Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1651.

Solve : AVG 8.0?

Answer»

I downloaded the latest version of AVG at home, brought my LAPTOP to work, ran it and everything seemed fine. I can on occasion get a wireless connection at work so I tried to get on the internet and in my search bar no matter what I type in it says , http://search.yahoo.com/search?fr=ffds1&p=search.yahoo.com and I also noticed avg added a toolbar to my page and a yahoo toolbar?

I really don't need either SINCE the one with Mazilla works just fine for me. AVG sometimes will have an option to install yahoo! toolbar with install (usually already TICKED).

Just uninstall it from add/remove programs would be the easiest fix.Hmmm funny thing.

There is no yahoo or avg toolbar listed in add remove ?This is what you've done (should be similar to latest version although it's a version that's a little older)? See screenshots on link below. When I last tried with AVG, no yahoo toolbar was installed

http://coastalcomputerconnections.com/forum/viewtopic.php?f=5&t=6Good choice would be to dump AVG and download Avira AntiVir Personal.....free as well.


http://www.avira.com/en/download/index.html
or you can get free version of avast antivirus from http://avast.com/

and yes, it's also free like AVG or Avira AntiVir but just remember you'll have to fill out a form on their website to obtain a key so that the AVAST guys KNOW you are using their free edition.

(But in any case, pick the one you like and ONLY HAVE ONE on your PC).

I've personally never had problem with AVG, AVAST or AVIRA. Have tried all, they all do fine. Just I liked AVAST interface over AVG after a bit of playing around with the three major free antivirus softwares and it's here to stay Quote from: 2x3i5x on June 18, 2009, 10:57:50 PM

This is what you've done (should be similar to latest version although it's a version that's a little older)? See screenshots on link below. When I last tried with AVG, no yahoo toolbar was installed

http://coastalcomputerconnections.com/forum/viewtopic.php?f=5&t=6

Well heres what I wound up doing. I went into view , tool bars and unchecked yahoo and AVG.
I can see tomorrow I will be uninstalling and custom installing AVG again.

Thanks much,
MP.Sure, let us know how it goes

Yes, hiding the toolbar is a temporary fix for having the toolbars not show up, but it wont' get rid of it off your machine so we'll see how you do tomorrow.Removed 1st install of 8.5 reinstalled and no toolbar.

Thanks much,
MP.Glad that everything worked out for you Thank you for the time and effort.
1652.

Solve : XEROX - NWWIA?

Answer»

Hai, i am gopinath - please solve my problem in the given below.

System Configuration

Windows xp with server pack 3 / 512 MB ram / Chrome browser

i can't delete the folder named as xerox in E:\program files\, and also have the sub folder in xerox named as nwwia, i want to know how to remove from my system.

Regards
GopinathIf the folder is in use ( such as PRINTER driver etc related to the Xerox is in service ) Windows will not delete and will state file in use etc.

Have you tried to use the uninstaller that should be LOCATED under control pannel, add/remove programs?

If uninstaller is bad you will have to find the service that is xerox and kill the service and then mark it not to automatic start the service, then REBOOT windows, then you might be able to remove it as long as you are the administrator of the system.

1653.

Solve : Vundo?

Answer»

Just so I don't HIJACK that other THREAD anymore

Looks like you were RIGHT, Kpac. SAS found 2 VUNDO FILES right off the bat.

Still running scans, I'll get logs in here shortly.Okay, I'll be waiting.

1654.

Solve : What are the top free antivirus and spyware programs for my computer?

Answer»

I have a reconditioned hp computer with windows xp and i would like to know what the best antivirus programs are to install to KEEP my computer clean and how many i need to install. Thank You. System: Microsoft Windows XP Professional Version 2002 Service Pack 3. Intel(R) Pentium(R) 4 CPU 3.20GHz 3.19Ghz, .099 GB of Ram.1. for antivirus -- get AVAST, AVG, or AVIRA (all three are free, get the one you like best ... only one antivirus is needed, DO NOT GET MORE THAN ONE!!)

