 10:2070656 c:\windows\system32\ie4uinit.exe
+ 2004-08-10 12:00 . 2009-04-28 09:0570656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 22:36 . 2009-04-29 04:5563488 c:\windows\system32\icardie.dll
- 2007-08-13 22:36 . 2009-02-20 18:0963488 c:\windows\system32\icardie.dll
- 2004-08-10 12:00 . 2009-02-20 18:0944544 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5644544 c:\windows\system32\dllcache\pngfilt.dll
- 2008-07-30 21:22 . 2009-02-20 18:0952224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-07-30 21:22 . 2009-04-29 04:5552224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2004-08-10 12:00 . 2009-02-20 18:0927648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5527648 c:\windows\system32\dllcache\jsproxy.dll
- 2008-07-30 21:22 . 2009-02-20 10:2013824 c:\windows\system32\dllcache\ieudinit.exe
+ 2008-07-30 21:22 . 2009-04-28 09:0513824 c:\windows\system32\dllcache\ieudinit.exe
- 2004-08-10 12:00 . 2009-02-20 18:0944544 c:\windows\system32\dllcache\iernonce.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5544544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-10 12:00 . 2009-02-20 18:0978336 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-10 12:00 . 2009-04-29 04:5578336 c:\windows\system32\dllcache\ieencode.dll
- 2004-08-10 12:00 . 2009-02-20 10:2070656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-10 12:00 . 2009-04-28 09:0570656 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-07-30 21:22 . 2009-02-20 18:0963488 c:\windows\system32\dllcache\icardie.dll
+ 2008-07-30 21:22 . 2009-04-29 04:5563488 c:\windows\system32\dllcache\icardie.dll
+ 2009-06-27 02:39 . 2005-06-10 23:5357856 c:\windows\system32\dllcache\cache\spoolsv.exe
- 2009-06-26 02:24 . 2009-06-27 00:3232768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-26 02:24 . 2009-06-27 19:2332768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-26 02:24 . 2009-06-27 19:2316384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-06-26 02:24 . 2009-06-27 00:3216384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-06-26 02:24 . 2009-06-27 00:3232768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-26 02:24 . 2009-06-27 19:2332768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-27 19:30 . 2009-02-20 18:0944544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll
+ 2009-06-27 19:31 . 2009-02-20 18:0952224 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll
+ 2009-06-27 19:31 . 2009-02-20 18:0927648 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll
+ 2009-06-27 19:31 . 2009-02-20 10:2013824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-06-27 19:31 . 2009-02-20 18:0944544 c:\windows\ie7updates\KB969897-IE7\iernonce.dll
+ 2009-06-27 19:31 . 2009-02-20 18:0978336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll
+ 2009-06-27 19:31 . 2009-02-20 10:2070656 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe
+ 2009-06-27 19:31 . 2009-02-20 18:0963488 c:\windows\ie7updates\KB969897-IE7\icardie.dll
- 2006-10-16 10:21 . 2008-04-17 10:37351744 c:\windows\system32\xpsp3res.dll
+ 2006-10-16 10:21 . 2009-04-15 09:24351744 c:\windows\system32\xpsp3res.dll
- 2004-08-10 12:00 . 2009-02-20 18:09233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56105984 c:\windows\system32\url.dll
- 2004-08-10 12:00 . 2009-02-20 18:09105984 c:\windows\system32\url.dll
- 2004-08-10 12:00 . 2009-06-27 02:32366876 c:\windows\system32\perfh009.dat
+ 2004-08-10 12:00 . 2009-06-27 22:59366876 c:\windows\system32\perfh009.dat
- 2004-08-10 12:00 . 2009-02-20 18:09102912 c:\windows\system32\occache.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56102912 c:\windows\system32\occache.dll
- 2004-08-10 12:00 . 2009-02-20 18:09671232 c:\windows\system32\mstime.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56671232 c:\windows\system32\mstime.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56193024 c:\windows\system32\msrating.dll
- 2004-08-10 12:00 . 2009-02-20 18:09193024 c:\windows\system32\msrating.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56477696 c:\windows\system32\mshtmled.dll
- 2004-08-10 12:00 . 2009-02-20 18:09477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 22:54 . 2009-02-20 18:09459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 22:34 . 2009-02-20 18:09268288 c:\windows\system32\iertutil.dll
+ 2007-08-13 22:34 . 2009-04-29 04:55268288 c:\windows\system32\iertutil.dll
- 2004-08-10 12:00 . 2009-02-20 18:09385024 c:\windows\system32\iedkcs32.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 16:27 . 2009-02-20 18:09383488 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 16:27 . 2009-04-29 04:55383488 c:\windows\system32\ieapfltr.dll
- 2004-08-10 12:00 . 2009-02-20 05:14161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 12:00 . 2009-04-25 05:26161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55230400 c:\windows\system32\ieaksie.dll
- 2004-08-10 12:00 . 2009-02-20 18:09230400 c:\windows\system32\ieaksie.dll
- 2004-08-10 12:00 . 2009-02-20 18:09153088 c:\windows\system32\ieakeng.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55153088 c:\windows\system32\ieakeng.dll
- 2008-07-12 20:51 . 2009-04-04 21:25112584 c:\windows\system32\FNTCACHE.DAT
+ 2008-07-12 20:51 . 2009-06-27 19:51112584 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-10 12:00 . 2009-04-29 04:55133120 c:\windows\system32\extmgr.dll
- 2004-08-10 12:00 . 2009-02-20 18:09133120 c:\windows\system32\extmgr.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55214528 c:\windows\system32\dxtrans.dll
- 2004-08-10 12:00 . 2009-02-20 18:09214528 c:\windows\system32\dxtrans.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55347136 c:\windows\system32\dxtmsft.dll
- 2004-08-10 12:00 . 2009-02-20 18:09347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56827392 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-10 12:00 . 2009-02-20 18:09233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56105984 c:\windows\system32\dllcache\url.dll
- 2004-08-10 12:00 . 2009-02-20 18:09105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-10 12:00 . 2009-04-15 15:11584192 c:\windows\system32\dllcache\rpcrt4.dll
- 2004-08-10 12:00 . 2007-07-09 13:09584192 c:\windows\system32\dllcache\rpcrt4.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56102912 c:\windows\system32\dllcache\occache.dll
- 2004-08-10 12:00 . 2009-02-20 18:09102912 c:\windows\system32\dllcache\occache.dll
- 2004-08-10 12:00 . 2009-02-20 18:09671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56671232 c:\windows\system32\dllcache\mstime.dll
- 2004-08-10 12:00 . 2009-02-20 18:09193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56193024 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-10 12:00 . 2009-04-29 04:56477696 c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-10 12:00 . 2009-02-20 18:09477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-07-30 21:22 . 2009-04-29 04:55459264 c:\windows\system32\dllcache\msfeeds.dll
- 2008-07-30 21:22 . 2009-02-20 18:09459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2004-08-10 12:00 . 2009-05-07 15:44344064 c:\windows\system32\dllcache\localspl.dll
+ 2008-07-13 01:24 . 2009-04-25 05:27636088 c:\windows\system32\dllcache\iexplore.exe
+ 2008-07-30 21:22 . 2009-04-29 04:55268288 c:\windows\system32\dllcache\iertutil.dll
- 2008-07-30 21:22 . 2009-02-20 18:09268288 c:\windows\system32\dllcache\iertutil.dll
- 2004-08-10 12:00 . 2009-02-20 18:09385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-07-30 21:22 . 2009-02-20 18:09383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-07-30 21:22 . 2009-04-29 04:55383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2004-08-10 12:00 . 2009-02-20 05:14161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-10 12:00 . 2009-04-25 05:26161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-10 12:00 . 2009-02-20 18:09230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55230400 c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-10 12:00 . 2009-02-20 18:09153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-10 12:00 . 2009-02-20 18:09133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-10 12:00 . 2009-02-20 18:09214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55214528 c:\windows\system32\dllcache\dxtrans.dll
- 2004-08-10 12:00 . 2009-02-20 18:09347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2009-06-27 02:39 . 2008-04-14 00:12507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-27 02:39 . 2007-03-08 15:36577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55124928 c:\windows\system32\dllcache\advpack.dll
- 2004-08-10 12:00 . 2009-02-20 18:09124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-10 12:00 . 2009-04-29 04:55124928 c:\windows\system32\advpack.dll
- 2004-08-10 12:00 . 2009-02-20 18:09124928 c:\windows\system32\advpack.dll
+ 2009-06-27 19:30 . 2009-03-03 00:18826368 c:\windows\ie7updates\KB969897-IE7\wininet.dll
+ 2009-06-27 19:30 . 2009-02-20 18:09233472 c:\windows\ie7updates\KB969897-IE7\webcheck.dll
+ 2009-06-27 19:30 . 2009-02-20 18:09105984 c:\windows\ie7updates\KB969897-IE7\url.dll
+ 2009-06-27 19:31 . 2008-07-09 07:38382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-06-27 19:31 . 2008-07-09 07:38231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-06-27 19:30 . 2009-02-20 18:09102912 c:\windows\ie7updates\KB969897-IE7\occache.dll
+ 2009-06-27 19:30 . 2009-02-20 18:09671232 c:\windows\ie7updates\KB969897-IE7\mstime.dll
+ 2009-06-27 19:30 . 2009-02-20 18:09193024 c:\windows\ie7updates\KB969897-IE7\msrating.dll
+ 2009-06-27 19:30 . 2009-02-20 18:09477696 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09459264 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll
+ 2009-06-27 19:31 . 2009-02-28 04:54636072 c:\windows\ie7updates\KB969897-IE7\iexplore.exe
+ 2009-06-27 19:31 . 2009-02-20 18:09268288 c:\windows\ie7updates\KB969897-IE7\iertutil.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09385024 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09383488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll
+ 2009-06-27 19:31 . 2009-02-20 05:14161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09230400 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09153088 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09347136 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll
+ 2009-06-27 19:31 . 2009-02-20 18:09124928 c:\windows\ie7updates\KB969897-IE7\advpack.dll
+ 2004-08-10 12:00 . 2009-04-29 04:561159680 c:\windows\system32\urlmon.dll
+ 2004-08-10 12:00 . 2009-04-29 04:563596288 c:\windows\system32\mshtml.dll
- 2007-08-13 22:54 . 2009-02-20 18:096066176 c:\windows\system32\ieframe.dll
+ 2007-08-13 22:54 . 2009-04-29 04:556066176 c:\windows\system32\ieframe.dll
+ 2004-08-10 12:00 . 2009-04-17 09:581846656 c:\windows\system32\dllcache\win32k.sys
+ 2004-08-10 12:00 . 2009-04-29 04:561159680 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-10 12:00 . 2009-04-29 04:563596288 c:\windows\system32\dllcache\mshtml.dll
+ 2008-07-30 21:22 . 2009-04-29 04:556066176 c:\windows\system32\dllcache\ieframe.dll
- 2008-07-30 21:22 . 2009-02-20 18:096066176 c:\windows\system32\dllcache\ieframe.dll
+ 2009-06-27 02:39 . 2007-06-13 10:231033216 c:\windows\system32\dllcache\cache\explorer.exe
+ 2009-06-27 19:30 . 2009-02-20 18:091160192 c:\windows\ie7updates\KB969897-IE7\urlmon.dll
+ 2009-06-27 19:30 . 2009-02-20 18:093595264 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
+ 2009-06-27 19:31 . 2009-02-20 18:096066176 c:\windows\ie7updates\KB969897-IE7\ieframe.dll
+ 2009-06-27 19:31 . 2008-07-09 14:252455488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-04-09 1176808]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-11-16 88209]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/25/2009 9:38 PM 203280]
S3 DCamUSBTP10;Cam IV;c:\windows\system32\drivers\TP6810.SYS [7/24/2008 3:52 PM 240584]
.
Contents of the 'Scheduled Tasks' folder

2008-09-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-06-26 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-26 12:57]

2009-06-26 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-26 12:57]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://70.46.125.59/WebDiginet.CAB
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-27 19:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4008)
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2009-06-27 19:10
ComboFix-quarantined-files.txt 2009-06-27 23:10
ComboFix2.txt 2009-06-26 01:15

Pre-Run: 67,797,995,520 bytes free
Post-Run: 67,864,244,224 bytes free

292--- E O F ---2009-06-27 19:58

    I don't see anything malware related now.

    How is the computer running?

    ----------

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
The computer seems to be running fine the only thing thats really irratating is that it keeps shutting off randomly! it's quite often too!Quote
computer keeps shutting off randomly

This could be any number of things causing that.

Have you INSTALLED any new hardware recently?Nopee no new software installed!Was it happening before the malware problems?

Quote
c:\program files\Windows Doctor

Is Windows Doctor still installed?



It wasnt happening before! and yes Windows Doctor is still installed! is that bad?If it isn't paid for then yes I would uninstall Windows Doctor. I've never heard of it and what I researched was conflicting information on it's trustworthiness.

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will OPEN two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.
DDS (Ver_09-06-26.01) - NTFSx86
Run by XP User at 2:35:17.00 on Mon 06/29/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.162 [GMT -4:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\XP User\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://70.46.125.59/WebDiginet.CAB
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxsrvc.dll
LSA: Authentication Packages = msv1_0 nwprovau

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-6-27 214024]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-6-25 210216]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-25 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-25 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-25 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-25 35272]
S3 DCamUSBTP10;Cam IV;c:\windows\system32\drivers\TP6810.SYS [2008-7-24 240584]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-25 606736]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-25 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-25 40552]

=============== Created Last 30 ================

2009-06-27 20:00--ds----C:\ComboFix
2009-06-27 19:20--d-----C:\e3061928c59c400685fca2c6
2009-06-26 22:41--d-----c:\documents and settings\xp user\WINDOWS
2009-06-26 20:3113,712a-------c:\windows\system32\wpa.bak
2009-06-25 22:25--d-----c:\program files\Windows Doctor
2009-06-25 22:175,169a-------c:\windows\system32\Config.MPF
2009-06-25 21:39--d-----c:\program files\SiteAdvisor
2009-06-25 21:31--d-----c:\program files\McAfee.com
2009-06-25 21:14-cd-----c:\windows\system32\dllcache\cache
2009-06-25 20:51a-dshr--C:\cmdcons
2009-06-25 19:48--d-----c:\windows\system32\appmgmt
2009-06-25 19:26--d-----c:\windows\system32\CatRoot2
2009-06-25 18:2840,552a-------c:\windows\system32\drivers\mfesmfk.sys
2009-06-25 18:2879,816a-------c:\windows\system32\drivers\mfeavfk.sys
2009-06-25 18:2835,272a-------c:\windows\system32\drivers\mfebopk.sys
2009-06-25 18:28120,136a-------c:\windows\system32\drivers\Mpfp.sys
2009-06-25 18:26--d-----c:\program files\common files\McAfee
2009-06-25 18:25--d-----c:\program files\McAfee
2009-06-25 18:2434,248a-------c:\windows\system32\drivers\mferkdk.sys
2009-06-25 18:09--d-----c:\docume~1\alluse~1\applic~1\Geek Squad

==================== Find3M ====================

2009-05-13 23:25214,024a-------c:\windows\system32\drivers\mfehidk.sys
2009-05-07 11:44344,064a-------c:\windows\system32\localspl.dll
2009-04-29 00:56827,392a-------c:\windows\system32\wininet.dll
2009-04-29 00:5578,336a-------c:\windows\system32\ieencode.dll
2009-04-17 05:581,846,656a-------c:\windows\system32\win32k.sys
2009-04-15 11:11584,192a-------c:\windows\system32\rpcrt4.dll
2009-04-06 00:0790,112a-------c:\windows\DUMP62e0.tmp

============= FINISH: 2:36:57.28 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/12/2008 9:32:29 PM
System Uptime: 6/29/2009 2:32:49 AM (0 hours ago)

Motherboard: Hewlett-Packard | | 309D
Processor: Intel(R) Celeron(R) M processor 1.50GHz | U1 | 1496/400mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 75 GiB total, 63.419 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 6/27/2009 10:26:18 PM - System Checkpoint

==== Installed Programs ======================

Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Agere Systems AC'97 Modem
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
Broadcom 802.11 Wireless LAN Adapter
Cam IV
GTOneCare
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
Intel(R) Graphics Media Accelerator Driver for Mobile
iTunes
Java(TM) 6 Update 3
Java(TM) 6 Update 7
LimeWire 4.16.6
LiveUpdate 3.1 (Symantec Corporation)
McAfee SecurityCenter
Microsoft .NET FRAMEWORK 1.0 Hotfix (KB930494)
Microsoft Application Error Reporting
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
PowerDVD
QuickTime
Safari
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
SoundMAX
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
WebFldrs XP
Windows Doctor 2.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086

==== Event Viewer Messages From Past Week ========

6/27/2009 6:54:43 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 0014A57A06C4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
6/27/2009 4:04:03 PM, error: DCOM [10005] - DCOM got error "%1450" attempting to start the service COMSysApp with arguments "" in ORDER to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Services service terminated unexpectedly. It has done this 3 time(s).
6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 3 time(s).
6/26/2009 7:54:58 PM, error: Service Control Manager [7034] - The McAfee Network Agent service terminated unexpectedly. It has done this 3 time(s).
6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/26/2009 7:53:27 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
6/26/2009 7:47:11 PM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s).
6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
6/26/2009 7:47:11 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/26/2009 5:21:23 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 81ec16e8, parameter3 81ec185c, parameter4 805c77ca.
6/25/2009 9:08:36 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
6/25/2009 8:54:25 PM, error: Service Control Manager [7034] - The McAfee Proxy Service service terminated unexpectedly. It has done this 3 time(s).
6/25/2009 8:53:08 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/25/2009 8:52:44 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
6/25/2009 8:50:29 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/25/2009 8:17:50 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
6/25/2009 7:47:44 PM, error: Service Control Manager [7024] - The Symantec SPBBCSvc service terminated with service-specific error 4294967295 (0xFFFFFFFF).
6/25/2009 7:19:31 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/25/2009 7:18:06 PM, error: Service Control Manager [7034] - The Media Center Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:18:00 PM, error: Service Control Manager [7034] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:17:42 PM, error: Service Control Manager [7034] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:17:36 PM, error: Service Control Manager [7034] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:17:20 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:17:16 PM, error: Service Control Manager [7034] - The Symantec AntiVirus Definition Watcher service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 7:17:04 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 6:42:06 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
6/25/2009 6:41:42 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
6/25/2009 6:32:00 PM, error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
6/25/2009 6:13:42 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
6/25/2009 4:40:58 PM, error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

==== End Of File ===========================
Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the Desktop.

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

----------

Download the Norton Removal Tool (SymNRT) to your desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.
  • Go to your desktop and double click on the 'Norton_Removal_Tool' and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC.
  • Delete the 'Norton_Removal_Tool' from your desktop.
.
----------

How is the computer running now?

.
1623.

Solve : WARNING New scam targets User Forums.. activationlink.co?

Answer»

WARNING New scam targets User Forums.. activationlink.co

A new user will ch eck in with something LIKE this:

Hello, I dont know if I am writing in a proper board but I have got a problem with activation,
link is not working... http: // activationlink.co/,

DO NOT try the link. (I broke it on purpose.)
The user names changes, but the text is the same.err- a scam gets money from the victim- this seems to be SPAM.I'm not able to investigate the link right now but what is the exploit?I saw that on in a advertisement it crashed my browser. DONT GO THERE!Is that the right link?

hxxp://activationlink.com

Not finding it in any of the databases.

http://www.mywot.com/en/scorecard/www.activationlink.com
https://safeweb.norton.com/report/show?url=activationlink.com&x=12&y=11
http://www.siteadvisor.com/lookup/?q=activationlink.com

Appears clean. http://unmaskparasites.com/security-report/Can't find out what it is because it somehow is very clever.
If will show up on forums using PHP. The would include this forum. I found it on a a site using SMF. The are dozens, maybe hundreds of sites getting this post. I think it is called a

Santy Worm

But I don't have enough knowledge to confirm this. It attacks PHP code

There is no such site.
I used Sandboxie and visited. It's just a generic search provider hosted on Godaddy servers. Didn't have time to look around too much but I never was able to find anything malicious.

www.sandboxie.com <- Great for investigating malicious sites.

I think it's just a spammer trying to generate traffic.Quote

It's just a generic search provider

Thanks for checking it out. for some reason my ISP or browser blocks that site.
My limited research indicated that is was part of a PHP ATTACK.

Because no harm was done, that does no PROVE lack of malicious intent.

The attack is very widespread and seeks out user forums. Yea I saw it in my Google search. It's definitely not to be trusted!I recently found this site: http://www.tkafeestekene.be/index.php?option=com_akobook&Itemid=29 The link will take you to their guestbook where you can see MANY of these messages spammed.

The website is for a German cafe but you can see all the messages in the guestbook.

The links are broken.Great, so these people come here and post links in (a href=) with a bogus description. Is there a way to set up description tags like slashdot has?
1624.

Solve : Help needed! CPU freezing. Inexpericenced user.?

Answer»

Ok I have a Dell Desktop that I've owned for 2, maybe 3 years. Always worked fine no major problems until recently. My cpu started freezing up during startup. I WOULD log on and it would start to load my desktop and programs and halfway through it would freeze. I ran a few programs in safe mode and now can start the CPU but if i plug in my wireless adapter and try to connect to the internet my cpu will freeze. I use Mozilla firefox. I can run firefox in "safemode with networking" which I am doing now.
Any help is appreciated as I know little to nothing about spyware, viruses, ETC. I just try and run the popular anti-virus, spyware, etc programs for my "protection". I know nothing about fixing cpu problems. Thanks guys!!Have you tried "last known good configuration"?

What avtivirus program(s) do you have?

Did you make any changes (like downloading a file) recently?i have these programs:

avast antivirus
advanced system care
mal-warebyte antimalware
spybot search and destroy



i tried the last know good config and that also froze. my CPU has been acting this way for atleast a month. Open up your case and CHECK for dust.....use compressed air..........sounds like you are overheating......check your fans and heatsink for dirt and operation.

http://www.professormesser.com/2008/03/24/keeping-things-clean/really overheating? my CPU will run fine in normal mode as long as I don't try to connect to the internet. can dust really cause this problem? i will clean my CPU tomorrow ASAP. i still think its a hardware problem, either a virus or something along those lines but i can easily be wrong. i downloaded and ran Hijack this. here is the log file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:42:36 AM, on 6/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\MICROSOFT\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - Global Startup: DIGITAL Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210395714937
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 6808 bytes

1625.

Solve : Malwarebytes problems!! need help!?

Answer»

So i downloaded Malwarebytes Malware remover and its on my desktop, and all of the files appear to be present, but every time i click the icon or try to open the file, nothing happens...at all.. i believe that it may be because of some kind of virus affecting my registry or something im not EXACTLY sure.... I also cannot run Disk Defragmenter (every time i click analyze or defrag it pops up a window saying "Disk Defragmenter could not start") and cannot go to certain websites such as malwarebytes.org.....many of them simply say "Internet Explorer cannot display the webpage."

Please HELP!! hi ur prob might b same as mine (SEE post below) if i get ne response i will let u no.Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

  • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
  • Then search for TDSSserv.sys
  • Let me know if you find this or not.
  • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
  • Also if this is found and you disable it.
  • Now reboot and see if you can run the other scans that would not run.
Quote from: maxxj3 on JUNE 27, 2009, 12:41:40 PM
Hey, does anyone have problems with malwarebytes DESTROYING the drivers for your cd rom or dvd rom? Or keeps you from connecting to the internet with on one of your users?

Please don't hijack someone else's post. Start a new one.
1626.

Solve : Completed Evilfantasy's directions - here are my posts.?

Answer»

I was unsure where I needed to post this, but here it is.
I was having TROUBLE... I'll check back here soon to SEE what you guys have to say.
Thanks.

[attachment deleted by admin]Harry , you should not pass judgement on people like that.....I had a client who had 240 trojans on her pc, and she was getting hundreds of popups an hour relating to *censored* sites........yet she had never been to a PORN site. All her problems originated from using a pirated copy of XP, whose origin I won't mention.......She is now HAPPILY using Ubuntu, and no more popups.sorry removed

1627.

Solve : Possibly Conficker, logs included?

Answer»

Ok...a couple days ago I had to format my C and reinstall windows xp pro. One of the first things I did was install windows update and get sp2. Then reinstalled AVG Malwarebytes and Opera. Last night I discovered I needed to get the .net frame for another program I run.
I cant get to any part of the Microsoft domain using either Opera or IE6.
Installing IE8 via yahoo failed.
Uninstalling AVG doesnt fix it. There are no blocked sites listed anywhere I can find in Opera or IE.
I can go anywhere else I want.
Others reach the site fine and I can reach it fine on my laptop, so its not a router issue I guess.
There is no SAS log as I cant get to the site to download it.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:34:40 PM, on 6/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\D-Link\AirPlus XtremeG DWL-G520\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Opera\Opera.exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG DWL-G520] C:\Program Files\D-Link\AirPlus XtremeG DWL-G520\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-21-1214440339-1604221776-725345543-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1214440339-1604221776-725345543-1003\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245972850194
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - SUN Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5238 bytes

===========================================
Malwarebytes' Anti-Malware 1.38
Database version: 2297
Windows 5.1.2600 Service Pack 2

6/26/2009 2:58:37 PM
mbam-log-2009-06-26 (14-58-37).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 130513
Time elapsed: 1 hour(s), 7 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data ITEMS Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Administrator\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\DavidG\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Thank you for you help




Are you sure you reinstalled or just recopied the files? Some name brand computers have either a copy windows files over setting or a destructive setting. You may not have set it to format the hdd.Paudash, he has Virut...he has to reformat/reinstall.Its not a brand name, I built it from parts. It was fully formatted, not the quick version either.
While Ive been waiting, I used the self help and searched the hjt log. It doesnt show any issues. It doesnt seem to notice that my windows firewall is in fact turned on. I can get to microsoft sites now after scanning the drives multiple times, but its still obvious something is wrong. David, you have a variant of virut.

C:\WINDOWS\system32\reader_s.exe (Trojan.Agent)


You can search Virut on this forum, and you'll see evilfantasy recommends wiping the hard drive and reinstall XP.

You cannot remove this malware, it replicates as quickly as you can remove it.

Evilfantasy will confirm this for you.Good eye Karnac.

The logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. Trying to fix this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information.

Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

Backing up files before formatting

If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like TEXT documents and personal photos.

Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.

-) Dr.Web CureIt!
-) AVG Win32/Virut Removal Tool
-) Symantwc W32.Virut Removal Tool
-) McAfee Avert Stinger
-) Microsoft Windows Malicious Software Removal Tool

If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

Very important, do the following immediately or as soon as possible!

If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.

From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and TRANSACTION information.

1628.

Solve : Hii geeks two probs cant find solution?

Answer»

hiii geeks i have 2 probs one is trojan virus and another is no POST or no BOOT sound.

Virus :

my systems are infected by some trojon virus. Wats the problem is if a folder is opened an exe file containing the folders name or a word DOCUMENT containing the folders name is being created. It makes the computer tooo slow and Net connection also too slow......can one pls SUGGEST me gud anti virus to get away from this.....
i tried Avast, Avira, MCAfee, Kaspersky ,etc etc.....but no solution i would be thk FUL if anyone GIVES me a permanent solution.....i also tried formatting, but when i back up the files the virus comes inside again............Did you try any of the antivirus programs while booted from Safe Mode?We are not geeks! (Hugs computer)Quote

Avast, Avira, MCAfee, Kaspersky

Do you have all of those programs on your computer at once?Quote
no POST


It won't post at all? I assume that it won't start up either?hii all thks for the replies but i tried all the ways.....i have installed CA antivirus, MCAfee, etc....all at once but its not reoving ....i want to remove the word file that is being created in each and every folder....pls help out..!You only want one antivirus program at one time. If you have more than one antivirus program on your computer they will bump HEADS. This will cause major problems with your computer.
Go into Add/Remove Programs and uninstall all but one of your antivirus programs.
1629.

Solve : file msnmgnr.exe is missing flashes after start up?

Answer»

2 weeks ago i was having time/date reset to september 2020 everytime i boot my PC. back then i thought it was a virus/malware problem but my avg antivirus cannot see it. this week i started to have the error missing file msnmgnr.exe after my pc starts. then i started reading about that file and realized its in fact a virus. i found out that the file msnmgnr.exe in fact causes the date reset i experienced 2 weeks ago. however, i wasnt able to find a clear fix over the net for my problem. i need help. the necessary logs are found below. thanks.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/10/2009 at 01:35 AM

Application Version : 4.26.1004

Core Rules Database Version : 3930
Trace Rules Database Version: 1873

Scan type : Complete Scan
Total Scan Time : 01:02:37

Memory items scanned : 450
Memory threats detected : 0
Registry items scanned : 6375
Registry threats detected : 29
File items scanned : 93254
File threats detected : 6

Trojan.Downloader-Gen/FotoMoto
HKLM\Software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{733716E1-76D2-4003-AC39-845281C0EF85}
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{733716E1-76D2-4003-AC39-845281C0EF85}
HKCR\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}
HKCR\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\ProgID
HKCR\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\Programmable
HKCR\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\TypeLib
HKCR\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\VersionIndependentProgID

Adware.MyWebSearch
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

Adware.HotBar/ShopperReports (Low Risk)
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{100EB1FD-D03E-47FD-81F3-EE91287F9465}

Unclassified.Unknown Origin
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
E:\DOWNLOADS\MISC\COLLAGE MAKER\KEYGEN.NFO
E:\DOWNLOADS\MISC\KEYGEN.NFO

Adware.Zango/ShoppingReport
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B2}
HKU\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5428486-50A0-4A02-9D20-520B59A9F9B3}

Adware.MyWebSearch/FunWebProducts
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib#Version

Trojan.Media-Codec/V4
C:\Program Files\Video Add-on Setup

Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\RemoveRP

Rogue.Component/Trace
HKLM\Software\Microsoft\600DE937
HKLM\Software\Microsoft\600DE937#600de937
HKLM\Software\Microsoft\600DE937#Version

Trojan.Net-SvHoster
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\PROTECT\SVHOST.EXE

Adware.AdRotator/SuperiorAds
C:\WINDOWS\SYSTEM32\SUPERIORADS-UNINST.EXE

Adware.180solutions/Seekmo/Zango
E:\DOWNLOADS\SETUP.EXE



Malwarebytes' Anti-Malware 1.37
Database version: 2255
Windows 5.1.2600 Service Pack 3

6/10/2009 2:00:38 AM
mbam-log-2009-06-10 (02-00-38).txt

Scan type: Quick Scan
Objects scanned: 96960
Time elapsed: 4 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 4
Registry Data Items Infected: 4
Folders Infected: 1
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\dc_ads.ads (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dc_ads.ads.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp.1 (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Delete on reboot.
HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\a1301497-029d-cff7-a294-146df193dc0e (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcadssocial (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\qalkfxor.bqva (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\qalkfxor.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cont_dcads (Adware.Adrotator) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\rqbmvpso (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\pdoskegl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (55274-648-2323245-23256) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
c:\WINDOWS\system32\a1301497-029d-cff7-a294-146df193dc0e.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
c:\RECYCLER\s-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\DcadsSocial-uninstall.exe (Adware.RightOnAds) -> Quarantined and deleted successfully.
c:\documents and settings\Administrator\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\favorites\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\favorites\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\favorites\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cont_dcads-remove.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
c:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:46 PM, on 6/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fmz.qiwa.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=62548
R3 - URLSearchHook: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll
F2 - REG:system.ini: Shell=Explorer.exe msnmgnr.exe
O2 - BHO: (no name) - {0021042F-2CC8-EFD8-B715-2713974D46A3} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {60D2E6AF-F47E-45B8-917F-DE66D9C379B8} - (no file)
O2 - BHO: (no name) - {706D5729-5152-4040-8978-F49C6D23F9C7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {a0b71f07-c3b7-1c4a-99c9-0bbe2de60d71} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {B0F73815-DCE5-4838-9000-41CF13C3610F} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: qalkfxor - {8BE3A45C-46D2-407E-8A70-878D0828634D} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.ph/com/EGamesPlugin.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: xxyXOhFX - xxyXOhFX.dll (file missing)
O23 - Service: Adobe LM Service - Adobe SYSTEMS - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 9831 bytes
Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.required logs below:



DDS (Ver_09-05-14.01) - NTFSx86
Run by Jared at 14:16:14.85 on Wed 06/10/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1397 [GMT 8:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jared\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://fmz.qiwa.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
mWinlogon: Shell=Explorer.exe msnmgnr.exe
BHO: {0021042F-2CC8-EFD8-B715-2713974D46A3} - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {60D2E6AF-F47E-45B8-917F-DE66D9C379B8} - No File
BHO: {706D5729-5152-4040-8978-F49C6D23F9C7} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Encarta Web Companion Helper Object: {955be0b8-bc85-4caf-856e-8e0d8b610560} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: {a0b71f07-c3b7-1c4a-99c9-0bbe2de60d71} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: CPrintEnhancer Object: {ae84a6aa-a333-4b92-b276-c11e2212e4fe} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: {B0F73815-DCE5-4838-9000-41CF13C3610F} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: qalkfxor: {8be3a45c-46d2-407e-8a70-878d0828634d} -
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
EB: {97F32659-2957-DE6E-6FA4-EC24F7C7CEF0} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
uRun: [Uniblue SpeedUpMyPC] c:\program files\uniblue\speedupmypc 3\SpeedUpMyPC.exe -s
uRun: [Uniblue SpyEraser] "c:\program files\uniblue\spyeraser\SpyEraser.exe" -m
mRun: [Gainward] c:\program files\vdotool\TBPanel.exe /A
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - hxxps://www.e-games.com.ph/com/EGamesPlugin.cab
DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} - hxxp://legendofares.netgame.com/download/MusaLauncherNew.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: xxyXOhFX - xxyXOhFX.dll
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll,c:\progra~1\google\google~1\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {60D2E6AF-F47E-45B8-917F-DE66D9C379B8} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Authentication Packages = msv1_0 c:\windows\system32\hgGxWqrr

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jared\applic~1\mozilla\firefox\profiles\rfcjzjrh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - prefs.js: keyword.URL - hxxp://www2.yoog.com/search.php?q=
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ZangoSA.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkimi.dll

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: content.switch.threshold - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www2.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-16 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-16 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-16 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-12-16 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-16 298776]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2007-9-7 38656]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\drivers\s125bus.sys [2007-4-24 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\system32\drivers\s125mdfl.sys [2007-4-24 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\system32\drivers\s125mdm.sys [2007-4-24 108680]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\system32\drivers\s125obex.sys [2007-4-24 98696]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]

=============== Created Last 30 ================

2009-06-10 12:39--d-----c:\program files\Trend Micro
2009-06-10 01:49--d-----c:\docume~1\jared\applic~1\Malwarebytes
2009-06-10 01:4940,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 01:4919,096a-------c:\windows\system32\drivers\mbam.sys
2009-06-10 01:49--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-10 01:49--d-----c:\program files\Malwarebytes' Anti-Malware
2009-06-10 00:53410,984a-------c:\windows\system32\deploytk.dll
2009-06-10 00:22--d-----c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-10 00:22--d-----c:\program files\SUPERAntiSpyware
2009-06-10 00:22--d-----c:\docume~1\jared\applic~1\SUPERAntiSpyware.com
2009-06-09 23:52--d-----c:\program files\CCleaner
2009-06-09 09:26--dsh---c:\docume~1\alluse~1\applic~1\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-09 09:22--d-----c:\docume~1\alluse~1\applic~1\Uniblue
2009-06-09 09:07--d-----c:\program files\Uniblue
2009-06-09 08:44--d-----c:\docume~1\jared\applic~1\Uniblue
2009-06-09 08:43-cd-h---c:\docume~1\alluse~1\applic~1\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-06-08 12:3923,392a-------c:\windows\system32\nscompat.tlb
2009-06-08 12:3916,832a-------c:\windows\system32\amcompat.tlb
2009-05-29 15:44--d-----c:\program files\MSECache
2009-05-28 22:5298,304a-------c:\windows\system32\CmdLineExt.dll
2009-05-27 10:173,255a-------c:\windows\system32\wbem\Outlook_01c9de71480d7222.mof

==================== Find3M ====================

2009-05-09 09:54325,896a-------c:\windows\system32\drivers\avgldx86.sys
2009-05-09 09:5411,952a-------c:\windows\system32\avgrsstx.dll
2009-05-09 09:54108,552a-------c:\windows\system32\drivers\avgtdix.sys
2009-01-25 21:224---shr--c:\docume~1\alluse~1\applic~1\sysqcl1129139270.dat
2007-10-25 11:2818,895,728a-------c:\program files\Install_Messenger.exe
2008-08-28 19:0929,587a--sh---c:\windows\system32\rrqWxGgh.ini2
2008-09-09 22:4916,384a--sh---c:\windows\system32\config\systemprofile\cookies\index.dat
2008-09-09 22:4932,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-09 22:4932,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090920080910\index.dat
2008-09-09 22:4932,768a--sh---c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 14:16:37.10 ===============






UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/7/2005 11:24:05 PM
System Uptime: 6/10/2009 12:19:00 PM (2 hours ago)