2. Turn off the windows firewall, it's junk. get comodo firewall instead --> http://personalfirewall.comodo.com/

3. Get superantispyware --> http://www.superantispyware.com/

4. Get malwarebytes' anti-malware (http://malwarebytes.org/mbam.php, download link on left side)

Superantispyware and malwarebytes' have free and paid version, no difference in either except in free version, you have to do EVERYTHING manually, like the scanning and the updating and there's no realtime protection.

5. I would have ccleaner and advanced systemcare on your pc.

That is your pc army to keep your pc in good shape, in my opinion.

And you list 0.099GB of ram> are you sure you have that number right> 0.099 GB is approx 99 MEGABYTES you know.go for avast and all of the above , all very good Thank you so much! I really APPRECIATE it. And it is .99gb not .099 (type o). I will come here for all my info needs. you will and can get all the advice you want , harryavast RUNS it-self you can stop it the odd night if you want to

run ccleaner twice a week

the other 3 , once a week , harryWell, just find an antivirus that you like, is automatically updating at least once a day and has realtime protection. (AVIRA, AVAST and AVIRA all do it and all three are free and fine for average user and so find the one you like best if you want to go the free way )

1655.

Solve : Computer is not working right??

Answer»

My computer is not working right. I'm not exactly sure of what is GOING on with it but I know that there is something wrong. I really need help. I know I have not posted my logs yet but I will asap.Nobody is going to be ABLE to provide any help at all until you tell US exactly what the specific problems are.

1656.

Solve : Windows Security Alert problems...?

Answer»

Well im pretty ure i have malware problems, I did the malware tutorial steps.
after SUPERantispyware scanned my lap top, i made sure everything was checked and quarantined
but after my lap top rebooted SUPERantipyware will no longer open.
i get this "application cannot be executed. the file wltuser.exe is INFECTED. do you want to activate your antivirus software now?"

and i keep getting pop UPS for antivirus soft.com and also some ADULTXXX websites.

I have hit a wall and do not know what else to do. can someone please help??Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster Jaydragonmaster jay,

I tried to download combofix, but when the window opens with the downloads from firefox it wont let me open combofix to install, it will open for a second then close and the little balloon at the BOTTOM right says application cannot be executed. Delete your copy of ComboFix; grab a fresh copy, except before you download it, rename it to blackpudding.bat


Navigate to Start --> RUN, and enter the FOLLOWING command exactly as shown:

"%userprofile%\desktop\blackpudding.bat" /killall

See if ComboFix will run now.

1657.

Solve : Orange Email problem?

Answer»

Hi, I can log into my Orange home page no prob, I then click the link to my Email account then a full page SECURITY mess comes up and tells me There is a problem with this websites security cert. The security cert presented by this website has expired or is not yet valid, Ive never had this prob before with Orange I've tried changing the time on my computer clock and system restore but nothing has helped any ideas please More info would be helpful. Does Orange mean http://www.orange.co.uk/? Do you use always ACCESS your email VIA their webmail logon, in other words, via your web browser?
Quote

There is a problem with this websites security cert. The security cert presented by this website has expired or is not yet valid, Ive never had this prob before with Orange ...
Does the message actually pertain to Orange or to the website which is being opened from a hyperlink in an email message in your Orange account? Hi everyone problem solved
went to start search typed inetcpl.cpl hit ENTER opened advanced tab and clicked reset, re downloaded INTERNET explorer 8 and everything is now working fine. yipee OK.
1658.

Solve : Possible Malware/Virus Problem?

Answer»

Hi, i've been having regular PROBLEMS with my computer which I suspect is a virus/spyware/malware problem. Every time i try to open an application it says "Application cannot be executed. The file _______ is infected. Do you want to activate your antivirus software now?" Any help would be greaty appreciated.Try all of these please.

Try not to restart the computer until one of the tools we use does it for you or tells you to.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the next one.

Vista and Windows 7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran SUCCESSFULLY.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run then try to immediately run the following.


Download and run exeHelper

* Please download exeHelper from Raktor to your desktop.
* Double-click on exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the log.txt file to your next message.

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and POST the two logs together (they will both be in the one file).

Please run TDSSKiller per the below steps:

* Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
* Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any sub-folder of the Desktop.
* Click Start > Run and copy/paste the following RED text into Run box and hit Enter on your KEYBOARD.

"%userprofile%\Desktop\TDSSKiller.exe" -v

* Follow the instructions to type in "delete" when it asks you what to do when if finds something.
* When done, a log file should be created on your C: drive called 'TDSSKiller.txt' please add this log to your next reply.I ran rkill as requested and it worked but when i try to download the link you gave me for the exehelper it says "File not found Firefox can't find the file at http://www.raktor.net/exeHelper/exeHelper.com."The link works for me. It must be the malware.

Skip down to TDSSKiller.TDSSKILLER runs for about 2 seconds before i get the "Application cannot be executed. The file tdsskiller.exe is infected. Do you want to activate your antivirus software now?" message and it closes.Try booting the computer into Safe Mode and then run TDSSKiller.

1659.

Solve : Autorun Infections on USB Drives?

Answer»

Yes that would be best.When I tried to drag the CFScript.txt onto the ComboFix icon I think it asked to Run and I think I said O.K. then I realised my browser was still OPEN and so I tried to delay the ComboFix program while I closed it.

The browser is now shut.

However, I have a couple of warning screens saying that Avast and BOClean are active.

Will I be able to shut them from the icons on the TaskBar while the warning boxes are still visible ?

Should something ELSE have happened ?

What should I do ?

Again massive thanks for your patience.

Quote

Will I be able to shut them from the icons on the TaskBar while the warning boxes are still visible ?

Yes shut them down now and then let CF continue.I've closed Avast and BOClean and the ComboFix Blue area has appeared.

It has given a message that there is a new version of ComboFix available and is asking if I want to download it.

Should I update now or proceed with the scan ?Yes update it before continuing.In case it is important, I thought I had better mention that both times after ComboFix re-booted the Lenovo it has briefly displayed a text line saying that it couldn't find combofix.sys.

I have attached the ComboFix Report generated after starting it with the CFScript.

I have run the Temp File Cleaner. It removed 68.00MB.

[Saving space, attachment deleted by admin]That looks good now.

I'm confident that the computer is clean and it should perform a little better with all of the Norton stuff gone.


Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.

* Click START then RUN
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter.

The above procedure will:
* Delete: ComboFix and its associated files and folders.
* Reset the CLOCK settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Here are some more suggestions to help tighten up your computers security.

Use the Secunia Software Inspector to check for out of date software.

* Click Start Now
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERANTISPYWARE and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online SCAMS, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hi. Thank you for your help.

I am trying to uninstall ComboFix.

I have typed the command in the RUN box.

BOClean hs produced this message :

RSK-HIDE.SAA MALWARE STOPPED by BOCLEAN

Location of startup : FILE
C:\32788R22FW\HIDEC.EXE

This trojan horse was found on your machine.
It has been shut down, but the FILE from which it
started still remains and can be started up again.

Do you want the file removed also ?

YES/NO

Please advise.Disable BOClean before uninstalling ComboFix.I closed down BOClean and Avast so that the unistallation would continue.

I have an "Info" Box on screen that says "ComboFix is ininstalled".

It appeared really quickly, there were no other screens and the computer did not re-boot.

Is that O.K?Yes it's gone. It happens very fast.


You should be good to go on cleaning the other drives now. Nothing on the computer will spread to them. Just don't let the drives auto launch before you are sure they're cleaned.
In the process of using a 250GB Iomega Hard Drive, that has not had contact with the Lenovo, to transport Flash Disinfector, Panda USB Vaccine and Avira Anti-Virus to my Toshiba laptop, I discovered that I had not been following your TWEAK UI Auto-Run instructions properly.

What I have found is that if you -->

Open Tweak UI
Expand My Computer
Expand AutoPlay
Click Types
UNcheck "Enable Autoplay for removable drives"
Click Apply
Click O.K.

your external hard drive will STILL Autoplay, even after a re-boot.

I suppose the Tweak Tool is divided up so that the section I looked at and modified is geared towards ENABLING a function - whereas the LIST I *should* have looked at is about SWITCHING THINGS OFF.

I'm posting my mistake so that hopefully other people will avoid it.

I do find it confusing that IMY WRONG Tweak appears to have no effect.

Is AutoPlay ever actually really necessary for anything ?

If you have a CD or a DVD, could you not always CHOOSE to make it start by clicking the optical drive's icon ?