Motherboard: ASUSTeK Computer INC. | | M2N8-VMX
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | CPU 1 | 2209/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 156 GiB total, 120.383 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 142 GiB total, 89.403 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP364: 3/13/2009 11:21:21 PM - System Checkpoint
RP365: 3/15/2009 6:08:19 PM - System Checkpoint
RP366: 3/17/2009 8:10:08 PM - System Checkpoint
RP367: 3/18/2009 8:20:55 AM - Avg8 Update
RP368: 3/19/2009 8:33:21 AM - System Checkpoint
RP369: 3/20/2009 12:12:03 PM - System Checkpoint
RP370: 3/21/2009 12:42:51 PM - System Checkpoint
RP371: 3/22/2009 12:01:07 AM - Software Distribution Service 3.0
RP372: 3/24/2009 8:12:04 AM - System Checkpoint
RP373: 3/25/2009 11:38:20 AM - System Checkpoint
RP374: 3/25/2009 7:08:55 PM - Configured AVG Free 8.5
RP375: 3/26/2009 8:31:33 AM - Avg8 Update
RP376: 3/27/2009 8:51:28 AM - Avg8 Update
RP377: 3/28/2009 10:22:00 AM - System Checkpoint
RP378: 3/30/2009 10:07:04 AM - System Checkpoint
RP379: 3/31/2009 1:21:33 PM - System Checkpoint
RP380: 4/1/2009 1:44:20 PM - System Checkpoint
RP381: 4/2/2009 2:39:14 PM - System Checkpoint
RP382: 4/3/2009 10:40:12 PM - System Checkpoint
RP383: 4/4/2009 10:59:16 PM - System Checkpoint
RP384: 4/4/2009 11:59:57 PM - Installed Windows Media Player 10
RP385: 4/5/2009 12:20:02 AM - Software Distribution Service 3.0
RP386: 4/6/2009 12:23:20 AM - System Checkpoint
RP387: 4/6/2009 3:00:15 AM - Software Distribution Service 3.0
RP388: 4/7/2009 8:37:10 AM - System Checkpoint
RP389: 4/8/2009 9:20:54 AM - System Checkpoint
RP390: 4/11/2009 12:14:05 PM - Avg8 Update
RP391: 4/12/2009 1:07:08 PM - System Checkpoint
RP392: 4/13/2009 1:51:45 PM - System Checkpoint
RP393: 4/14/2009 2:22:25 PM - System Checkpoint
RP394: 4/15/2009 8:50:45 PM - System Checkpoint
RP395: 4/16/2009 9:10:32 AM - Avg8 Update
RP396: 4/17/2009 3:00:22 AM - Software Distribution Service 3.0
RP397: 4/18/2009 7:58:30 AM - System Checkpoint
RP398: 4/19/2009 9:18:17 AM - System Checkpoint
RP399: 4/20/2009 2:50:10 PM - System Checkpoint
RP400: 4/21/2009 3:58:01 PM - System Checkpoint
RP401: 4/22/2009 5:37:38 PM - System Checkpoint
RP402: 4/23/2009 9:27:13 PM - System Checkpoint
RP403: 4/30/2009 9:45:26 PM - System Checkpoint
RP404: 5/1/2009 9:16:43 AM - Software Distribution Service 3.0
RP405: 5/7/2009 9:27:51 PM - System Checkpoint
RP406: 5/7/2009 11:40:17 PM - Software Distribution Service 3.0
RP407: 5/9/2009 9:50:28 AM - Avg8 Update
RP408: 5/9/2009 9:55:04 AM - Avg8 Update
RP409: 5/10/2009 1:14:55 PM - System Checkpoint
RP410: 5/10/2009 2:30:02 PM - Removed GG E-Sports Platform
RP411: 5/12/2009 5:29:01 PM - System Checkpoint
RP412: 5/13/2009 5:36:28 PM - Software Distribution Service 3.0
RP413: 5/14/2009 10:48:59 PM - System Checkpoint
RP414: 5/16/2009 10:45:07 AM - Avg8 Update
RP415: 5/18/2009 9:26:47 AM - System Checkpoint
RP416: 5/19/2009 8:13:39 AM - Avg8 Update
RP417: 5/19/2009 8:16:54 AM - Avg8 Update
RP418: 5/21/2009 11:52:12 AM - System Checkpoint
RP419: 5/22/2009 10:45:03 PM - System Checkpoint
RP420: 5/24/2009 5:47:53 PM - System Checkpoint
RP421: 5/25/2009 8:21:50 PM - System Checkpoint
RP422: 5/26/2009 9:30:28 PM - System Checkpoint
RP423: 5/28/2009 8:40:26 AM - System Checkpoint
RP424: 5/28/2009 10:40:52 PM - Installed DirectX
RP425: 5/28/2009 10:45:50 PM - Installed DirectX
RP426: 5/29/2009 3:44:39 PM - Installed Compatibility Pack for the 2007 Office system
RP427: 5/30/2009 4:41:19 PM - System Checkpoint
RP428: 5/31/2009 5:40:10 PM - System Checkpoint
RP429: 6/2/2009 12:43:05 PM - System Checkpoint
RP430: 6/3/2009 5:20:09 PM - System Checkpoint
RP431: 6/5/2009 7:51:11 PM - System Checkpoint
RP432: 6/7/2009 10:57:53 PM - System Checkpoint
RP433: 6/8/2009 11:59:43 AM - Removed Ad-Aware
RP434: 6/8/2009 12:37:37 PM - Installed Windows Media Player 11
RP435: 6/8/2009 12:41:01 PM - Installed Windows Media Player 11
RP436: 6/8/2009 12:42:54 PM - Installed Windows XP MSCompPackV1.
RP437: 6/9/2009 1:12:03 AM - Software Distribution Service 3.0
RP438: 6/9/2009 9:11:10 AM - Uniblue RegistryBooster
RP439: 6/9/2009 9:16:17 AM - Uniblue RegistryBooster
RP440: 6/9/2009 9:26:02 AM - Removed TuneUp Utilities 2008
RP441: 6/9/2009 9:27:02 AM - Installed TuneUp Utilities 2009
RP442: 6/9/2009 10:13:46 AM - Removed TuneUp Utilities 2009
RP443: 6/9/2009 11:00:17 AM - Software Distribution Service 3.0
RP444: 6/9/2009 11:29:48 PM - Removed Comic Life
RP445: 6/10/2009 12:22:44 AM - Installed SUPERAntiSpyware Free Edition
RP446: 6/10/2009 12:52:39 AM - Installed Java(TM) 6 Update 13
RP447: 6/10/2009 12:31:03 PM - Removed Java(TM) 6 Update 2
RP448: 6/10/2009 12:31:47 PM - Removed Java(TM) 6 Update 3
RP449: 6/10/2009 12:32:25 PM - Removed Java(TM) 6 Update 5
RP450: 6/10/2009 12:33:18 PM - Removed Java(TM) 6 Update 7

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop CS2
Adobe Reader 8.1.2
AIO_Scan
Apple Mobile Device Support
Apple Software Update
Attansic Giga Ethernet Utility
AVG 8.5
Bonjour
BufferChm
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Copy
CorelDRAW Graphics Suite X3
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
Destinations
DeviceManagementQFolder
DivX
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
EN
eSupportQFolder
F4100
F4100_Help
Final Draft 7
FontNav
Garena
Google Desktop
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Customer Participation Program 8.0
HP Deskjet All-In-One Software 8.0
HP Imaging Device Functions 8.0
HP Photosmart Essential
HP Smart Web Printing 1.0
HP Solution Center 8.0
HP Update
HPProductAssistant
HPSSupply
Imikimi Plugin
InterActual Player
InterVideo WinDVD 7
iTunes
Java(TM) 6 Update 13
LimeWire 4.16.6
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta Premium 2007
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft XML Parser
Mozilla Firefox (3.0.10)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nero Suite
NVIDIA Drivers
OpenOffice.org Installer 1.0
Picture Collage Maker
QuickFix
QuickTime
Realtek High Definition Audio Driver
Scan
Scrapbook Flair
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
SereneScreen Marine Aquarium 2.6
Skype™ 3.8
SolutionCenter
Status
SUPERAntiSpyware Free Edition
The Settlers II - 10th Anniversary
ToggleEN Toolbar
Toolbox
TrayApp
Uniblue RegistryBooster 2
Uniblue SpeedUpMyPC 3
Uniblue SpyEraser
UnloadSupport
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Manager
VBA
VDOTool 5.3
Ventrilo Client
WebFldrs XP
WebReg
Winamp (remove only)
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

6/9/2009 8:35:37 AM, error: Service Control Manager [7000] - The Cardex service failed to start due to the following error: Cannot create a file when that file already exists.
6/8/2009 12:43:06 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
6/3/2009 2:34:20 PM, error: Cdrom [11] - The driver detected a controller error on \Device\CdRom0.
6/10/2009 2:03:37 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

==== End Of File ===========================
Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these DIRECTIONS as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
BHO: {0021042F-2CC8-EFD8-B715-2713974D46A3} - No File
BHO: {60D2E6AF-F47E-45B8-917F-DE66D9C379B8} - No File
BHO: {706D5729-5152-4040-8978-F49C6D23F9C7} - No File
BHO: {a0b71f07-c3b7-1c4a-99c9-0bbe2de60d71} - No File
BHO: {B0F73815-DCE5-4838-9000-41CF13C3610F} - No File
TB: qalkfxor: {8be3a45c-46d2-407e-8a70-878d0828634d} -
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
EB: {97F32659-2957-DE6E-6FA4-EC24F7C7CEF0} - No File
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
SEH: {60D2E6AF-F47E-45B8-917F-DE66D9C379B8} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\hgGxWqrr

Firefox::
FF - ProfilePath - c:\docume~1\jared\applic~1\mozilla\firefox\profiles\rfcjzjrh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: keyword.URL - hxxp://www2.yoog.com/search.php?q=
FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ZangoSA.dll
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www2.yoog.com/search.php?q=


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious SITES can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa

  • Unzip the file and open the JavaRa.exe
  • Click Remove Older Versions
  • JavaRa will search for and remove any outdated version of Java and remove any that are found.
  • Click Additional Tasks
  • Place a check next to Remove Useless JRE Files and click Go
  • Exit JavaRa
  • Delete the JavaRa files from the Desktop
Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.Wow Amazing! Thank you very much! i dont have the error message anymore. am i off the hook? CF log below.


ComboFix 09-06-09.06 - Jared 06/11/2009 9:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1590 [GMT 8:00]
Running from: c:\documents and settings\Jared\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jared\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\messenger\msmsgs.exe
c:\program files\Need2Find
c:\program files\Need2Find\bar\Cache\00255494
c:\windows\system32\rrqWxGgh.ini
c:\windows\system32\rrqWxGgh.ini2

.
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.

2009-06-11 00:47 . 2009-06-11 00:47--------d-----w-c:\program files\Java
2009-06-10 04:39 . 2009-06-10 04:39--------d-----w-c:\program files\Trend Micro
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\Jared\Application Data\Malwarebytes
2009-06-09 17:49 . 2009-05-26 05:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-09 17:49 . 2009-05-26 05:1919096----a-w-c:\windows\system32\drivers\mbam.sys
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-06-09 16:53 . 2009-06-11 00:47410984----a-w-c:\windows\system32\deploytk.dll
2009-06-09 16:52 . 2009-06-09 16:52152576----a-w-c:\documents and settings\Jared\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-09 16:24 . 2009-06-09 17:45117760----a-w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\program files\SUPERAntiSpyware
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com
2009-06-09 15:52 . 2009-06-09 15:52--------d-----w-c:\program files\CCleaner
2009-06-09 01:26 . 2009-06-09 01:26--------d-sh--w-c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-09 01:22 . 2009-06-09 01:22--------d-----w-c:\documents and settings\All Users\Application Data\Uniblue
2009-06-09 01:07 . 2009-06-09 01:21--------d-----w-c:\program files\Uniblue
2009-06-09 00:44 . 2009-06-09 01:22--------d-----w-c:\documents and settings\Jared\Application Data\Uniblue
2009-06-09 00:43 . 2009-03-13 15:052567647-c----w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}\Uniblue RegistryBooster.exe
2009-06-09 00:43 . 2009-06-09 00:54--------dc-h--w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-05-29 07:44 . 2009-05-29 07:44--------d-----w-c:\program files\MSECache
2009-05-28 14:55 . 2009-06-08 14:30--------d-----w-c:\documents and settings\Jared\Local Settings\Application Data\S2
2009-05-28 14:52 . 2009-05-28 14:5298304----a-w-c:\windows\system32\CmdLineExt.dll
2009-05-28 14:52 . 2009-05-28 14:52--------d--h--r-c:\documents and settings\Jared\Application Data\SecuROM
2009-05-28 14:45 . 2009-05-28 14:45--------d-----w-c:\program files\Ubisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 16:22 . 2007-09-11 08:11--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-06-09 15:31 . 2008-01-23 13:45--------d-----w-c:\program files\GameHouse
2009-06-09 02:20 . 2007-12-23 05:30--------d-----w-c:\program files\YouTube Downloader
2009-06-09 01:17 . 2008-09-28 19:06--------d-----w-c:\documents and settings\Jared\Application Data\uTorrent
2009-06-08 12:41 . 2007-09-07 08:12900--sha-w-c:\windows\system32\KGyGaAvL.sys
2009-06-08 04:42 . 2009-04-04 16:21--------d-----w-c:\program files\Windows Media Connect 2
2009-06-08 04:00 . 2009-04-03 01:03--------d-----w-c:\documents and settings\Jared\Application Data\FMZilla
2009-05-29 07:45 . 2008-08-31 13:0465600----a-w-c:\documents and settings\Jared\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 13:17 . 2008-10-24 02:22--------d-----w-c:\documents and settings\Jared\Application Data\LimeWire
2009-05-21 23:42 . 2008-12-16 01:03--------d-----w-c:\documents and settings\Jared\Application Data\AVGTOOLBAR
2009-05-17 08:39 . 2009-05-10 07:43--------d-----w-c:\program files\Garena
2009-05-10 06:29 . 2009-05-10 06:29--------d-----w-c:\documents and settings\Jared\Application Data\InstallShield
2009-05-09 01:54 . 2008-12-16 01:0311952----a-w-c:\windows\system32\avgrsstx.dll
2009-05-09 01:54 . 2008-12-16 01:03325896----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-05-09 01:54 . 2008-12-16 01:0327784----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-05-09 01:54 . 2008-12-16 01:03108552----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-04-17 05:49 . 2008-11-08 06:22--------d-----w-c:\documents and settings\Jared\Application Data\Skype
2007-10-25 03:28 . 2007-10-25 03:2818895728----a-w-c:\program files\Install_Messenger.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-02-16 07:441882136----a-w-c:\program files\ToggleEN\tbTogg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="c:\program files\VDOTool\TBPanel.exe" [2007-06-26 2165272]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-11 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8466432]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-07-23 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-11 68856]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 04:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 01:5411952----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"Alcmtr"=ALCMTR.EXE
"QuickFix"=c:\program files\QuickFix\QuickFix.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizzard Downloader: 6112
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
"6999:TCP"= 6999:TCP:Blizzard Downloader: 6999
"6990:TCP"= 6990:TCP:Blizzard Downloader: 6990
"6885:TCP"= 6885:TCP:Blizzard Downloader: 6885
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"443:TCP"= 443:TCP:https
"21:TCP"= 21:TCP:ftp

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)
"AllowInboundTimestampRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)
"AllowInboundRouterRequest"= 0 (0x0)
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
"AllowOutboundTimeExceeded"= 0 (0x0)
"AllowRedirect"= 0 (0x0)
"AllowOutboundPacketTooBig"= 0 (0x0)

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/16/2008 9:03 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/16/2008 9:03 AM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/16/2008 9:03 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/16/2008 9:03 AM 298776]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [9/7/2007 2:26 PM 38656]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635618}]
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\msnmgnr.exe
.
Contents of the 'Scheduled Tasks' folder

2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 09:57]

2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42]

2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42]

2009-06-09 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2009-06-09 01:14]

2009-06-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 14:18]
.
- - - - ORPHANS REMOVED - - - -

Notify-xxyXOhFX - xxyXOhFX.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://fmz.qiwa.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jared\Application Data\Mozilla\Firefox\Profiles\rfcjzjrh.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: content.switch.threshold - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: keyword.enabled - true
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-11 09:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:17,6d,cf,8a,bc,c6,12,a1,65,fd,49,de,73,33,23,08,b0,ba,36,dd,0b,cc,85,
e8,09,5a,97,46,ab,6e,9d,d4,0d,a6,98,eb,a6,7a,22,eb,50,e7,00,14,15,c5,8e,11,\
"??"=hex:dc,bc,25,01,99,f9,4d,24,96,0e,32,50,c4,b1,f9,22

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\ProgID]
@DACL=(02 0000)
@="dc_ads.ads.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\Programmable]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\TypeLib]
@DACL=(02 0000)
@="{E94C3AF8-D32C-4389-AC9A-BE17471EDC42}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\VersionIndependentProgID]
@DACL=(02 0000)
@="dc_ads.ads"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(1476)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\program files\VDOTool\TBPanelExt.dll
c:\windows\system32\nvcpl.dll
c:\windows\system32\nvapi.dll
c:\windows\system32\nvshell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WgaTray.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-11 9:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-11 01:29

Pre-Run: 128,982,495,232 bytes free
Post-Run: 129,051,725,824 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

233--- E O F ---2009-06-09 03:00
Not there yet...

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
FF - user.js: browser.search.defaultenginename - Yoog Search

Firefox::
FF - user.js: browser.search.defaultenginename - Yoog Search

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635618}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"iTunesHelper"=-
"KernelFaultCheck"=-
"Alcmtr"=-
"QuickFix"=-


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezethe next CF log below.


ComboFix 09-06-09.06 - Jared 06/11/2009 10:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1539 [GMT 8:00]
Running from: c:\documents and settings\Jared\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jared\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.

2009-06-11 00:47 . 2009-06-11 00:47--------d-----w-c:\program files\Java
2009-06-10 04:39 . 2009-06-10 04:39--------d-----w-c:\program files\Trend Micro
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\Jared\Application Data\Malwarebytes
2009-06-09 17:49 . 2009-05-26 05:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-09 17:49 . 2009-05-26 05:1919096----a-w-c:\windows\system32\drivers\mbam.sys
2009-06-09 17:49 . 2009-06-09 17:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-06-09 16:53 . 2009-06-11 00:47410984----a-w-c:\windows\system32\deploytk.dll
2009-06-09 16:52 . 2009-06-09 16:52152576----a-w-c:\documents and settings\Jared\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-09 16:24 . 2009-06-09 17:45117760----a-w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\program files\SUPERAntiSpyware
2009-06-09 16:22 . 2009-06-09 16:22--------d-----w-c:\documents and settings\Jared\Application Data\SUPERAntiSpyware.com
2009-06-09 15:52 . 2009-06-09 15:52--------d-----w-c:\program files\CCleaner
2009-06-09 01:26 . 2009-06-09 01:26--------d-sh--w-c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-09 01:22 . 2009-06-09 01:22--------d-----w-c:\documents and settings\All Users\Application Data\Uniblue
2009-06-09 01:07 . 2009-06-09 01:21--------d-----w-c:\program files\Uniblue
2009-06-09 00:44 . 2009-06-09 01:22--------d-----w-c:\documents and settings\Jared\Application Data\Uniblue
2009-06-09 00:43 . 2009-03-13 15:052567647-c----w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}\Uniblue RegistryBooster.exe
2009-06-09 00:43 . 2009-06-09 00:54--------dc-h--w-c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-05-29 07:44 . 2009-05-29 07:44--------d-----w-c:\program files\MSECache
2009-05-28 14:55 . 2009-06-08 14:30--------d-----w-c:\documents and settings\Jared\Local Settings\Application Data\S2
2009-05-28 14:52 . 2009-05-28 14:5298304----a-w-c:\windows\system32\CmdLineExt.dll
2009-05-28 14:52 . 2009-05-28 14:52--------d--h--r-c:\documents and settings\Jared\Application Data\SecuROM
2009-05-28 14:45 . 2009-05-28 14:45--------d-----w-c:\program files\Ubisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 16:22 . 2007-09-11 08:11--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-06-09 15:31 . 2008-01-23 13:45--------d-----w-c:\program files\GameHouse
2009-06-09 02:20 . 2007-12-23 05:30--------d-----w-c:\program files\YouTube Downloader
2009-06-09 01:17 . 2008-09-28 19:06--------d-----w-c:\documents and settings\Jared\Application Data\uTorrent
2009-06-08 12:41 . 2007-09-07 08:12900--sha-w-c:\windows\system32\KGyGaAvL.sys
2009-06-08 04:42 . 2009-04-04 16:21--------d-----w-c:\program files\Windows Media Connect 2
2009-06-08 04:00 . 2009-04-03 01:03--------d-----w-c:\documents and settings\Jared\Application Data\FMZilla
2009-05-29 07:45 . 2008-08-31 13:0465600----a-w-c:\documents and settings\Jared\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 13:17 . 2008-10-24 02:22--------d-----w-c:\documents and settings\Jared\Application Data\LimeWire
2009-05-21 23:42 . 2008-12-16 01:03--------d-----w-c:\documents and settings\Jared\Application Data\AVGTOOLBAR
2009-05-17 08:39 . 2009-05-10 07:43--------d-----w-c:\program files\Garena
2009-05-10 06:29 . 2009-05-10 06:29--------d-----w-c:\documents and settings\Jared\Application Data\InstallShield
2009-05-09 01:54 . 2008-12-16 01:0311952----a-w-c:\windows\system32\avgrsstx.dll
2009-05-09 01:54 . 2008-12-16 01:03325896----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-05-09 01:54 . 2008-12-16 01:0327784----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-05-09 01:54 . 2008-12-16 01:03108552----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-04-17 05:49 . 2008-11-08 06:22--------d-----w-c:\documents and settings\Jared\Application Data\Skype
2007-10-25 03:28 . 2007-10-25 03:2818895728----a-w-c:\program files\Install_Messenger.exe
.