Thanks again for all the help that you have provided. This site is brilliant. The direct links to the relevant pages for program downloads cut through so much time searching at Google or just trying to navigate through a software company's site.


ADDITION : I just went to manually modify the AutoPlay settings on the Lenovo and this Systemax and can see that ALL of the drives - even the optical drives - have been deselected.

So I take it that's what Panda Vaccine does when it "Vaccinates a Computer" rather than an external drive.


There are some more solutions for disabling autoruns here. http://support.microsoft.com/kb/967715
1660.

Solve : Please review- Help !!! 3 Different problems !?

Answer»
- I have tried to download the NEW 9.0 AVG - and it will not load - gets to the end and says it can't be installed. ( I have 8.5 running)
- I TRIED to load the SuperAntispyware - Website is temporarily unavailable.....
I did run the hijack This - log attached
I ran MalwareBytes -Log attached
I ran AVG in safe mode and got a bunch of problems .. -Log attached
So far the 3 main issues i have found are -
Packed.DelfCrypt
Vundo.JP
and Fake Alert.OQ
I don't even know where to start as everytime I try run the scan it just freezes and shuts down - however I did run AVG in safe mode
Any help would be greatly appreciated !
Thanks ,
M3lani3


[Saving space, attachment deleted by admin]Welcome to CH Spicegirl.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
  • O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
  • O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
  • O20 - AppInit_DLLs: 71.dll
  • O20 - Winlogon Notify: d4a6afe8757 - I:\WINDOWS\
.
Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

NOTE: Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers

----------

Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix
Thank You Evil - I have done as instructed and then did a new log from combo fix...
I did run the Malware bytes again last night and got it down to 4 infections- still need to upgrade my AVG -
My IE still hangs - wont move off of the front page .... Only Firefox running at this point- can you help me with that too?? Is it all still connected to the Viruses/ spyware?


Greatly Appreciate all your help ~!
M3L

[Saving space, attachment deleted by admin]Let me know how things are after this.



1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
i:\program files\Save\Save.exe

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
"BootExecute"=hex(7):61,75,74,6f,63,68,65,63,6b,20,61,75,74,6f,63,68,6b,20,2a,00,00

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WhenUSave"=-


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in CASE it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThanks again Evil ..
I have done as instructed again , and attaching the log ...
STILL no IE - brings up yahoo homepage , then just sits .. Can't do anything .. Thankfully Firefox , still ok..

Anymore suggestions to fix the IE ?
Thanks again !

M3L !



[Saving space, attachment deleted by admin]Download the Fix IE Utility to your desktop.

Before running the utility, make sure that all your Internet Explorer windows are closed!

* Extract the contents of the .zip file to your desktop.
* Double click the Fix IE Utility button to run the tool.
* Click Run Utility
* Click OK when you see 'Re-registered all files'
* Open Internet Explorer and see how it works.


Let me know how things are now.
THANK YOU, THANK YOU, THANK YOU !!!!!
I **THINK** it is all back to normal now ... I am writing to you again through IE this time (YAY!!)
I have run AVG and nothing comes up - will run the Malware Bytes again this evening , but seems to be running alot better ...
Thanks soooo much for all your help Evil!
I have applied to learn to fight malware(@ GeekPolice Acadamy) to assist others like you have done for me !
Do I need to delete the combofix , hijack this and various other things from my computer now ? Or shall I keep them just in case?? ( suppose I could always just re-install them all ..)

Once again , THANK YOU !!!!! (I'd hug ya if I knew ya better !!!) * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then HIT Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan LogWell, it all SEEMED good ! hhahah !
The ESET found 2 infected files ..
Log Attached ..

Thanks Evil...

[Saving space, attachment deleted by admin]Those were nothing to worry about.

Disable/Enable the System Restore Utility to flush old infected restore points

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Use only trusted security software like the programs listed on this page. Trusted security tools & resourcesThank You for your help Evil -
I have done as you instructed above - did have to update the Java , and have now added the WOT , so hopefully it helps me out !
I really appreciate all the help !
Mel Your welcome.

Safe surfing...
1661.

Solve : spyware/malware??

Answer»

Thanks DMJ...

couple things of note:
1) this is her work computer and although I was able to download and run the programs you have listed, we are unable to upgrade SPS, Office and a few of the other items...this is how the IT GROUP who manages their computers have them set up....not a thing i can do about that...
2) she KNOWS how she was infected - she opened an email she was expecting and it was infected...
3) she uses FF as is - i've convinced her long ago to abandon IE, but there are some sites that will only work in IE so she's not 100% FF...

so, looking over everything posted here, does she LOOK to be free of spyware?Yes free of infection.

For Firefox, and running sites that will not load correctly (unless in Internet Explorer), use this BROWSER add-on: IE TAB: https://addons.mozilla.org/en-US/firefox/addon/1419

It uses the IE engine, and helps with compatibility.

Any other questions?nope, you got it all for me! thanks for the help...You're welcome.

1662.

Solve : New AV?

Answer»

Hi guy's

My AV is up for renewal, been using Norton for the past three years, and before everyone offers there opinions on the product that's not why I'm here.
I'm here because of very reliable people such as WillyW and Patio that Norton may not be the best and should the opportunity arise to change which has maybe I should look elsewhere.

This is in no way a defamatory look at Norton as I said I have been with them 3yrs and as you may have noticed... never posted a problem in here.
I also run malwarebytes, Ccleaner and superantispyware as a general rule of my week by week caretaker duties.

I suppose I'm asking is there any REASON to change and if so why.... money is not a problem but my computer should not be.

As always any useful posts appreciated and I thank in advance. you could try sophos AV it's not normally used for home computers and seems to be more aimed at distributed platforms such as in college servers where many different computers/OS's (MAC,Windows,Linux,Unix etc) could be connecting to get on the NET. I ran it for 2 years and never had a problem. It was almost like using an industrial chemical for home cleaning purposes...needlessly excessive!!! and more than a safe bet for home computing.Quote from: alphanumeric on February 11, 2010, 01:45:46 AM

you could try sophos AV it's not normally used for home computers and seems to be more aimed at distributed platforms such as in college servers where many different computers/OS's (MAC,Windows,Linux,Unix etc) could be connecting to get on the net. I ran it for 2 years and never had a problem. It was almost like using an industrial chemical for home cleaning purposes...needlessly excessive!!! and more than a safe bet for home computing.

Yeah one reason to move from Norton would be the fact that Norton is a massive 'resource hog'. How is sophos when it comes to background stuff? Thanks for the reply. I, myself, prefer MicroSoft Security Essentials. With a 98% EFFIENCY rating and not being a resource hog sure gets my vote.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) AVIRA AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.Quote from: SuperDave on February 11, 2010, 08:58:52 AM
I, myself, prefer MicroSoft Security Essentials. With a 98% effiency rating and not being a resource hog sure gets my vote.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.


Very helpful SuperDave, thanks for the links. Thinking I may give MS security essentials a run.
1663.

Solve : ??? Web-Protection ????

Answer»

While downloading somthing else Mc-Afee got installed on my computer.I just ran 1 scan with it and it says I have no internet protection,what do they mean with that ? I do have Avast.(I don`t run the 2 at the same time,I was curious and thought;Let`s see if it "can spot something Avast has missed).As I see it Avast is I-Net protection.Or do they mean there is no childrens lock installed ?
And what exactly is a firewall ? I do run SpywareBlaster.
Is Avast+SpywareBlaster enough ? If not what else must I install ?


All the best,greetings : Eric..................Remember...Google is your friend.

"While downloading somthing else Mc-Afee got installed on my computer." McAfee doesn't just "download" itself. It's not free so it's gonna cost. You don't say what you were downloading, your ISP or if you've run any scans. More info would be nice.

Alan <>< I do not know exactly but it was one of these get a "free" scan actions.I did not look what I was doing and it got installed.I don`t even know what a ISP is,sorry...
I just know when I downloaded something I did not "uncheck" one of the boxes(The ones that normally install a toolbar or so),and there is McAfee scan plus on my screen...But that is not the problem,it says I do not have I-Net security while I do run A-Vast and SpywareBlaster.I want to un-install Mc-A but why is it telling me I have no webprotection while I do run Avast and SpywareBlaster...
To keep it easy:Is A-Vast and spywareBlaster enough for my computer or must I install anything else.And (if you know):what is the difference between a fire-wall and a anti-virus program ?