((((((((((((((((((((((((((((( [emailprotected]_01.27.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 02:20 . 2009-06-11 02:2016384 c:\windows\temp\Perflib_Perfdata_790.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-02-16 07:441882136----a-w-c:\program files\ToggleEN\tbTogg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-11 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1947928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8466432]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-12-20 16860672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-11 68856]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 04:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 01:5411952----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"Alcmtr"=ALCMTR.EXE
"QuickFix"=c:\program files\QuickFix\QuickFix.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizzard Downloader: 6112
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
"6999:TCP"= 6999:TCP:Blizzard Downloader: 6999
"6990:TCP"= 6990:TCP:Blizzard Downloader: 6990
"6885:TCP"= 6885:TCP:Blizzard Downloader: 6885
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"443:TCP"= 443:TCP:https
"21:TCP"= 21:TCP:ftp

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)
"AllowInboundTimestampRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)
"AllowInboundRouterRequest"= 0 (0x0)
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
"AllowOutboundTimeExceeded"= 0 (0x0)
"AllowRedirect"= 0 (0x0)
"AllowOutboundPacketTooBig"= 0 (0x0)

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/16/2008 9:03 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/16/2008 9:03 AM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/16/2008 9:03 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/16/2008 9:03 AM 298776]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [9/7/2007 2:26 PM 38656]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 09:57]

2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42]

2009-06-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2009-06-09 01:42]

2009-06-09 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2009-06-09 01:14]

2009-06-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 14:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://fmz.qiwa.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jared\Application Data\Mozilla\Firefox\Profiles\rfcjzjrh.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: content.switch.threshold - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: keyword.enabled - true
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-11 10:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:17,6d,cf,8a,bc,c6,12,a1,65,fd,49,de,73,33,23,08,b0,ba,36,dd,0b,cc,85,
e8,09,5a,97,46,ab,6e,9d,d4,0d,a6,98,eb,a6,7a,22,eb,50,e7,00,14,15,c5,8e,11,\
"??"=hex:dc,bc,25,01,99,f9,4d,24,96,0e,32,50,c4,b1,f9,22

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\ProgID]
@DACL=(02 0000)
@="dc_ads.ads.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\Programmable]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\TypeLib]
@DACL=(02 0000)
@="{E94C3AF8-D32C-4389-AC9A-BE17471EDC42}"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{733716E1-76D2-4003-AC39-845281C0EF85}\VersionIndependentProgID]
@DACL=(02 0000)
@="dc_ads.ads"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3576)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2009-06-11 10:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-11 02:26
ComboFix2.txt 2009-06-11 01:29

Pre-Run: 129,100,296,192 bytes free
Post-Run: 129,081,024,512 bytes free

212--- E O F ---2009-06-09 03:00
This one file is being stubborn.

Download Registry Search by Bobbi Flekman
(see the link TITLED RegSearch Download Link)
  • Extract the files from Regsearch.zip into a folder.
  • Doubleclick regsearch.exe to start the program.
  • Enter Yoog in the top area of the form and then click "OK".
  • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
  • Add the contents of the Notepad file to your next reply.
regsearch log below.



Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 6/11/2009 11:29:19 AM for strings:
; 'yoog'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
"URL"="http://www2.yoog.com/search.php?q={searchTerms}"
"DisplayName"="Yoog Search"

; End Of The Log.Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_USERS\S-1-5-21-1547161642-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]


Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.registry entry was successful.
    How is the computer running now?
    .
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download
ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

Thanks again Evilfantasy. Great great help u did and I appreciate it. My pc is fine now. Your welcome. Safe surfing... too bad no one is helping me..
1630.

Solve : Spyware apps won't start, browsers redirect?

Answer»

he said, Only one Anti-Virus- you can have a NUMBER of anti-spyware/malware apps installed (IE, SUPER anti-spyware and MalwareBytes Anti-Malware)Quote

he said, Only one Anti-Virus- you can have a number of anti-spyware/malware apps installed (IE, SUPER anti-spyware and MalwareBytes Anti-Malware)
Exactly, because Malwarebytes' is not real-time protection.

Quote
Antivirus - I'm running Symantec antivirus, which I'm HAPPY with except when it hogs resources when scanning. Do you recommend switching to one of the free ones?
Yes, I would recommend removing Symantec and replacing it with avast!. That's my opinion, but many people will agree with me.

Quote
Antispyware - Only one? It seems like they all catch different things. Is it OKAY to have more than one installed, as long as only one of them is actively monitoring?
Like I said above, only one real-time scanner, or as you said - one actively monitoring.

Quote
Firewall - I just have Windows Firewall.. should I deactivate that and switch to a different one?
I'd recommend Comodo. Windows Firewall = scrap.

Quote
Can I UNINSTALL the programs that I installed in this process and DELETE the logs? My wife's desktop is getting pretty crowded.
Yes, all yours.
1631.

Solve : Trojan Horse Injector opening with svchost and iexplorer.exe?

Answer» BASICALLY i think i'm having a malware problem

Following the steps now. on the SUPERAntiSpyware step, and doing the full scan.
It's been just over an HOUR now, and it APPEARS to be scanning the same few files over and over again...

If you reach a point where you think the program is stuck, MAKE a note of it and proceed to the next program.
1632.

Solve : Very odd.?

Answer»

Ok, my friend got a virus which killed his computer. (It wouldn't boot up past the "WINDOWS XP" logo.

He gave it to me to format and put windows 7 on.

I TRIED this... but it just won't work! It installs fine, then freezes at the windows 7 logo on its FIRST boot.
Kubuntu 8.10 gets past its logo and then the screen blanks out, never to return. (Even when you use the live cd!)
GParted does all its loading text then the screen goes blank too.

What am I to do?Its a Toshiba Satellite M40I just tried Kubuntu again and I got a green screen for a few seconds, then a flashing CURSOR, then the Kubuntu mouse cursor, then a light blue/black screen with nothing on it.

Very odd.Okay, i finally got gparted going and reformatted it. However, there is a small problem - the 80gb HDD is only showing up as 57gb. Any ideas? May be a hidden restore partition.

Try holding the zero KEY at boot to see if a factory restore function comes up?I tried that with no success. After talking to my friend he said there is a recovery partition, but Gparted is not picking it up. The first win7 install I did picked it up but no further ones (i did it four times) have picked it up. Is it possible the virus is still resident and is blocking Gparted etc from seeing the partition?I think i've solved the virus problem. D/loaded Darik's Boot and Nuke 1.0.7

Currently wiping and zeroing the entire HDD, killing all partitions and any remnant virus that is still lurking.

If it doesn't work past this then I know that its a hardware problem, not a virus problem.

1633.

Solve : CCleaner how do you see the cookies??

Answer»

I am trying to follow the directions. It SAYS: on the left side you will see the cookies, select this and you will have a list of cookies to keep and cookies to toss out. However many of the boxes contain a green check mark and one of them is "Cookies" I have unchecked the box, double clicked on it and re-checked the box. Please help.

Oh, why I am here... computer running very slow and typed in "Why is my computer running slow" in the google search box. And up popped your WEBSITE. I started to go through what the computer is running in the back ground and relized that the CPU would run at a 100% EVERY 30sec. or so. Then I whent through looking up the individual .exe's that were listed. On the second one I found a problem....msmsgs.exe. So I am working through the help page your site has. I am still trying to run through the first page of instructions. But right now I am stalled on where to find my cookies.

Thankyou
Wyndmeup

Wyndmeup,

If you are stalled then proceed to the next step......why would you want any cookies take them all out , the next time you go to the sight it will put it back

when you open ccleaner untick everthing eccept cookies and run , it brings up your list then click the one you want to remove , but remember the ones to have to reclick if you want to not have to relogin to CERTAIN websites (like your yahoo account for example, if you're using the My Yahoo! as your homepage), then you'll want to have that cookie saved!

Not all cookies are bad, but you'll have to pick and choose what you definitely want to save so ccleaner won't delete it if you always want to have the clear cookies options enabled.2x3i5x , you must log into yahoo now and again for security reasons as you do in ch and other sites , you are wrong in saying keep their cookie and you don't have to , harryWell, I had my cookie on for a long time and things seem okay. But I do have yahoo ask for my password at the interval times when I do log into the yahoo email.

But of course, you want to be safe, but it's not incorrect what I SAID, just you gotta be careful at all costs that somebody don't hack your account and become you without your permission!

1634.

Solve : autorun.inf on USB and Virus Killing?

Answer»

This is my first post, but I am house trained and can generally communicate in a coherent manner.

I searched the forum to find information on this but I couldn't find anything.

What I want to figure out is how to create an autorun.inf for my USB drive which will start a batch file I created. The batch file removes the autorun.inf and (Random Name).dll the virus on the computer I have to use likes to drop on any USB drive inserted in it.

The reason I have to do this is that the Norton AV on the computer does not seem to think anything is amiss and it is a locked down computer on a domain of which I am not an admin. I have brought this issue to the attention of the head IT guy and his response is "They're all like that, there's nothing I can do." He doesn't have the ability to change the AV suite to something that actually works (AVG) and there are hundreds of machines scattered all over the country... So.

I wrote the following batch and placed it in a folder CALLED 'data' on the root of the USB drive. I run it after the USB drive is inserted and infected before I pull it out:

shell/command=
echo
del /f/a:h ..\*.dll
del /f/a:s ..\*.dll
del /f/a:R ..\*.dll
del /f/a:a ..\*.dll
del /f/a:sh ..\*.dll
del /f/a:rsh ..\*.dll
del /f/a:h ..\autorun.inf
del /f/a:s ..\autorun.inf
del /f/a:r ..\autorun.inf
del /f/a:a ..\autorun.inf
del /f/a:sh ..\autorun.inf
del /f/a:rsh ..\autorun.inf
xcopy/h/r/y ..\data\autorun.inf ..\autorun.inf
echo off

This is some ugly code, I know. What it does is deletes any DLL file on the root of the thumb drive, whether Read Only, SYSTEM or Hidden. Since I have no reason to have a DLL file in the root of my USB drive, and the virus is loaded to the drive as a DLL, this is a good thing.

The second thing it does is copy my autorun.inf out of the folder 'data' where I keep a backup and write it to the root so my custom icon and label show when I insert the drive into a computer.

The only hangup with the batch file is that the dos window asks whether "autorun.inf" is a file or directory during the operation and I have to type 'F' to complete the run.

So, what I would like is some help with:

1) The autorun.inf: I can't seem to come up with the syntax to get it to run the batch file. Does anyone know?
2) The batch file: Is there a switch or different syntax to get it to know that autorun.inf is a file and save me from having to type 'F'?
3) Is there a way to delay the execution of the batch to allow the virus time to do its thing and 'check the block' before the batch fixes it?

Any help or guidance is gratefully accepted.

KyleWelcome to the forum.

Are you trying to move a virus from a flash drive to another PC?Thank you for the welcome.

Actually, I'm trying to keep it away from my computer. I have to use an infected box and the batch file above deletes the virus files from my USB drive. Then I pull out the drive and go on my way knowing that I am not a vector for the infection.

I just need some help cleaning up the code and automating the process. I figured somebody here would be able to assist. The only way you will ever clean the virus is with an Antivirus Program or with information on the virus itself and exactly what it does (what the files it creates are and what registry entries it modifies).

So, is there a virus on your PC or on other PC?The virus is on the computers I use at work. My box is clean and I am diligent about keeping it so.

The virus on the work boxes simply dumps an autorun.inf and a (random name).dll on the root of the USB drive. So I delete the autorun and all dlls on the root before I pull the USB drive out. That keeps me from transmitting the virus to other computers, like mine. That is what that batch file does for me so I don't have to do it manually.

The USB drive is a transport medium, it can only be a carrier. Only an OS can be infected. If the transmission files are deleted they can't be launched, and that is that. Since I know that there should be no dlls on my USB drives root and I wrote my own autorun.inf file, I can IDENTIFY the vector and delete it.

Since I cannot tear into the work boxes and the IT folks have surrendered, I am taking steps to protect my box. I just need a little coding help and I think this may be useful to others who are stuck in the same situation.I like what you are on to and it could indeed be a huge help to others. There is already a tool very similar to what you are trying to do that is available for use (free) by a brilliant malware fighter named sUBs called Flash Disinfector.

That said we aren't a bunch of coders here and we mainly focus on malware removal.

You might want to sign up at Wilders Security Forum. The Wilders forums are frequented by users who take a great interest in exactly what you are doing and I would think they would have some good advice.

Good luck!Evilfantasy, I appreciate your post.

When I went looking for something to help me with this I couldn't find anything. Probably I was using the wrong search terms. I figure that all I really need is someone who has more recent experience with DOS commands, Windows 3.1 was heady stuff a long time AGO, but it was a long time ago...

I will check out the two places you suggested.

If anyone here thinks of something that will help please post it. Try this.

Create a batch file with the following code:
Code: [Select]attrib
pause
Now save it to your flash drive.

Plug it in the infected computer so your flash drive gets infected.
Run the batch file from the Flash Drive and look for any files with an SH attribute.
If you see any files with that attribute, post their filenames here.
This way we may be able to find out what the virus actually is.

Know your enemy before you try to defend against it. Carbon,

Here is the skinny on the viri I am dealing with:

Upon insertion of a USB drive the following are dropped on the root of the USB drive: (Random Name).dll and autorun.inf.

They are always the same except for the name of the .dll.

My last was called “svcpacj.dll” which has attributes: h s r.
The autorun.inf, which has attributes: h s r, is:

[autorun]
open=
shell\open=Explore
shell\open\Command=rundll32.exe .\\svcpacj.dll,InstallM
shell\open\Default=1

I have the dll saved as a txt if you’d like to see the code.

I tried DriveSentry on another USB drive and it failed to start automatically. When I tried to start it manually I got a message that I did not have admin privileges on the machine. So I just deleted the files manually since I did not have that drive set up with my batch file.

I brought the dll back in a sub folder on my USB drive to my box and AVG identified it as Trojan horse Downloader.Generic7.NAI. Which name does not come up in a Google search.

Really, the name and nature of the pest is less important to me than that I can kill it. I’d just like to make the killing less obtrusive.
save as autorun.inf
Code: [Select][autorun]
icon=drive.ico
open=launch.bat
action=Click ok to Run DLL_del.bat
shell\open\command=DLL_del.bat
save as DLL_del.bat
Code: [Select]@echo off
SET odrive=%odrive:~0,2%
attrib -h -s -r -a *.dll
del /f *.dll
attrib -h -s -r -a autorun.inf
del /f autorun.inf
"%drive%\data\autorun.inf"
xcopy "%drive%\data\autorun.inf" "%drive%"
that is as far as i got but it does not want to copy the real autorun it opens it in notepad

1635.

Solve : Completed the six steps for malware and still need help...?

Answer»

can SOMEONE please HELP me with this? Her are my LOGS:

http://www.filedropper.com/superantispywarescanlog-06-01-2009-18-45-28_1

http://www.filedropper.com/mbam-log-2009-06-0120-19-35_1

http://www.filedropper.com/hijackthis_3

[ATTACHMENT deleted by admin]

1636.

Solve : I think my computer is infected with some kinda virus.?

Answer»

Okay. My computer has been running very slow as of late. Plus..When I click on a link after doing a google search, I am taken to a PAGE that is totally different than the link I clicked. I ran a few programs such as Spybot, Super anti spyware and Malware bytes. All of which picked up some tracking cookies, but not much more than that. However. When running Spybot, I noticed that the program would freeze while trying to scan Virtumonde.sdn

So I scanned with spybot in safe mode. That seemed to get rid of Virtumonde.sdn

But my PC is now doing everything it was doing before. Any help would be appreciated. I scanned with Hijack This. This is the log file.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:17, on 2009-05-27
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\johnny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,[emailprotected]
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\johnny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Geni Publisher - http://www.geni.com/plugins/genipublisher.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebook.com/controls/FacebookPhotoUploader2.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.putfile.com/includes/ImageUploader4.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - PROTOCOL: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\fufoburo,C:\WINDOWS\system32\fufoburo.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\superantispyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

--
End of file - 7347 bytes
Anybody?


Edit:Sorry. I just noticed the NO Bump rule. Unfortunately, there are no malware specialists online now, but the first thing that I can see anyway, is that you've got 2 anti-virus programs running. Not recommended!Okay. I disabled Nod32. And thanks for the reply. You'd be better off uninstalling one of them. It doesn't matter which, but having two installed can cause conflicts, false-alerts, and slowness.I uninstalled nod32 since I can't really update it anymore. Download DDS by sUBs and save it to your desktop. Alternate DDS download link

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.
Quote

DDS (Ver_09-05-14.01) - NTFSx86
Run by johnny at 9:46:51.01 on Sun 05/31/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.33 [GMT -3:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\johnny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\johnny\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No File
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\johnny\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Geni Publisher - hxxp://www.geni.com/plugins/genipublisher.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader2.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - hxxp://www.putfile.com/includes/ImageUploader4.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\windows\system32\fufoburo,c:\windows\system32\fufoburo.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli c:\windows\system32\fufoburo.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\johnny\applic~1\mozilla\firefox\profiles\yb7con40.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\documents and settings\johnny\application data\mozilla\firefox\profiles\yb7con40.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll
FF - plugin: c:\documents and settings\johnny\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npBitCometAgent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npnul32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppdf32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppl3260.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nprjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npupd62.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox 3.5 beta 4\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror");
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false);
c:\program files\mozilla firefox 3.5 beta 4\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-18 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-18 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-18 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2006-10-10 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 55024]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-18 298776]
S3 bfastfao;bfastfao;\??\c:\docume~1\johnny\locals~1\temp\bfastfao.sys --> c:\docume~1\johnny\locals~1\temp\bfastfao.sys [?]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\pavsrk.sys --> c:\windows\system32\PavSRK.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
S3 SiSV6306;SiSV6306;c:\windows\system32\drivers\SiS6306p.sys [2006-6-21 68608]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2005-12-28 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2005-12-28 85696]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-18 908568]
S4 Tmpmaa8ydhutat;Tmpmaa8ydhutat;


=============== Created Last 30 ================

2009-05-31 09:44<DIR>--d-h---c:\windows\PIF
2009-05-18 23:55<DIR>--d-h---C:\$AVG8.VAULT$
2009-05-18 18:5211,952a-------c:\windows\system32\avgrsstx.dll
2009-05-18 18:52108,552a-------c:\windows\system32\drivers\avgtdix.sys
2009-05-18 18:52325,896a-------c:\windows\system32\drivers\avgldx86.sys
2009-05-18 18:51<DIR>--d-----c:\windows\system32\drivers\Avg
2009-05-18 18:51<DIR>--d-----c:\docume~1\johnny\applic~1\AVGTOOLBAR
2009-05-18 18:51<DIR>--d-----c:\program files\AVG
2009-05-18 18:51<DIR>--d-----c:\docume~1\alluse~1.win\applic~1\avg8
2009-05-10 08:5641,424a-------c:\windows\system32\drivers\VBoxUSBMon.sys
2009-05-10 08:41<DIR>--d-----c:\program files\Mozilla Firefox 3.5 Beta 4
2009-05-06 00:10<DIR>--d-----C:\VundoFix Backups
2009-05-05 19:55266a-------c:\windows\wininit.ini