Thank you for the quick reply:Eric..................You probably installed the McAfee Security Scan while updating or installing something. Just go to Add or Remove Programs and uninstall McAfee Security Scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and UNRELIABLE shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ENSURE you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free CLEANING/maintenance tools to help keep your computer running smooth.Thank you VERY much.W.O.T.,I have allready installed(Thanks for the tip).And I am busy with the rest.I was one of those guys that was a freak in cleaning and ran much to much cleaning-programs.Now I know what I REALLY need I`ll keep it at that.
If I encounter any problems with the other programs I`ll let you know.But I think all is all right now !!!

Thanks a million : Eric............

PS : What is: Bumping a thread ??

1664.

Solve : help! cannot open any programs. keep getting virus alerts?

Answer»

out of nowhere today my computer kept getting popups telling me i have a virus. it won't let me open any programs other than firefox. i've been reading posts with other people who had this problem but nothing seems to work. it's called antivirus soft. please help me.
forgot to post the msg that comes up everytime i open anything. 'Security Warning - Application cannot be executed. The file .....exe is infected. Do you want to activate your antivirus SOFTWARE now?'

thanksPlease download ComboFix from BleepingComputer.com

Alternate link: GeeksToGo.com

Alternate link: Forospyware.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
  • Click Start>Run then copy paste the following COMMAND into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's STRONGLY recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
i've done that and the pop ups seemed to have gone away now. thanks!
here's the log


ComboFix 10-02-01.02 - User Account 02/02/2010 6:29.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.479.91 [GMT -4:00]
Running from: c:\documents and settings\User Account\desktop\commy.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\documents and settings\User Account\Application Data\inst.exe
C:\Install.exe
c:\program files\INSTALL.LOG
c:\recycler\S-1-5-21-299502267-1715567821-839522115-1003
c:\windows\EventSystem.log
c:\windows\system32\Thumbs.db
c:\windows\system32\trial icon - .ico

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.

2010-02-02 04:20 . 2010-02-02 04:20--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-02 04:16 . 2010-02-02 04:16--------d-----w-c:\program files\SUPERAntiSpyware
2010-02-02 04:16 . 2010-02-02 04:16--------d-----w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com
2010-02-02 03:24 . 2010-02-02 03:24--------d-sh--w-c:\documents and settings\Administrator\PrivacIE
2010-02-02 00:15 . 2010-02-02 00:15--------d-----w-c:\windows\LMI5C.tmp
2010-02-02 00:05 . 2010-02-02 00:05--------d-----w-c:\program files\LogMeIn Rescue
2010-02-01 21:22 . 2010-02-01 21:22--------d-----w-c:\program files\Trend Micro
2010-02-01 21:15 . 2010-02-01 21:15--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2010-02-01 20:34 . 2010-02-01 20:34--------d-----w-c:\documents and settings\User Account\Application Data\Malwarebytes
2010-02-01 20:33 . 2010-01-07 20:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 20:33 . 2010-02-01 20:33--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-01 20:33 . 2010-02-02 04:01--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-02-01 20:33 . 2010-01-07 20:0719160----a-w-c:\windows\system32\drivers\mbam.sys
2010-02-01 18:29 . 2010-02-02 10:20--------d-----w-c:\documents and settings\User Account\Local Settings\Application Data\fngmom
2010-01-23 13:53 . 2007-03-19 00:3765602----a-w-c:\windows\system32\cook3260.dll
2010-01-19 14:37 . 2010-01-31 01:30--------d-----w-c:\documents and settings\User Account\Application Data\Vso
2010-01-19 14:36 . 2010-01-23 13:53--------d-----w-c:\program files\VSO
2010-01-19 14:24 . 2010-01-19 14:24--------d-----w-c:\program files\Haali