==================== Find3M ====================

2009-04-06 15:3238,496a-------c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 15:3215,504a-------c:\windows\system32\drivers\mbam.sys
2009-03-06 11:22284,160a-------c:\windows\system32\pdh.dll
2009-03-02 21:18826,368a-------c:\windows\system32\wininet.dll
2007-09-05 20:0756---shr--c:\windows\system32\95DF0265E4.sys
2006-05-03 06:06163,328---shr--c:\windows\system32\flvDX.dll
2007-09-05 20:073,350a--sh---c:\windows\system32\KGyGaAvL.sys
2007-02-21 07:4731,232---shr--c:\windows\system32\msfDX.dll
2007-12-17 09:4327,648---sh---c:\windows\system32\Smab0.dll
2008-09-15 20:2532,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090820080915\index.dat
2008-09-15 23:5732,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091520080916\index.dat
2008-09-16 20:4549,152a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091620080917\index.dat

============= FINISH: 9:48:02.93 ===============


Quote
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 6/20/2006 11:23:10 PM
System UPTIME: 5/28/2009 6:46:37 PM (63 hours ago)

Motherboard: Seanix | | MS-6769
Processor: Intel(R) Celeron(R) CPU 2.20GHz | Socket 478 | 2191/100mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 75 GiB total, 11.673 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP39: 7/20/2006 9:27:16 AM - System Checkpoint
RP40: 7/21/2006 11:37:33 AM - System Checkpoint
RP41: 7/21/2006 7:39:16 PM - Installed Microsoft AntiSpyware
RP42: 7/21/2006 8:31:45 PM - Removed Microsoft AntiSpyware
RP43: 7/22/2006 11:29:39 PM - System Checkpoint
RP44: 7/23/2006 4:35:52 PM - Installed PopThis! Free Version
RP45: 7/24/2006 6:17:48 PM - System Checkpoint
RP46: 7/25/2006 7:13:18 PM - System Checkpoint
RP47: 7/26/2006 8:15:58 PM - System Checkpoint
RP48: 7/27/2006 10:16:55 PM - System Checkpoint
RP49: 7/28/2006 11:21:58 PM - System Checkpoint
RP50: 7/30/2006 12:09:29 AM - System Checkpoint
RP51: 7/31/2006 1:09:29 AM - System Checkpoint
RP52: 8/1/2006 1:10:35 AM - System Checkpoint
RP53: 8/2/2006 2:09:29 AM - System Checkpoint
RP54: 8/3/2006 2:49:06 AM - System Checkpoint
RP55: 8/4/2006 3:09:24 AM - System Checkpoint
RP56: 8/4/2006 7:27:12 PM - Installed SmartFTP Client 2.0
RP57: 8/4/2006 7:53:58 PM - Installed Microsoft Office XP Professional with FrontPage
RP58: 8/5/2006 8:18:27 PM - System Checkpoint
RP59: 8/7/2006 12:23:56 AM - System Checkpoint
RP60: 8/8/2006 1:02:35 AM - System Checkpoint
RP61: 8/9/2006 2:49:29 AM - System Checkpoint
RP62: 8/10/2006 3:06:32 AM - System Checkpoint
RP63: 8/11/2006 4:06:28 AM - System Checkpoint
RP64: 8/12/2006 9:38:04 AM - System Checkpoint
RP65: 8/13/2006 9:56:56 AM - System Checkpoint
RP66: 8/14/2006 10:36:51 AM - System Checkpoint
RP67: 8/15/2006 11:36:52 AM - System Checkpoint
RP68: 8/16/2006 12:36:50 PM - System Checkpoint
RP69: 8/17/2006 1:36:51 PM - System Checkpoint
RP70: 8/18/2006 2:36:48 PM - System Checkpoint
RP71: 8/19/2006 3:36:51 PM - System Checkpoint
RP72: 8/20/2006 5:26:34 PM - System Checkpoint
RP73: 8/21/2006 6:20:58 PM - System Checkpoint
RP74: 8/22/2006 6:36:47 PM - System Checkpoint
RP75: 8/23/2006 7:36:47 PM - System Checkpoint
RP76: 8/24/2006 8:37:27 PM - System Checkpoint
RP77: 8/25/2006 10:01:22 PM - System Checkpoint
RP78: 8/26/2006 11:34:19 PM - System Checkpoint
RP79: 8/28/2006 12:58:39 AM - System Checkpoint
RP80: 8/28/2006 11:43:12 PM - Installed Panda Titanium 2006 Antivirus + Antispyware
RP81: 8/30/2006 12:59:58 AM - System Checkpoint
RP82: 8/31/2006 7:31:57 PM - System Checkpoint
RP83: 9/2/2006 12:09:41 PM - System Checkpoint
RP84: 9/3/2006 10:41:46 PM - System Checkpoint
RP85: 9/5/2006 12:28:42 AM - System Checkpoint
RP86: 9/5/2006 8:54:09 PM - Installed The Print Shop Business Card Creator
RP87: 9/6/2006 10:54:10 PM - System Checkpoint
RP88: 9/7/2006 11:08:54 PM - System Checkpoint
RP89: 9/8/2006 11:52:31 PM - System Checkpoint
RP90: 9/10/2006 2:26:55 AM - System Checkpoint
RP91: 9/11/2006 2:36:58 AM - System Checkpoint
RP92: 9/12/2006 4:02:32 AM - System Checkpoint
RP93: 9/13/2006 4:34:01 AM - System Checkpoint
RP94: 9/14/2006 5:46:42 AM - System Checkpoint
RP95: 9/15/2006 5:59:06 AM - System Checkpoint
RP96: 9/16/2006 6:49:55 AM - System Checkpoint
RP97: 9/17/2006 7:49:49 AM - System Checkpoint
RP98: 9/18/2006 8:10:01 AM - System Checkpoint
RP99: 9/19/2006 8:12:30 AM - System Checkpoint
RP100: 9/20/2006 8:22:32 AM - System Checkpoint
RP101: 9/21/2006 9:35:01 AM - System Checkpoint
RP102: 9/22/2006 9:40:29 AM - System Checkpoint
RP103: 9/23/2006 9:56:43 AM - System Checkpoint
RP104: 9/24/2006 10:50:51 AM - System Checkpoint
RP105: 9/24/2006 3:25:20 PM - Installed Windows Media Player 10
RP106: 9/25/2006 4:13:38 PM - System Checkpoint
RP107: 9/26/2006 4:49:54 PM - System Checkpoint
RP108: 9/27/2006 5:22:31 PM - System Checkpoint
RP109: 9/28/2006 6:08:10 PM - System Checkpoint
RP110: 9/28/2006 8:22:14 PM - Removed Panda Titanium 2006 Antivirus + Antispyware
RP111: 9/28/2006 8:39:06 PM - Installed Trend Micro PC-cillin Internet Security 2006
RP112: 9/29/2006 10:54:04 PM - System Checkpoint
RP113: 10/1/2006 1:12:07 AM - System Checkpoint
RP114: 10/2/2006 2:06:52 AM - System Checkpoint
RP115: 10/3/2006 3:06:51 AM - System Checkpoint
RP116: 10/4/2006 3:07:57 AM - System Checkpoint
RP117: 10/5/2006 4:06:52 AM - System Checkpoint
RP118: 10/6/2006 5:06:52 AM - System Checkpoint
RP119: 10/7/2006 6:06:53 AM - System Checkpoint
RP120: 10/7/2006 9:01:02 PM - Installed Windows Media Player 10 KB917734_WMP10.
RP121: 10/7/2006 9:03:18 PM - Installed Windows XP KB911280.
RP122: 10/8/2006 11:34:20 PM - System Checkpoint
RP123: 10/10/2006 12:22:58 AM - System Checkpoint
RP124: 10/11/2006 1:24:02 AM - System Checkpoint
RP125: 10/12/2006 2:22:58 AM - System Checkpoint
RP126: 10/13/2006 3:22:57 AM - System Checkpoint
RP127: 10/14/2006 4:22:57 AM - System Checkpoint
RP128: 10/15/2006 5:21:57 AM - System Checkpoint
RP129: 10/15/2006 9:19:47 AM - Installed J2SE Runtime Environment 5.0 Update 9
RP130: 10/16/2006 4:37:41 PM - Installed InstantCopy
RP131: 10/16/2006 4:43:37 PM - Install CloneDVD
RP132: 10/17/2006 5:13:09 PM - System Checkpoint
RP133: 10/17/2006 10:20:04 PM - Installed DirectX
RP134: 10/17/2006 10:20:54 PM - Installed Nero 7

==== Installed Programs ======================

Able2Extract Professional v4.0
[emailprotected] ISO Burner v 1.1
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Download Manager 2.2 (Remove Only)
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop 7.0
Adobe Photoshop CS3
Adobe Reader 7.0.9
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Advertisement Service
Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4
Amor AVI DivX to VCD SVCD DVD Converter 2.3
AnyDVD
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
AutoUpdate
Avant Browser (remove only)
AVG Free 8.5
Backburner
BitComet 1.06
Bonjour
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
CDisplay 1.8
Combined Community Codec Pack 2007-07-22
CopyToDVD
Crimson Editor (remove only)
Critical Update for Windows Media Player 11 (KB959772)
Dell AIO 810
DivX Codec
DivX Converter
DivX Player
DivX Web Player
DVD-RAM Driver
DVD X Rescue
DVDXCopy Platinum 3.2.1
Easy CD & DVD Creator 6
GOM Player
Google Chrome
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
HP Original supplies
ieSpell 2.2.0 (build 647)
iTunes
J2SE Runtime Environment 5.0 Update 9
Jasc Animation Shop 3
K-Lite Codec Pack 2.77 Full
LADSPA_plugins-win-0.4.15
LG PC Suite
LG USB Modem driver
LimeWire 4.18.8
Magic ISO Maker v5.4 (build 0251)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
MIKSOFT Mobile Media Converter
Mozilla Firefox (3.0.10)
Mozilla Firefox (3.5b4)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
My Drivers 3.31
Nero 8
neroxml
Open Video Converter version 3.0.3
Opera 9.27
Orca Browser (remove only)
PDF Settings
PeerGuardian 2.0
PopThis! Free Version
PowerISO
QuickTime
RealPlayer
Realtek AC'97 Audio
Registry Mechanic
Rhapsody Player Engine
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
SereneScreen Aquarium
SiS 650_651_M650_M652_740
SiS VGA Utilities
SiSAGP driver
SmartFTP Client
SmartFTP Client 2.0 Setup Files (remove only)
SmartFTP Client 3.0 Setup Files (remove only)
Sony Ericsson DRM Packager 1.35
Sony Vegas Pro 8.0
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
SpywareBlaster 4.0
SUPER © Version 2008.bld.30 (Mar 22, 2008)
SUPERAntiSpyware Free Edition
SWF & FLV Toolbox 3.5 (build 3.5.17.252)
Tsunami-Filter-Pack
Update for Windows XP (KB967715)
URGE
VCRedistSetup
VLC media player 0.9.4
WebFldrs XP
Winamp
WinAVI Video Converter
Windows Defender Signatures
Windows Desktop Search 3.01
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Movie Maker 2.0
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
Xara Webstyle 3.0
XML Paper Specification Shared Components Pack 1.0
Xvid 1.1.3 final uninstall

==== Event Viewer Messages From Past Week ========

5/27/2009 5:14:05 PM, error: SRService [104] - The System Restore initialization process failed.
5/27/2009 5:12:47 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
5/27/2009 12:43:34 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Aspi32 AvgLdx86 AvgMfx86 AvgTdiX cdudf_xp Fips intelppm IPSec MRxSmb NetBIOS NetBT nod32drv RasAcd Rdbss SASDIFSV SASKUTIL SCDEmu Tcpip WS2IFSL
5/27/2009 12:43:34 PM, error: Service Control Manager [7023] - The System Restore Service service terminated with the following error: The system cannot find the file specified.
5/27/2009 12:43:34 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
5/27/2009 12:43:34 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
5/27/2009 12:43:34 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
5/27/2009 12:43:34 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
5/27/2009 12:42:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

==== End Of File ===========================
Go to Add or Remove Programs and uninstall:

- AutoUpdate
- Spybot - Search & Destroy 1.4 <- WAY out of date!
- SpywareBlaster 4.0 <- Needs to be updated to Version 4.2

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
Tmpmaa8ydhutat
bfastfao

RootKit::
bfastfao.sys

DDS::
mStart Page = about:blank
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No File
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
AppInit_DLLs: c:\windows\system32\fufoburo,c:\windows\system32\fufoburo.dll
LSA: Notification Packages = scecli c:\windows\system32\fufoburo.dll

File::
c:\windows\system32\fufoburo.dll

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

Download JavaRa to your Desktop and unzip it to its own folder.

  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts. A log will appear (JavaRa.log), please post the contents of this log on the forum.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
.
Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.
I couldn't find anything in add remove programs called AutoUpdate


Combofix log

Quote
ComboFix 09-05-31.02 - johnny 05/31/2009 20:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.98 [GMT -3:00]
Running from: c:\documents and settings\johnny\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\johnny\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\fufoburo.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\messenger\msmsgs.exe
c:\windows\patch.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BFASTFAO
-------\Legacy_TDSSSERV
-------\Service_bfastfao
-------\Service_Tmpmaa8ydhutat


((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.

2009-05-31 12:44 . 2009-05-31 12:44--------d--h--w-c:\windows\PIF
2009-05-31 00:34 . 2009-01-19 08:4843008----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
2009-05-31 00:34 . 2009-01-19 08:4843008----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-05-31 00:34 . 2009-01-19 08:48233984----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-05-31 00:34 . 2009-01-19 08:48245248----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll
2009-05-31 00:34 . 2009-01-19 08:48239616----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-05-31 00:34 . 2009-01-19 08:48243200----a-w-c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll
2009-05-19 02:55 . 2009-05-30 05:22--------d--h--w-C:\$AVG8.VAULT$
2009-05-18 21:52 . 2009-05-18 21:5211952----a-w-c:\windows\system32\avgrsstx.dll
2009-05-18 21:52 . 2009-05-18 21:52108552----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-05-18 21:52 . 2009-05-18 21:52325896----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-05-18 21:51 . 2009-05-18 21:5127784----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-05-18 21:51 . 2009-05-31 12:26--------d-----w-c:\windows\system32\drivers\Avg
2009-05-18 21:51 . 2009-05-21 00:25--------d-----w-c:\documents and settings\johnny\Application Data\AVGTOOLBAR
2009-05-18 21:51 . 2009-05-31 23:41--------d-----w-c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-05-18 21:51 . 2009-05-18 21:51--------d-----w-c:\program files\AVG
2009-05-14 19:52 . 2009-05-14 19:52390664----a-w-c:\documents and settings\johnny\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-10 11:56 . 2009-04-27 23:3941424----a-w-c:\windows\system32\drivers\VBoxUSBMon.sys
2009-05-10 11:41 . 2009-05-18 13:24--------d-----w-c:\program files\Mozilla Firefox 3.5 Beta 4
2009-05-06 03:10 . 2009-05-06 03:10--------d-----w-C:\VundoFix Backups
2009-05-06 02:05 . 2009-05-20 19:22117760----a-w-c:\documents and settings\johnny\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2100-07-12 21:16 . 2005-03-29 02:10--------d-----w-c:\program files\Common Files\Symantec Shared
2009-05-31 22:56 . 2008-07-11 02:43--------d-----w-c:\program files\PeerGuardian2
2009-05-31 22:53 . 2006-06-21 01:12--------d-----w-c:\program files\SpywareBlaster
2009-05-31 22:52 . 2006-07-24 11:24--------d-----w-c:\program files\Spybot - Search & Destroy
2009-05-31 22:52 . 2006-07-24 11:24--------d-----w-c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-05-28 22:18 . 2006-06-21 01:15--------d-----w-c:\program files\CyberLink
2009-05-28 22:17 . 2005-03-29 06:06--------d--h--w-c:\program files\InstallShield Installation Information
2009-05-28 22:14 . 2007-07-17 19:18--------d-----w-c:\program files\Azureus
2009-05-28 22:14 . 2006-06-23 23:20--------d-----w-c:\program files\Ares
2009-05-22 15:19 . 2008-10-05 23:30--------d-----w-c:\program files\Avant Browser
2009-05-20 19:22 . 2008-01-10 00:59--------d---a-w-c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-05-18 21:21 . 2006-07-01 22:52--------d-----w-c:\program files\Dl_cats
2009-05-18 18:51 . 2008-09-16 22:51--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-05-18 18:51 . 2008-09-16 22:522967799----a-w-c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-18 18:41 . 2008-12-08 11:09--------d-----w-c:\program files\BitComet
2009-05-08 21:00 . 2006-06-25 13:50--------d-----w-c:\documents and settings\johnny\Application Data\Roxio
2009-05-06 01:59 . 2007-06-03 22:18--------d-----w-c:\program files\superantispyware
2009-04-19 02:19 . 2008-12-26 02:20--------d-----w-c:\documents and settings\johnny\Application Data\LimeWire
2009-04-06 18:32 . 2008-09-16 22:5138496----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 18:32 . 2008-09-16 22:5115504----a-w-c:\windows\system32\drivers\mbam.sys
2009-03-06 14:22 . 2004-08-04 03:56284160----a-w-c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 03:56826368----a-w-c:\windows\system32\wininet.dll
2007-09-05 23:07 . 2007-09-05 22:5956--sh--r-c:\windows\system32\95DF0265E4.sys
2006-05-03 09:06 . 2008-05-12 00:25163328--sh--r-c:\windows\system32\flvDX.dll
2007-09-05 23:07 . 2007-09-05 22:533350--sha-w-c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2008-05-12 00:2531232--sh--r-c:\windows\system32\msfDX.dll
2007-12-17 12:43 . 2008-05-12 00:2527648--sh--w-c:\windows\system32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\johnny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-19 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-02-27 47104]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2006-03-09 49152]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\superantispyware\SASSEH.DLL" [2008-11-12 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-05-06 01:59356352----a-w-c:\program files\superantispyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-18 21:5211952----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^RAMASST.lnk]
backup=c:\windows\pss\RAMASST.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Utility Tray.lnk]
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneDVDElbyDelay
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrevxOne
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS KHooker
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue Registry Booster
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pctspk"=2 (0x2)
"sdAuxService"=3 (0x3)
"sdCoreService"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"WinDefend"=2 (0x2)
"AresChatServer"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Autodesk Licensing Service"=2 (0x2)
"mi-raysat_3dsmax8"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)
"aspnet_state"=3 (0x3)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"CCALib8"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"usnjsvc"=3 (0x3)
"avg8emc"=2 (0x2)
"avg8wd"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19686:TCP"= 19686:TCP:BitComet 19686 TCP
"19686:UDP"= 19686:UDP:BitComet 19686 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/18/2009 6:52 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/18/2009 6:52 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [10/10/2006 1:53 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2/27/2007 12:39 PM 55024]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2/16/2006 5:51 PM 4096]
S3 SiSV6306;SiSV6306;c:\windows\system32\drivers\SiS6306p.sys [6/21/2006 12:04 AM 68608]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [12/28/2005 12:48 PM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [12/28/2005 12:49 PM 85696]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/18/2009 6:51 PM 908568]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/18/2009 6:51 PM 298776]
.
Contents of the 'Scheduled Tasks' folder

2009-05-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34]

2009-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1606980848-688789844-725345543-1003.job
- c:\documents and settings\johnny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 22:46]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys
MSConfigStartUp-pccguide - (no file)
MSConfigStartUp-SCDEmuApp - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949}
DPF: Geni Publisher - hxxp://www.geni.com/plugins/genipublisher.CAB
FF - ProfilePath - c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yb7con40.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\documents and settings\johnny\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBitCometAgent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nprjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npupd62.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror");
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false);
c:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 20:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(580)
c:\program files\superantispyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(1840)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\system32\searchindexer.exe
.
**************************************************************************
.
Completion time: 2009-05-31 21:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-01 00:04
ComboFix2.txt 2009-05-28 22:46

Pre-Run: 5,620,408,320 bytes free
Post-Run: 6,102,302,720 bytes free

261--- E O F ---2009-05-18 21:35



JavaRa.log

Quote
JavaRa 1.14 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Sun May 31 21:07:46 2009

Found and removed: C:\Program Files\Java\jre1.5.0_01

Found and removed: C:\Windows\System32\jpicpl32.cpl

Found and removed: Software\JavaSoft\Java2D\1.5.0_09

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510009

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510009

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510009

Found and removed: SOFTWARE\Classes\JavaPlugin.150_09

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_09

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_09

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510009

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510009

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150090}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_09

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_09\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

------------------------------------

Finished reporting.




    That looks OK. How is the computer running now?

    Cleanup steps. Be sure to do these to prevent reinfection.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download
ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

----------

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
Important: Restart the computer before continuing.
Everything seems to be working normally....so far. I've even noticed a difference in speed. Much faster.
I can't thank you enough for your time. It is very much appreciated. If I ever have a problem again....I know where I am heading... and will recommend this site to all my friends.

Just one question. I'm looking for a solid anti-virus/anti-spyware program. Something that is effective, but doesn't bog down an older PC. Is there such a thing? If so...Please help me out.
Thanks in advance. I prefer either Avast or Avira.

Remember to only install one antivirus!

Avast! Home Free Edition

Avira AntiVir Personal

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Again...Thank you very much.
1637.

Solve : Possible spyware on computer?

Answer»

Guys

I was at a WEBSITE i should haven't been on and suddenly firefox slowed down and everything was frozen and I had to reboot. I restarted and then saw the WINDOWS update icon on the TASKBAR showing '0% downloaded" and when I clicked on it, it didn't come up. I right-clicked and it presented no options at all. Then I checked my \windows\WindowsUpdate.log and didn't see any activity for the time PERIOD when I saw the icon.

I suspect some sort of virus or spyware is INSTALLED. I did a spybot clean and it only shows cookies

Attached is my hijack this log. I do see a funny service installed called XJOENIYP.exe. What else can I try? Can someone suggest any rootkit detectors as well?

Thank you

[attachment deleted by admin]

1638.

Solve : Will Avast get rid of a virus??

Answer»

Yes , here's a link

http://netsquirrel.com/msconfig/msconfig_vista.htmlHow long ago did you install the HP printer? usually software from HP slows down the computer, especially digital imaging monitor. WHat happened to me was that (mine being wireless) every time I had turned the computer on it would take like 30 seconds to search for the printer on the network.Karnac -
Thanks for the link I will use it. Bob


Iamtonsoffun247 -
I connected the HP printer after I took the full factory restart, which was 2 or 3 weeks ago. It might have been about this time that I noticed the slowdown. Is there any way I can change HP looking for the printer? Thanks Bob


Karnac -
A couple of days ago you gave me this link: "netsquirrel.com/msconfig/msconfig_vista.html". I ran it. When I got the "Security Configuration" panel I found only 10 items listed. The first 3 appeared to be identical: "Intel(R()com". I eliminated the first 2. This put them last with the date that they were disabled. It did not appear to have changed the time for the computer to get on line at start up. As I said all other times appear normal. Any other suggestions? BobWhen you type msconfig in the run box, the system configuration window opens and there are several tabs....the Startup tab is the one you want.....then uncheck the programs you don't reguire at startup...this will speed up your startup. I have 2 startup items checked.....my firewall and my antivirus......all other boxes are unchecked......I open other programs as I require them.

You can also Click the Start button , click All Programs, right-click the Startup folder, and then click Open and delete any programs you don't need at startup.Karnac -
OK I got to the systems configuration and unchecked all the programs but two: Avast antivirus & Super antispyware. That did not make any difference. I have now returned to all of them checked. Maybe there is something wrong some place and not in the start up. I am not going to fight this but if you have any other suggestions I will try them. To review: When I PRESS the POWER button the monitor lights up after 40 seconds. Then it takes another 1 minute and 45 seconds for the red check mark to LEAVE the internet icon so I can use the internet. Thanks for all the help you have given me. BobMake sure you have your firewall on....Have a look and see if you are due for a defrag....you say they are all checked now.....did you click apply and reboot?........they should not return ,, only the checked programs should be therehi karnac , i did as you said in your post below took 6 out how do i find out what the rest are , also why are a lot of the ones below ticked but also stopped , these are the only questions i'll ask don't want to open a new post up , harry
-----------------------------

When you type msconfig in the run box, the system configuration window opens and there are several tabs....the Startup tab is the one you want.....then uncheck the programs you don't reguire at startup...this will speed up your startup. I have 2 startup items checked.....my firewall and my antivirus......all other boxes are unchecked......I open other programs as I require them.

You can also Click the Start button , click All Programs, right-click the Startup folder, and then click Open and delete any programs you don't need at


[attachment deleted by admin]Harry, you're in the wrong Tab....you want StartUp.....not Servicesjust looking in there i'll start my own topic under " system config " in other if you want to look at it , harry

1639.

Solve : Search engines hijacked! Have run...?

Answer»

Spybot, ad-aware, malwarebytes, Windows Defender and trend MICRO all say no virui or spyware, even after running them in safe mode.

When I do a search with Google, yahoo, or Microsoft, the first link I click on works normally, but the second link is a redirect to some unrelated site.

I use Firefox primarily, and IE on OCCASION. Happens with both. Following is the Hijackthis log. I humbly ask for help. Thanks!

LOGFILE of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:02 PM, on 6/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP SOFTWARE Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HTTP://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228702204676
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7521 bytes


Try doing a Kaspersky Online Scan:
http://www.kaspersky.co.uk/virusscanner

I will take a while to complete though.OK, Wyatt, I'll give it a shot.

In the meantime, I read the "READ THIS BEFORE POSTING" after I posted the above (ah, sorry) and as it suggested I disabled teatimer and downloaded Superantispyware and ran a scan with it. It said it picked up and cleaned a few spywares and trogans, but after rebooting, no change in the behavior.

Here's the latest Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:22:13 PM, on 6/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228702204676
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7474 bytes




Thanks!Quote from: WyattSoft on June 20, 2009, 03:26:45 PM

Try doing a Kaspersky Online Scan:
http://www.kaspersky.co.uk/virusscanner

I will take a while to complete though.

I ran the scan and it found one: not-a-virus:AdWare.Win32.Aureate.c in a .zip file from 2005. I don't think that's causing the problem because it just started happening a couple of days ago.

Anyone got any more suggestions?

Thanks!
1640.

Solve : [Complete] Free License for SUPERAntiSpyware Professional Edition?

Answer»

Quote from: 2x3i5x on JUNE 01, 2009, 01:08:06 PM

and you were the first to inquire when he's doing the raffle. LOL

LOL, I noticed that also. Trust me, I made sure it was completely RANDOM. I do solemnly swear that I faithfully had NOTHING to do with the decision and had no influence what-so-ever on the decision made by evilfantasy or any third parties. I mixed the order of the names that I had LISTED and then randomized them. I wanted to be sure that the first name on the list of diggers wasn't the first name on the random.com list. I figure that's about the best I could do...

This is how they went in.

naters0913
KingDoomed
StarLiteMedia
justinlutzfl
DeathStalker2
shaly777
JHenderson81
computeruler
2×3i5x
Karnac1
DeathStalker2
Fordy101 *Unsticking topic

I've already heard from the SAS guys and I should be doing this again in a few weeks.

Thanks again everyone!ooooo! I hope I win next time! Can you pm me if I dont reply and dont see the post or anything?I'll probably split a post from this topic so when I reply everyone will get an email.I dont get emails when there are new posts or anything. I use the new reply things but ok.
1641.

Solve : help can't remove trojan horse agent2.fmq virus and its killing me?

Answer»

You can use CCleaner to remove Cookies. They aren't dangerous so no need to worry over them.

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the SCAN to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and GET all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security ADDON for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and UNRELIABLE shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thank you so much for your help anyone reading this should take his advise, and stick with it. I had 187 trojan horse viruses that all came in one shot and he helped to removal all of them without causing me to lose any info or have a system crash.Your welcome.

Safe surfing...
1642.

Solve : Unwanted E-mail?

Answer»

I keep getting UNWANTED spam In my E-mail. I tried going to message and block sender In my outlook express but The e-mail changes Its name every time.

Any ideas on how to stop this, and or a GOOD free spamblocker?.You might find some here: http://www.snapfiles.com/Freeware/comm/fwoutlook.html
Or here: http://www.snapfiles.com/Freeware/comm/fwspam.htmlSPAMfighter - Free trial but still has full functions after the trial is over. Works GREAT!

MailWasher also has good reviews.Thanks again MR Evil.

1643.

Solve : Computer Acting weird (logs attached)?

Answer»

My computer has been acting really slow lately. It has really been acting up lately. ALSO, my internet has been acting SLOWER than usual. Please HELP!


Thank you!

naters0913

[ATTACHMENT DELETED by admin]

1644.

Solve : Malware Help Needed (AVG won't update / websites redirecting)?

Answer»

Trying to fix a family member's computer, DEFINITELY have some sort of virus. First noticed that certain websites were randomly redirecting to odd pages, and AVG would not be allowed access to the update server. Tried to install some anti-malware programs (SuperAntiSpyware, Malwarebytes, etc) but have not yet been able to eliminate the problem. Was hoping that I could get some help.

AVG found the following 3 viruses:
Adware GENERIC VDM
Trojan Horse dropper.delf.CAQ
Adware Generic.CEJ

I have also attached a HijackThis log; MBAM log (having quarantined and REMOVED the found objects). I am restarting my computer right now following the MBAM removal; PLEASE let me know what else I should try.

Thank you so much in advance for any help you might be able to provide.

[attachment DELETED by admin]

1645.

Solve : Tommypauly-Malware Removal-(Logs)?

Answer»

I followed the steps in the "Read here before..." thread and here are my logs:

=========================================================
HijackThis
=========================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:03:36 PM, on 5/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\USBToolbox\Res.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\IPOD\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ResModify] C:\Program Files\USBToolbox\Res.EXE
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cool People\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple INC. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 8280 bytes


============================================================
Malware Bytes log
============================================================
Malwarebytes' Anti-Malware 1.35
Database version: 1935
Windows 5.1.2600 Service Pack 3

4/2/2009 10:46:44 PM
mbam-log-2009-04-02 (22-46-44).txt

Scan TYPE: Full Scan (C:\|F:\|)
Objects scanned: 234094
Time elapsed: 1 hour(s), 21 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c559105-9ecf-42b8-b3f7-832e75edd959} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Sysvxd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

============================================================
SuperAntiSpyware Log
============================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/02/2009 at 03:54 PM

Application Version : 4.26.1000

Core Rules Database Version : 3825
Trace Rules Database Version: 1781

Scan type : Complete Scan
Total Scan Time : 00:52:59

Memory items scanned : 661
Memory threats detected : 0
Registry items scanned : 6989
Registry threats detected : 36
File items scanned : 32051
File threats detected : 1

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{ABC42510-9B22-41c1-9DCD-8182A2D07C63}
HKCR\CLSID\{ABC42510-9B22-41C1-9DCD-8182A2D07C63}
HKCR\CLSID\{ABC42510-9B22-41C1-9DCD-8182A2D07C63}
HKCR\CLSID\{ABC42510-9B22-41C1-9DCD-8182A2D07C63}\InProcServer32
HKCR\CLSID\{ABC42510-9B22-41C1-9DCD-8182A2D07C63}\InProcServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\IEHELPER.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABC42510-9B22-41c1-9DCD-8182A2D07C63}
HKU\S-1-5-21-1215824069-2983954535-449525478-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ABC42510-9B22-41C1-9DCD-8182A2D07C63}

Trojan.NewDotNet
HKU\S-1-5-21-1215824069-2983954535-449525478-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}

Adware.WhenU
HKU\S-1-5-21-1215824069-2983954535-449525478-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA2325ED-F9EB-4830-8FCE-0BC35B16969B}

Adware.Zango Toolbar/Hb
HKLM\Software\ZangoToolbar
HKLM\Software\ZangoToolbar\Install
HKLM\Software\ZangoToolbar\Install#OL
HKLM\Software\ZangoToolbar\Install#WP
HKCR\InstIE.HbInstObj
HKCR\InstIE.HbInstObj\CLSID
HKCR\InstIE.HbInstObj\CurVer
HKCR\InstIE.HbInstObj.1
HKCR\InstIE.HbInstObj.1\CLSID
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32#ThreadingModel
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\ProgID
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\Programmable
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\TypeLib
HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\VersionIndependentProgID
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\0
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\0\win32
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\FLAGS
HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\HELPDIR
HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}
HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid
HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid32
HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib
HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib#Version


I look forward to hearing from you, but take your time. I can run computer still, it is just slow
Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

.
Important: Close all windows except for HijackThis and then click Fix CHECKED.

Exit HijackThis.

----------

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information: .
It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
  • Viewpoint Experience Technology
.
----------

Malwarebytes and SUPERAntispyware are way out of date on the version numbers.

Open Malwarebytes' Anti-Malware.
  • Click the Update tab.
  • Click Check for Updates
  • If an update is found, it will download and install.
  • Click the Scanner tab.
  • Select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply along with a fresh HijackThis log.
.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

----------

You are way out of date with your version of SUPERAntiSpyware.

* Please uninstall your current version. <- This is important!
* Download and install SUPERAntiSpyware Free for Home Users
* After installing the new version, it may tell you that you need to reboot to complete the installation. You must reboot at this time!
* After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get any available updates.
* Now run a new full scan of your system.
* Post the log in your next reply.
1646.

Solve : malware smartbizsearch-com help- DNS change, pop up, spybot & mbam doesnt work?

Answer»

Hello. im really tired trying to clean this redirect. I really need help.


Logfile of random's system information tool 1.06 (written by random/random)
Run by Familia at 2009-05-31 05:36:04
Microsoft® Windows Vista™ Home Premium
System drive C: has 151 GB (32%) free of 477 GB
Total RAM: 2046 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5.36.18, on 31/05/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\mobsync.exe
C:\Users\Familia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GEE5IBP0\RSIT[1].exe
C:\Program Files\trend micro\Familia.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~3\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {389956FE-3A45-469C-B944-70308E06BAAC} (CVServerObject Object) - http://telebingomessina.no-ip.org/videocom.cab
O16 - DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} (Remote200 Control) - http://telebingo.no-ip.org/RemoteWeb.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldes-us.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1240257580096&h=88ef6d73759c3c78146248b2da232b95/&filename=jinstall-6u13-windows-i586-jc.cab
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} (F-Secure Online Scanner 4.0 Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.98,85.255.112.137
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.98,85.255.112.137
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.98,85.255.112.137
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll

--
End of file - 5711 bytes

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{1A0F8AAF-C754-49F8-857F-096C00F7C877}.job
C:\Windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-28 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Guida per l'accesso a Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-20 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=C:\Windows\system32\msconfig.exe [2006-11-02 222208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~3\AVG\AVG8\avgtray.exe [2009-05-28 1947928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2006-11-02 125440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
C:\Program Files\Microsoft LifeCam\LifeExp.exe [2008-08-04 160800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2007-09-19 4702208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-20 148888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
C:\Windows\vVX1000.exe [2008-08-04 721936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2009-04-16 1006264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsServicesStartup]
C:\Users\Familia\AppData\Local\Temp\svchost.exe 1 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-05-31 05:36:04 ----D---- C:\rsit
2009-05-30 19:23:22 ----D---- C:\Program Files\ESET
2009-05-30 19:17:06 ----A---- C:\lopR.txt
2009-05-30 19:16:34 ----D---- C:\Lop SD
2009-05-30 19:08:15 ----D---- C:\Program Files\Trend Micro
2009-05-29 11:21:24 ----D---- C:\ProgramData\Malwarebytes
2009-05-29 11:21:23 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-28 12:06:26 ----HD---- C:\$AVG8.VAULT$
2009-05-28 12:04:06 ----A---- C:\Windows\system32\avgrsstx.dll
2009-05-28 12:04:01 ----D---- C:\ProgramData\avg8
2009-05-28 12:04:01 ----D---- C:\Program Files\AVG
2009-05-28 11:34:38 ----A---- C:\Windows\ntbtlog.txt
2009-05-28 11:11:15 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-05-28 11:11:15 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-05-27 11:40:33 ----D---- C:\Windows\Sun
2009-05-26 08:35:26 ----D---- C:\Windows\pss
2009-05-23 15:08:56 ----A---- C:\Windows\system32\picn20.dll
2009-05-23 15:08:55 ----D---- C:\Program Files\Common Files\Ahead
2009-05-23 15:08:55 ----A---- C:\Windows\system32\NeroCheck.exe
2009-05-23 15:08:55 ----A---- C:\Windows\system32\ImagXpr5.dll
2009-05-23 15:08:55 ----A---- C:\Windows\system32\imagx5.dll
2009-05-23 15:08:55 ----A---- C:\Windows\system32\imagr5.dll
2009-05-23 15:08:51 ----D---- C:\Program Files\Ahead
2009-05-21 12:28:59 ----A---- C:\Windows\system32\msvcp71.dll
2009-05-21 12:24:03 ----D---- C:\Program Files\TVersity
2009-05-11 16:27:53 ----A---- C:\Windows\system32\mshtmler.dll
2009-05-11 16:27:53 ----A---- C:\Windows\system32\mshtmled.dll
2009-05-11 16:27:53 ----A---- C:\Windows\system32\jsproxy.dll
2009-05-11 16:27:53 ----A---- C:\Windows\system32\ieui.dll
2009-05-11 16:27:53 ----A---- C:\Windows\system32\icardie.dll
2009-05-11 16:27:53 ----A---- C:\Windows\system32\admparse.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\occache.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\msls31.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\licmgr10.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\inseng.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\imgutil.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\iernonce.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\iepeers.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\ieaksie.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\ieakeng.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\dxtrans.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\dxtmsft.dll
2009-05-11 16:27:52 ----A---- C:\Windows\system32\corpol.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-05-11 16:27:51 ----A---- C:\Windows\system32\wextract.exe
2009-05-11 16:27:51 ----A---- C:\Windows\system32\webcheck.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\pngfilt.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\mstime.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\msrating.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\msfeedssync.exe
2009-05-11 16:27:51 ----A---- C:\Windows\system32\msfeeds.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\iesetup.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\ieakui.dll
2009-05-11 16:27:51 ----A---- C:\Windows\system32\advpack.dll
2009-05-11 16:27:50 ----A---- C:\Windows\system32\vbscript.dll
2009-05-11 16:27:50 ----A---- C:\Windows\system32\url.dll
2009-05-11 16:27:50 ----A---- C:\Windows\system32\jscript.dll
2009-05-11 16:27:50 ----A---- C:\Windows\system32\iedkcs32.dll
2009-05-11 16:27:50 ----A---- C:\Windows\system32\ieapfltr.dll
2009-05-11 16:27:49 ----A---- C:\Windows\system32\wininet.dll
2009-05-11 16:27:49 ----A---- C:\Windows\system32\urlmon.dll
2009-05-11 16:27:49 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\PDMSetup.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\mshta.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\iexpress.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\ieUnatt.exe
2009-05-11 16:27:49 ----A---- C:\Windows\system32\iesysprep.dll
2009-05-11 16:27:49 ----A---- C:\Windows\system32\iertutil.dll
2009-05-11 16:27:49 ----A---- C:\Windows\system32\ie4uinit.exe
2009-05-11 16:27:48 ----A---- C:\Windows\system32\mshtml.dll
2009-05-11 16:27:48 ----A---- C:\Windows\system32\ieframe.dll
2009-05-11 04:03:25 ----A---- C:\Windows\vbaddin.ini
2009-05-11 02:59:22 ----D---- C:\Users\Familia\AppData\Roaming\Autodesk
2009-05-11 02:59:22 ----D---- C:\ProgramData\Autodesk
2009-05-11 02:58:14 ----D---- C:\Program Files\Common Files\Autodesk Shared
2009-05-11 02:58:14 ----D---- C:\Program Files\Autodesk
2009-05-11 02:57:59 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-05-02 10:48:29 ----D---- C:\Users\Familia\AppData\Roaming\Canon
2009-05-02 10:48:23 ----D---- C:\Program Files\Canon
2009-05-02 10:39:56 ----HD---- C:\ProgramData\CanonBJ
2009-05-02 10:39:34 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2009-05-02 10:38:39 ----HD---- C:\Program Files\CanonBJ
2009-05-02 10:24:21 ----D---- C:\Users\Familia\AppData\Roaming\TomTom
2009-05-02 10:24:21 ----D---- C:\Users\Familia\AppData\Roaming\Mozilla
2009-05-01 17:53:19 ----D---- C:\ProgramData\MSScanAppDataDir

======List of files/folders modified in the last 1 months======

2009-05-31 05:36:16 ----D---- C:\Windows\Prefetch
2009-05-31 05:36:08 ----D---- C:\Windows\Temp
2009-05-31 05:31:45 ----D---- C:\Windows\System32
2009-05-31 05:31:45 ----D---- C:\Windows\inf
2009-05-31 05:31:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-05-31 05:29:32 ----D---- C:\Windows\system32\drivers
2009-05-31 05:29:07 ----RD---- C:\Program Files
2009-05-31 05:27:22 ----D---- C:\Windows\Minidump
2009-05-31 05:27:15 ----D---- C:\Windows
2009-05-31 05:15:03 ----D---- C:\Windows\winsxs
2009-05-31 05:15:03 ----D---- C:\Program Files\Internet Explorer
2009-05-31 05:15:00 ----SHD---- C:\Windows\Installer
2009-05-31 05:14:58 ----D---- C:\Program Files\Common Files\microsoft shared
2009-05-31 05:14:13 ----D---- C:\Windows\system32\catroot
2009-05-30 19:42:23 ----RAD---- C:\Incoming
2009-05-30 19:41:40 ----SHD---- C:\System Volume Information
2009-05-30 19:23:23 ----SD---- C:\Windows\Downloaded Program Files
2009-05-30 19:08:21 ----D---- C:\Windows\system32\Tasks
2009-05-29 11:21:24 ----HD---- C:\ProgramData
2009-05-29 10:50:44 ----D---- C:\Windows\system32\catroot2
2009-05-28 23:53:20 ----SHD---- C:\RECYCLER
2009-05-28 12:41:07 ----D---- C:\Windows\Tasks
2009-05-28 12:38:19 ----SD---- C:\Users\Familia\AppData\Roaming\Microsoft
2009-05-26 22:46:50 ----D---- C:\Windows\LiveKernelReports
2009-05-26 08:33:09 ----RSD---- C:\Windows\assembly
2009-05-26 08:33:06 ----D---- C:\Windows\Help
2009-05-26 08:33:04 ----RSD---- C:\Windows\Fonts
2009-05-25 11:19:23 ----D---- C:\Windows\system32\WDI
2009-05-23 15:08:55 ----D---- C:\Program Files\Common Files
2009-05-21 01:22:09 ----D---- C:\Program Files\Windows Mail
2009-05-17 20:52:57 ----D---- C:\Windows\WindowsMobile
2009-05-17 10:48:00 ----D---- C:\Windows\system32\LogFiles
2009-05-17 10:47:03 ----D---- C:\Program Files\Microsoft
2009-05-16 19:29:57 ----SHD---- C:\$Recycle.Bin
2009-05-12 01:54:52 ----D---- C:\Windows\system32\migration
2009-05-12 01:54:52 ----D---- C:\Windows\system32\it-IT
2009-05-12 01:54:52 ----D---- C:\Windows\system32\en-US
2009-05-12 01:54:52 ----D---- C:\Windows\PolicyDefinitions
2009-05-11 04:03:35 ----A---- C:\Windows\ODBC.INI
2009-05-11 04:03:06 ----SD---- C:\ProgramData\Microsoft
2009-05-11 04:03:06 ----D---- C:\Program Files\Microsoft Office
2009-05-11 03:01:51 ----D---- C:\Windows\Microsoft.NET
2009-05-11 02:57:42 ----D---- C:\Program Files\Common Files\DESIGNER
2009-05-10 14:27:18 ----D---- C:\Windows\servicing
2009-05-07 09:16:29 ----A---- C:\Windows\system32\mrt.exe
2009-05-06 09:50:47 ----RD---- C:\Users
2009-05-01 01:24:07 ----D---- C:\Windows\system32\config

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-05-28 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-05-28 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-05-28 108552]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-02-26 4385792]
R3 HdAudAddService;Driver di funzioni Microsoft 1.1 UAA per servizio High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HdAudAddService;Driver di funzioni Microsoft 1.1 UAA per servizio High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-09-19 1959832]
R3 MSPQM;Proxy di gestione qualità di flusso Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
R3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
R3 RTL8169;Driver Realtek 8169 per NT; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 usbaudio;Driver audio USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 VX1000;VX-1000; C:\Windows\system32\DRIVERS\VX1000.sys [2008-08-04 1964432]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 drmkaud;Decodificatore audio DRM del KERNEL Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-03-26 16608]
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys []
S3 MSKSSRV;Proxy di servizio di flusso Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Proxy clock di flusso Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSTEE;Convertitore a T/Sito a sito per flusso Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 UMPass;Driver Microsoft UMPass; C:\Windows\system32\DRIVERS\umpass.sys [2006-11-02 7168]
S3 usb_rndisx;Scheda RNDIS USB; C:\Windows\system32\DRIVERS\usb8023x.sys [2006-11-02 14848]
S3 usbscan;Driver scanner USB; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 winusb;Driver WinUsb; C:\Windows\system32\DRIVERS\winusb.sys [2006-11-02 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2008-08-04 164896]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2006-11-02 22016]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2009-02-25 733184]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~3\AVG\AVG8\avgwdsvc.exe [2009-05-28 298776]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]

-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-05-31 05:36:20

======Uninstall list======

-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}
Adobe Reader 9.1 - Italiano-->MsiExec.exe /I{AC76BA86-7AD7-1040-7B44-A91000000001}
AdunanzA-->"C:\Program Files\eMule AdunanzA\Disinstallazione eMule AdunanzA.exe"
Assistente per l'accesso a Windows Live-->MsiExec.exe /I{DC7B9AB3-2635-45AA-957D-90FDE7CD51D7}
Autodesk DWF Viewer 7-->MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Canon MP Navigator 3.0-->"C:\Program Files\Canon\MP Navigator 3.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 3.0\uninst.ini
Canon MP160-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160 /L0x0010
Centro gestione dispositivi Windows Mobile-->MsiExec.exe /X{904CCF62-818D-4675-BC76-D37EB399F917}
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
ESET Online Scanner v3-->C:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
ffdshow [rev 1723] [2007-12-24]-->"C:\Program Files\K-Lite Codec Pack\ffdshow\unins000.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
K-Lite Codec Pack 4.7.0 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 3.5 - Language Pack SP1 (italiano)-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - ita\setup.exe
Microsoft .NET Framework 3.5 Language Pack SP1 - ita-->MsiExec.exe /I{55CA4086-0D2C-30E3-A7B5-C76BA737CECE}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Corporation-->MsiExec.exe /I{7B08D306-7266-4647-A926-2F78817ED1E0}
Microsoft LifeCam-->MsiExec.exe /X{6BCB7EAA-598C-4836-B7EA-3642E41AA222}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-0410-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110410-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio Professional 2003-->MsiExec.exe /I{90510410-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nokia Flashing Cable Driver-->MsiExec.exe /X{A4E0CA0F-1903-440A-9B98-FEA6CB049999}
Nokia Internet Tablet Software Update Wizard-->RunDll32 C:\PROGRA~3\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D198D2E7-B557-4404-A286-77F249625172}\setup.exe" -l0x10 -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~3\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x10 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins003.exe"
Strumento di caricamento di Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Call-->MsiExec.exe /I{49C77D21-F91F-4296-B7DF-19C5FF51AF4D}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E171E280-0BAE-4460-9F47-CA96D17828B6}
Windows Live Messenger-->MsiExec.exe /X{5AE2BE5E-930A-481C-817E-C373E8910C8A}
WinRAR gestione archivi-->C:\Program Files\WinRAR\uninstall.exe

======Security center information======

AV: AVG Anti-Virus Free
AS: AVG Anti-Virus Free (disabled)
AS: Windows Defender

======System event log======

Computer Name: PC-Familia
Event Code: 7036
Message: Il servizio Informazioni applicazioni è ora in modalità esecuzione.
Record Number: 100965
Source Name: Service Control Manager
Time Written: 20090531033507.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Familia
Event Code: 7036
Message: Il servizio Servizio trasferimento intelligente in background è ora in modalità esecuzione.
Record Number: 100966
Source Name: Service Control Manager
Time Written: 20090531033526.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Familia
Event Code: 7036
Message: Il servizio KtmRm per Distributed Transaction Coordinator è ora in modalità esecuzione.
Record Number: 100967
Source Name: Service Control Manager
Time Written: 20090531033527.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Familia
Event Code: 7036
Message: Il servizio Centro sicurezza PC è ora in modalità esecuzione.
Record Number: 100968
Source Name: Service Control Manager
Time Written: 20090531033527.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Familia
Event Code: 7036
Message: Il servizio Windows Update è ora in modalità esecuzione.
Record Number: 100969
Source Name: Service Control Manager
Time Written: 20090531033528.000000-000
Event Type: Informazioni
User:

=====Application event log=====

Computer Name: PC-Familia
Event Code: 1
Message: Client Servizi certificati avviato.
Record Number: 3443
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20090531033327.533209-000
Event Type: Informazioni
User: PC-Familia\Familia

Computer Name: PC-Familia
Event Code: 1
Message: Client Servizi certificati avviato.
Record Number: 3444
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20090531033329.051409-000
Event Type: Informazioni
User: NT AUTHORITY\SYSTEM

Computer Name: PC-Familia
Event Code: 1001
Message: Bucket errato 0x8E_nt!MiMapViewOfImageSection+815, tipo 0
Nome evento: BlueScreen
Risposta: Nessuno
ID CAB: 0

Firma problema:
P1:
P2:
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

File allegati:
C:\Users\Familia\AppData\Local\Microsoft\Windows\WER\ReportQueue\Report0479028f\Mini053109-02.dmp
C:\Users\Familia\AppData\Local\Microsoft\Windows\WER\ReportQueue\Report0479028f\WER-43711-0.sysdata.xml
C:\Users\Familia\AppData\Local\Microsoft\Windows\WER\ReportQueue\Report0479028f\WERF565.tmp.version.txt

I file potrebbero essere disponibili qui:
C:\Users\Familia\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0fc0c725
Record Number: 3445
Source Name: Windows Error Reporting
Time Written: 20090531033337.000000-000
Event Type: Informazioni
User:

Computer Name: PC-Familia
Event Code: 1
Message:
Record Number: 3446
Source Name: MBAMService
Time Written: 20090531033512.000000-000
Event Type: Errore
User:

Computer Name: PC-Familia
Event Code: 1
Message: Servizio Centro sicurezza PC Windows avviato.
Record Number: 3447
Source Name: SecurityCenter
Time Written: 20090531033527.000000-000
Event Type: Informazioni
User:

=====Security event log=====

Computer Name: PC-Familia
Event Code: 4672
Message: Privilegi speciali assegnati a nuovo accesso.

Soggetto:
ID protezione:S-1-5-18
Nome ACCOUNT:SYSTEM
Dominio account:NT AUTHORITY
ID accesso:0x3e7

Privilegi:SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26299
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090531033316.795394-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Familia
Event Code: 4648
Message: È stato tentato un accesso utilizzando credenziali esplicite.

Soggetto:
ID protezione:S-1-5-18
Nome account:PC-FAMILIA$
Dominio account:WORKGROUP
ID accesso:0x3e7
GUID accesso:{00000000-0000-0000-0000-000000000000}

Account di cui sono state utilizzate le credenziali:
Nome account:SYSTEM
Dominio account:NT AUTHORITY
GUID accesso:{00000000-0000-0000-0000-000000000000}

Server di destinazione:
Nome server di destinazione:localhost
Informazioni aggiuntive:localhost

Informazioni sul processo:
ID processo:0x288
Nome processo:C:\Windows\System32\services.exe

Informazioni di rete:
Indirizzo di rete:-
Porta:-

Questo evento viene generato quando un processo tenta di far accedere un account specificando esplicitamente le credenziali dell'account. Generalmente si verifica in configurazioni di tipo batch, ad esempio attività pianificate, oppure quando si utilizza il comando RUNAS.
Record Number: 26300
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090531033316.920195-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Familia
Event Code: 4624
Message: Accesso di un account riuscito.

Soggetto:
ID protezione:S-1-5-18
Nome account:PC-FAMILIA$
Dominio account:WORKGROUP
ID accesso:0x3e7

Tipo di accesso:5

Nuovo accesso:
ID protezione:S-1-5-18
Nome account:SYSTEM
Dominio account:NT AUTHORITY
ID accesso:0x3e7
GUID accesso:{00000000-0000-0000-0000-000000000000}

Informazioni sul processo:
ID processo:0x288
Nome processo:C:\Windows\System32\services.exe

Informazioni di rete:
Nome workstation:
Indirizzo rete di ORIGINE:-
Porta di origine:-

Informazioni di autenticazione dettagliate:
Processo di accesso:Advapi
Pacchetto di autenticazione:Negotiate
Servizi transitati:-
Nome pacchetto (solo NTLM):-
Lunghezza chiave:0

Questo evento viene generato quando viene creata una sessione di accesso. Viene generato nel computer in cui è stato effettuato l'accesso.

Il campo Soggetto indica l'account nel sistema locale che ha richiesto l'accesso. Generalmente si tratta di un servizio, quale il servizio Server, o di un processo locale, ad esempio Winlogon.exe o Services.exe.

Il campo Tipo di accesso indica il tipo di accesso che è stato effettuato. I tipi più comuni sono 2 (interattivo) e 3 (rete).

Il campo Nuovo accesso indica l'account per il quale è stato creato il nuovo accesso, vale a dire l'account che ha effettuato l'accesso.

Il campo Informazioni di rete indica l'origine della richiesta di accesso remota. Il nome della workstation non è sempre disponibile e può essere vuoto in alcuni casi.

Il campo Informazioni di autenticazione fornisce informazioni dettagliate sulla specifica richiesta di accesso.
- GUID accesso è un identificatore univoco che può essere utilizzato per correlare questo evento a un evento KDC.
- Servizi transitati indica quali servizi intermedi hanno partecipato alla richiesta di accesso.
- Nome pacchetto indica quale sottoprotocollo dei protocolli NTLM è stato utilizzato.
- Lunghezza chiave indica la lunghezza della chiave di sessione generata. Se non è stata richiesta alcuna chiave di sessione, la lunghezza sarà pari a zero.
Record Number: 26301
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090531033316.920195-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Familia
Event Code: 4672
Message: Privilegi speciali assegnati a nuovo accesso.

Soggetto:
ID protezione:S-1-5-18
Nome account:SYSTEM
Dominio account:NT AUTHORITY
ID accesso:0x3e7

Privilegi:SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26302
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090531033316.920195-000
Event Type: Controllo riuscito
User:

Computer Name: PC-Familia
Event Code: 5024
Message: Il servizio Windows Firewall è stato avviato correttamente.
Record Number: 26303
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090531033319.435209-000
Event Type: Controllo riuscito
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\CMD.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=2

-----------------EOF-----------------

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Home Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz )
BIOS : Award Modular BIOS v6.00PG
USER : Familia ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.5 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:465 Go (Free:144 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 31/05/2009| 5.07 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in Local

[26/04/2009|16.23] C:\Users\Familia\AppData\Local\Adobe
[11/05/2009|02.59] C:\Users\Familia\AppData\Local\Autodesk
[26/03/2009|03.31] C:\Users\Familia\AppData\Local\Cronologia
[30/05/2009|18.36] C:\Users\Familia\AppData\Local\d3d9caps.dat
[26/03/2009|03.31] C:\Users\Familia\AppData\Local\Dati applicazioni
[30/05/2009|20.06] C:\Users\Familia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[26/05/2009|08.37] C:\Users\Familia\AppData\Local\GDIPFONTCACHEV1.DAT
[11/05/2009|04.03] C:\Users\Familia\AppData\Local\Microsoft
[10/04/2009|16.48] C:\Users\Familia\AppData\Local\Microsoft Games
[31/05/2009|05.07] C:\Users\Familia\AppData\Local\Temp
[26/03/2009|03.31] C:\Users\Familia\AppData\Local\Temporary Internet Files
[02/05/2009|10.24] C:\Users\Familia\AppData\Local\TomTom
[29/05/2009|14.23] C:\Users\Familia\AppData\Local\VirtualStore
[3|File] C:\Users\Familia\AppData\Local\byte
[12|Directory] C:\Users\Familia\AppData\Local\byte disponibili

--------------------\\ Scheduled Tasks located in C:\Windows\Tasks

[31/05/2009 05.00][--ah-----] C:\Windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
[31/05/2009 04.55][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{1A0F8AAF-C754-49F8-857F-096C00F7C877}.job
[30/05/2009 19.09][--ah-----] C:\Windows\tasks\SA.DAT
[30/05/2009 17.50][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing Folders in C:\ProgramData

[21/04/2009|17.32] C:\ProgramData\Adobe
[02/11/2006|15.02] C:\ProgramData\Application Data
[26/05/2009|08.33] C:\ProgramData\Autodesk
[28/05/2009|16.17] C:\ProgramData\avg8
[02/05/2009|10.39] C:\ProgramData\CanonBJ
[26/03/2009|03.29] C:\ProgramData\Dati applicazioni
[02/11/2006|15.02] C:\ProgramData\Desktop
[26/03/2009|03.29] C:\ProgramData\Documenti
[02/11/2006|15.02] C:\ProgramData\Documents
[05/04/2009|04.33] C:\ProgramData\eMule AdunanzA
[02/11/2006|15.02] C:\ProgramData\Favorites
[29/05/2009|11.21] C:\ProgramData\Malwarebytes
[26/03/2009|03.29] C:\ProgramData\Menu Avvio
[11/04/2009|13.19] C:\ProgramData\Messenger Plus!
[11/05/2009|04.03] C:\ProgramData\Microsoft
[26/03/2009|03.29] C:\ProgramData\Modelli
[01/05/2009|17.53] C:\ProgramData\MSScanAppDataDir
[26/03/2009|03.29] C:\ProgramData\Preferiti
[28/05/2009|11.38] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15.02] C:\ProgramData\Start Menu
[02/11/2006|15.02] C:\ProgramData\Templates
[0|File] C:\ProgramData\byte
[23|Directory] C:\ProgramData\byte disponibili

--------------------\\ Listing Folders in C:\Program Files

[21/04/2009|17.32] C:\Program Files\Adobe
[23/05/2009|15.08] C:\Program Files\Ahead
[26/03/2009|04.40] C:\Program Files\ATI
[26/03/2009|04.40] C:\Program Files\ATI Technologies
[11/05/2009|02.58] C:\Program Files\Autodesk
[28/05/2009|12.04] C:\Program Files\AVG
[02/05/2009|10.48] C:\Program Files\Canon
[02/05/2009|10.38] C:\Program Files\CanonBJ
[23/05/2009|15.08] C:\Program Files\Common Files
[05/04/2009|04.33] C:\Program Files\eMule AdunanzA
[30/05/2009|19.23] C:\Program Files\ESET
[26/03/2009|03.29] C:\Program Files\File comuni [C:\Program Files\Common Files]
[26/04/2009|02.20] C:\Program Files\InstallShield Installation Information
[26/03/2009|04.14] C:\Program Files\Intel
[12/05/2009|01.54] C:\Program Files\Internet Explorer
[20/04/2009|21.58] C:\Program Files\Java
[26/03/2009|17.34] C:\Program Files\K-Lite Codec Pack
[11/05/2009|04.00] C:\Program Files\MagicDisc
[29/05/2009|11.21] C:\Program Files\Malwarebytes' Anti-Malware
[10/04/2009|21.54] C:\Program Files\Messenger Plus! Live
[17/05/2009|10.47] C:\Program Files\Microsoft
[02/11/2006|14.37] C:\Program Files\Microsoft Games
[10/04/2009|21.48] C:\Program Files\Microsoft LifeCam
[11/05/2009|04.03] C:\Program Files\Microsoft Office
[26/03/2009|04.56] C:\Program Files\Microsoft Office Outlook Connector
[10/04/2009|22.34] C:\Program Files\Microsoft Silverlight
[26/03/2009|03.35] C:\Program Files\Microsoft.NET
[02/11/2006|14.42] C:\Program Files\Movie Maker
[02/11/2006|14.37] C:\Program Files\MSBuild
[24/04/2009|14.11] C:\Program Files\MSECache
[02/11/2006|14.37] C:\Program Files\MSN
[26/04/2009|02.21] C:\Program Files\Nokia
[26/03/2009|03.54] C:\Program Files\obj
[26/03/2009|04.13] C:\Program Files\Realtek
[02/11/2006|14.37] C:\Program Files\Reference Assemblies
[28/05/2009|11.36] C:\Program Files\Spybot - Search & Destroy
[27/03/2009|23.23] C:\Program Files\TomTom DesktopSuite
[30/05/2009|19.08] C:\Program Files\Trend Micro
[21/05/2009|12.24] C:\Program Files\TVersity
[02/11/2006|15.01] C:\Program Files\Uninstall Information
[16/04/2009|08.44] C:\Program Files\Windows Calendar
[02/11/2006|14.42] C:\Program Files\Windows Collaboration
[16/04/2009|08.44] C:\Program Files\Windows Defender
[02/11/2006|14.42] C:\Program Files\Windows Journal
[26/03/2009|04.55] C:\Program Files\Windows Live
[26/03/2009|04.54] C:\Program Files\Windows Live SkyDrive
[21/05/2009|01.22] C:\Program Files\Windows Mail
[12/04/2009|19.57] C:\Program Files\Windows Media Player
[26/03/2009|03.29] C:\Program Files\Windows NT
[02/11/2006|14.42] C:\Program Files\Windows Photo Gallery
[12/04/2009|19.57] C:\Program Files\Windows Sidebar
[27/03/2009|23.10] C:\Program Files\WinRAR
[0|File] C:\Program Files\byte
[54|Directory] C:\Program Files\byte disponibili

--------------------\\ Listing Folders in C:\Program Files\Common Files

[21/04/2009|17.32] C:\Program Files\Common Files\Adobe
[23/05/2009|15.08] C:\Program Files\Common Files\Ahead
[26/05/2009|08.33] C:\Program Files\Common Files\Autodesk Shared
[11/05/2009|02.57] C:\Program Files\Common Files\DESIGNER
[29/03/2009|18.25] C:\Program Files\Common Files\InstallShield
[17/05/2009|10.47] C:\Program Files\Common Files\microsoft shared
[02/11/2006|13.18] C:\Program Files\Common Files\Services
[02/11/2006|13.18] C:\Program Files\Common Files\SpeechEngines
[16/04/2009|08.44] C:\Program Files\Common Files\System
[26/03/2009|04.52] C:\Program Files\Common Files\Windows Live
[0|File] C:\Program Files\Common Files\byte
[12|Directory] C:\Program Files\Common Files\byte disponibili

--------------------\\ Process

( 49 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 05:07:58
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
disk error: C:\Windows\System32\
please note that you need administrator rights to perform deep scan

--------------------\\ Searching for other infections

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.98,85.255.112.137
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.98,85.255.112.137
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.98,85.255.112.137
==> WAREOUT <==

--------------------\\ Cracks & Keygens ..

C:\Users\Familia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GNASK89S\88x31_crack[1].jpg
C:\Users\Familia\AppData\Roaming\Microsoft\Windows\Recent\AutoCAD-2008-keygen.rar.lnk
C:\Users\Familia\AppData\Roaming\Microsoft\Windows\Recent\AutoCAD-2008-keygen.[wnet.co.il].rar.lnk
C:\Users\Familia\AppData\Roaming\Microsoft\Windows\Recent\rebuilt.AutoCAD.2008.Keygen.Only-XFORCE.rar.lnk
C:\Users\Familia\AppData\Roaming\Microsoft\Windows\Recent\SERIALI OFFICE 2003 CRACK.TXT.lnk
C:\Users\Familia\AppData\Roaming\Microsoft\Windows\Recent\[pocket pc wm5] TomTom Navigator 6 + mappe italia v6.6 + istruzioni + PDI + crack HOMER.lnk


[F:3398][D:108]-> C:\Users\Familia\AppData\Local\Temp
[F:127][D:1]-> C:\Users\Familia\AppData\Roaming\MICROS~1\Windows\Cookies
[F:1075][D:4]-> C:\Users\Familia\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:15][D:5]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 30/05/2009|19.17 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 30/05/2009|19.19 - Option : [2]
3 - "C:\Lop SD\LopR_3.txt" - 31/05/2009| 5.07 - Option : [1]
4 - "C:\Lop SD\LopR_4.txt" - 31/05/2009| 5.08 - Option : [2]

--------------------\\ Scan completed at 5.08.09
[ UAC => 1 ]

Any help? ESET on line scanner v3 DOESNT find any thread. AVG is disabled by thread. DNS is set now to automatic retrieve (was modified before by thread). Spybot y mbam doesn work.

Thank you

1647.

Solve : Trojans wont let me go to anti-malware web addresses!!?

Answer»

Hello y'all, newb here with first post.

Down to buisness;

WINDOWS XP Home SP3
Avira AntiVir personal scan file:



Avira AntiVir Personal
Report file date: Sunday, May 31, 2009 09:45

Scanning for 1441077 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: chaka
Computer name: HOME

Version information:
BUILD.DAT : 8.2.0.353 17048 Bytes 5/15/2009 12:02:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 11/18/2008 14:21:26
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 13:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 18:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 13:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 2/11/2009 20:44:00
ANTIVIR2.VDF : 7.1.4.38 2692096 Bytes 5/29/2009 20:46:43
ANTIVIR3.VDF : 7.1.4.40 11264 Bytes 5/30/2009 20:46:44
Engineversion : 8.2.0.180
AEVDF.DLL : 8.1.1.1 106868 Bytes 5/30/2009 20:48:46
AESCRIPT.DLL : 8.1.2.0 389497 Bytes 5/30/2009 20:48:42
AESCN.DLL : 8.1.2.3 127347 Bytes 5/30/2009 20:48:34
AERDL.DLL : 8.1.1.3 438645 Bytes 11/4/2008 19:58:38
AEPACK.DLL : 8.1.3.18 401783 Bytes 5/30/2009 20:48:29
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 5/30/2009 20:48:13
AEHEUR.DLL : 8.1.0.129 1761655 Bytes 5/30/2009 20:48:08
AEHELP.DLL : 8.1.2.2 119158 Bytes 5/30/2009 20:47:13
AEGEN.DLL : 8.1.1.44 348532 Bytes 5/30/2009 20:47:10
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/14/2008 16:05:56
AECORE.DLL : 8.1.6.12 180599 Bytes 5/30/2009 20:46:58
AEBB.DLL : 8.1.0.3 53618 Bytes 10/14/2008 16:05:56
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 14:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 15:28:01
AVREP.DLL : 8.0.0.3 155688 Bytes 5/30/2009 20:46:48
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 17:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 14:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 18:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 23:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 18:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 18:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 19:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 19:34:37

Configuration settings for the scan:
Jobname..........................: Windows System Directory
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysdir.avp
Logging..........................: low
Primary ACTION...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
SEARCH for rootkits..............: on
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: Sunday, May 31, 2009 09:45

Starting search for hidden objects.
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-00000005.dll

  • Archive type: HIDDEN
[INFO] The file is not visible.
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-00000005.dll
[DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.JW back-door program
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys
  • Archive type: HIDDEN
[INFO] The file is not visible.
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys
[DETECTION] Is the TR/Rootkit.Gen Trojan
The repair notes were written to the file 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\AVSCAN-20090531-094623-9003C82F.avp'.
c:\windows\system32\tdsscfub.dll
[INFO] The file is not visible.
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was deleted!
c:\windows\system32\drivers\tdsspaxt.sys
[DETECTION]
[NOTE] The file was deleted!
c:\windows\system32\tdssfpmp.dll
[INFO] The file is not visible.
c:\windows\system32\tdssnrsr.dll
[INFO] The file is not visible.
[DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.adb back-door program
[INFO] No SpecVir entry was found!
c:\windows\system32\tdssoeqh.dll
[DETECTION]
[INFO] No SpecVir entry was found!
c:\windows\system32\tdssosvn.dat
[INFO] The file is not visible.
c:\windows\system32\tdssrhym.log
[INFO] The file is not visible.
c:\windows\system32\tdssriqp.dll
[INFO] The file is not visible.
[DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.acs back-door program
[INFO] No SpecVir entry was found!
c:\windows\system32\tdsstkdv.log
[INFO] The file is not visible.
c:\documents and settings\chaka\local settings\temp\tdss8d6f.tmp
[INFO] The file is not visible (shell).
[DETECTION] Is the TR/Patched.CL Trojan
[INFO] No SpecVir entry was found!


End of the scan: Sunday, May 31, 2009 09:46
Used time: 01:23 Minute(s)

The scan has been done completely.

0 Scanning directories
10 Files were scanned
6 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
2 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
4 Files not concerned
0 Archives were scanned
0 Warnings
2 Notes
51894 Objects were scanned with rootkit scan
15 Hidden objects were found

The issue I am having is ANY web browser I use (Firefox 3.0.10, IE 8, or Opera) will not let me connect to ANY anti malware sites.

I get a 'could not connect to.....' prompt.

I had AVG, but trojan would not let me update definitions.

I have MaxPC cd with Superantispyware and MALWAREBYTES, but cannot install, says files are corrupt (only these 2 of course!).

ALL Google inquires are redirected to malware sites or Apartmentfinder on all browsers.

I deleted and/or Quarantine through the anti virus but they come back upon reboot.

I suspect AV is compromisedjavascript:replaceText('%20>',%20document.forms.postmodify.message);

I am at wits end and out of options EXCEPT format, but do not have XP cd so this is my only hope!




[attachment deleted by admin]update

Was able to run hijack this

Logfile of HijackThis v1.97.7
Scan saved at 12:23:20 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
e:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\apps\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O11 - Options group: [INTERNATIONAL] International
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C9F18C6A-744A-4A9B-A644-74ADAA6E8121}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\..\{EF2FA76B-F1B8-49B8-B1D0-A18671B3A868}: NameServer = 208.67.222.222,208.67.220.220

Was able to download malwarebytes but freezes on install.

adaware and spybot will not let mu update.

1648.

Solve : Please review logs (recommended by forum members)?

Answer»

HERE is the thread where I was told to POST in the Malware section.
Please could you take a look at my logs.

Problem in brief: something is using a LOT of bandwith at certain times. The IP address where my network monitoring software told me the bandwith was "going" was google's homepage!

Anyway, here are all 3 logs and the original screenshot of the problem

[attachment DELETED by admin]

1649.

Solve : How about a game of nine-ball ??

Answer»

Nine Ball, a recent multi-layered Web browser ATTACK that, combined with Gumblar and Beladen, have already infected approximately 140,000 sites collectively.

Nine Ball targets LEGITIMATE websites to redirect users to malicious sites owned by the attacker and infects PCs through a number of EXPLOITS, including Adobe Reader and Quick Time, without the user's CONSENT or knowledge. Once infected, anything the victim types can be monitored and used to commit identity theft, such as credit card numbers, PASSWORDS and more.

this was sent to me - thought i'd pass it along to everyone.

1650.

Solve : I have no clue what im doing?

Answer»

Do this first.

Download DrWeb CureIt &AMP; save it to your desktop. Scan with DrWeb-CureIt as follows:

  • Double-click on drweb-cureit.exe and then click Start
  • An information notice will appear, click OK.
  • This starts a short scan that will scan the files currently running in memory.
  • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
  • If or when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Settings > Change Settings
  • Under the Scanning tab UNcheck HEURISTIC analysis and click OK
  • Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
  • Click Yes to all if it asks if you want to cure/move any FILE(s).
  • When the scan is done.
  • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit.
  • Important! REBOOT your computer because it could be possible that files in use will be moved/deleted during reboot.
* After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
* Copy and paste that log in the next replysorry this has taken so long..new hours at work!



11074468.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11094796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11095406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11096000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11096312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11097015.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11098234.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11098328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11098421.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11099890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11099953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100234.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100765.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100906.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11100953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101031.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101109.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101203.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101531.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101765.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11101875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102062.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102484.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102593.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102640.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102671.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102718.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102781.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11102968.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11103984.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11104156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11104281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11105031.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11106062.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11106328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11107390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11107531.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11125140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11126156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11132500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11132687.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11132921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133093.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133375.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133421.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133468.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133546.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133593.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133640.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133875.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11133937.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134109.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134156.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134437.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134656.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11134953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135078.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135187.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135546.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135609.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135687.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11135953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136250.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136359.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136578.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136703.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136890.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11136968.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137046.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137328.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137390.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137578.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137671.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137718.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137843.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11137953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138000.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138093.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138140.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138218.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138312.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138359.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138734.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138781.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138828.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138906.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11138953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139015.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139203.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139296.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139343.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139406.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139453.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139515.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139625.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139796.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139921.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11139984.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140046.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140125.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140187.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140265.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140375.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140500.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140562.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140656.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140750.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140812.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140859.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11140953.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11141171.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
11141281.FIL;C:\$VAULT$.AVG;Win32.Gael.3666;Cured.;
06990266.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.52774;Deleted.;
09420408.FIL;D:\$VAULT$.AVG;Adware.ClickSpring;;
15784188.FIL;D:\$VAULT$.AVG;Modification of BackDoor.Generic.1699;;
15784829.FIL;D:\$VAULT$.AVG;Modification of BackDoor.Generic.1699;;
29400078.FIL\data003;D:\$VAULT$.AVG\29400078.FIL;Adware.Sonetads.1;;
29400078.FIL;D:\$VAULT$.AVG;Archive contains infected objects;;
29400421.FIL;D:\$VAULT$.AVG;Trojan.DownLoad.1015;Deleted.;
29400593.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.56730;Deleted.;
76061671.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
76061906.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
76061968.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
76331203.FIL;D:\$VAULT$.AVG;Adware.Maxifiles;;
86893687.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86893906.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86893968.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86919571.FIL;D:\$VAULT$.AVG;Trojan.MulDrop.5530;Deleted.;
86920243.FIL;D:\$VAULT$.AVG;Win32.HLLW.Pytica;Deleted.;
86920368.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86920680.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86920774.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
86920821.FIL;D:\$VAULT$.AVG;Trojan.DownLoader.18142;Deleted.;
ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe;D:\Documents and Settings\Linda\Desktop\ComboFix.exe/data002;Program.PsExec.171;;
data002;D:\Documents and Settings\Linda\Desktop;Archive contains infected objects;;
ComboFix.exe;D:\Documents and Settings\Linda\Desktop;Container contains infected objects;;
SDFix.exe\SDFix\apps\Process.exe;D:\Documents and Settings\Linda\Desktop\SDFix.exe;Tool.Prockill;;
SDFix.exe;D:\Documents and Settings\Linda\Desktop;Archive contains infected objects;;
alisha keys superwoman.mp3;D:\Documents and Settings\Linda\My Documents\LimeWire\Saved;Trojan.WMALoader;Cured.;
system.dll.vir;D:\Qoobox\Quarantine\D\Program Files\COMMON~1\{10B7B~1;Trojan.DownLoader.18142;Deleted.;
system.dll.vir;D:\Qoobox\Quarantine\D\Program Files\COMMON~1\{10B7B~2;Trojan.DownLoader.18142;Deleted.;
Process.exe;D:\SDFix\apps;Tool.Prockill;;
A0000824.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Tool.Prockill;;
A0000928.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Tool.Prockill;;
A0001043.exe;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP14;Adware.Maxifiles;;
A0001145.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
A0001146.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
A0001160.EXE;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Program.PsExec.170;;
A0001161.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
A0001162.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
A0001163.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
A0001164.dll;D:\System Volume Information\_restore{8E9F19A5-B25A-4409-86BB-4F20D41DEE84}\RP17;Trojan.DownLoader.18142;Deleted.;
OK how is the computer running now?rediculously slowI don't think it's malware.

Try doing a disk cleanup and defrag to see what that does.dno what that is or how to do itDelete temporary files

Go to:
  • Start
  • Run
  • type: CLEANMGR.EXE
  • Press Enter.
When prompted select the C: drive and click OK.
Check the boxes for:
  • Temporary Internet Files
  • Downloaded Program Files
  • Recycle Bin
  • Temporary Files
.
Click OK or Enter

Restart the computer.

----------

You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

the choices i got were recycle bin, system restore: obsolete data stores and catalog files for the content indexer


do those?Here, this is automated.

Download ATF Cleaner by Atribune and save it to your Desktop.
Alternate Download link

Windows Vista users:ATF-Cleaner must be Run as an Administrator

Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:

  • Windows TEMP
  • Current User Temp
  • All Users Temp
  • Temporary Internet Files
  • Prefetch
  • Java Cache
  • Recycle bin
The rest are optional - if you want it to remove everything check Select All
Now click Empty Selected
When you get the Done Cleaning message, click OK

Firefox
users click Firefox on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved Passwords click No on the prompt.

Opera users click Opera on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved Passwords click No on the prompt

Note that your system will run slower for a reboot or two after having used this tool so don't panicMy wife's computer lost sound about 2 years ago. I worked with a Windows XP Escalation Engineer who took me under his wing so to speak. Her system is a Systemax with licensed software for their proprietary systems: no windows disc came with the system. If you go to controll panel > sounds > and it is grayed out and defaults to a modem that you may not have installed, the issue is a dropped Windows driver. To fix the problem get a "clean" windows disc. If you don't have one Microsoft will send you a replacement. The Utilities disc manufacuters send with their systems ~ will not work! In save mode insert the disc and check "Repair"; be sure and check your BIOS to see if it is set to auto start [yes]. The disc will reload all the drivers necessary. Be sure to down load new audio drivers [Audio 97 or disc prompt] to a folder on your desktop - it's easy to find there. While the repair is patching files, for each file that it requests a disc to be inserted to load a specific dynamic link library .dll file, make note and download those as well. After you are prompted - reboot, and download those files that the Windows disc asked for during repair. Once you have downloaded and installed the requested file updates, reboot and your problem will be solved. Just a note: systems with factory installed Windows are problematic and without a legit version of Windows XP, your problem is there to stay. My only problem now is keeping my wife's volume turned down....If I can be of further assistance let me know. That problem was persitant.