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 10:06 . 2010-02-02 04:21117760----a-w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-02 04:21 . 2010-02-02 04:2152224----a-w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-01 19:52 . 2008-05-12 01:43--------d-----w-c:\documents and settings\User Account\Application Data\Azureus
2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\windows\system32\drivers\pcouffin.sys
2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\documents and settings\User Account\Application Data\pcouffin.sys
2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\documents and settings\User Account\Application Data\pcouffin.sys
2010-01-23 13:44 . 2010-01-23 12:58--------d-----w-c:\program files\Common Files\AVSMedia
2010-01-23 13:44 . 2010-01-23 12:58--------d-----w-c:\program files\AVS4YOU
2010-01-23 13:01 . 2010-01-23 13:01--------d-----w-c:\documents and settings\User Account\Application Data\AVS4YOU
2010-01-23 13:01 . 2010-01-23 13:01--------d-----w-c:\documents and settings\All Users\Application Data\AVS4YOU
2010-01-22 19:34 . 2010-02-02 00:04177568----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\rahook.dll
2010-01-22 19:34 . 2010-02-02 00:056116752----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\npRescue.dll
2010-01-22 19:34 . 2010-02-02 00:05959904----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\components\npRescuePostInstallProcedure.exe
2010-01-22 19:34 . 2010-02-02 00:051803680----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\LMIRSrv.dll
2010-01-20 13:00 . 2009-10-03 16:06--------d-----w-c:\program files\Microsoft Silverlight
2010-01-19 23:29 . 2010-01-19 15:55--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk
2010-01-19 14:24 . 2009-11-17 04:35--------d-----w-c:\program files\AviSynth 2.5
2010-01-18 13:07 . 2010-01-26 15:451260800----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-18 13:07 . 2010-01-26 15:453777280----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-07 01:11 . 2008-10-26 22:41--------d-----w-c:\program files\Vuze
2009-12-21 19:14 . 2004-08-10 21:51916480----a-w-c:\windows\system32\wininet.dll
2009-12-17 01:20 . 2009-12-17 01:19--------d-----w-c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-17 01:19 . 2009-12-17 01:19360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-12-17 01:19 . 2009-12-17 01:1912464----a-w-c:\windows\system32\avgrsstx.dll
2009-12-17 01:19 . 2009-12-17 01:19333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-12-17 01:19 . 2009-12-17 01:1928424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-12-17 01:18 . 2009-12-17 01:18--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2009-12-17 01:18 . 2009-06-21 18:01--------d-----w-c:\program files\AVG
2009-11-27 16:54 . 2009-07-16 23:4561664-c-ha-w-c:\windows\system32\mlfcache.dat
2009-11-21 15:51 . 2004-08-10 21:49471552----a-w-c:\windows\AppPatch\aclayers.dll
2009-11-10 03:20 . 2009-11-10 03:2015884----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\azitunes\libProcessAccess.dll
2009-11-10 03:20 . 2009-11-10 03:20102400----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
2009-11-10 03:20 . 2009-11-10 03:204141117----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe
2009-11-10 03:20 . 2009-11-10 03:206516755----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime TASK"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"D-Link Wireless G WUA-1340"="c:\program files\D-Link\Wireless G WUA-1340\AirGCFG.exe" [2007-08-27 1662976]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
MBCameraMonitor.lnk - c:\program files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe [2009-9-5 541976]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 18:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-17 01:1912464----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:0439792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:1215360------w-c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 05:4149152----a-w-c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 00:21141600----a-w-c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
2005-08-25 02:25101080-c--a-w-c:\program files\Microsoft Location Finder\LocationFinder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 19:443883856----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50155648-c--a-w-c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2005-04-27 19:035898240----a-w-c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2005-04-27 19:0386016-c--a-w-c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2005-04-27 19:031519616-c--a-w-c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 04:54417792----a-w-c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-01-21 04:0477824-c--a-w-c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-02-22 07:25144784-c--a-w-c:\program files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/05/2008 1:10 AM 715248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [16/12/2009 9:19 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [16/12/2009 9:19 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 7:56 AM 74480]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [03/10/2009 8:25 AM 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [03/10/2009 8:25 AM 234888]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [16/12/2009 9:18 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [16/12/2009 9:18 PM 285392]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 7:56 AM 7408]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/09/2009 11:15 AM 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34]

2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 15:15]

2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 15:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {8F4213B4-A970-4B3C-820D-343C693D5BF0} - hxxp://dsp02.eastlink.ca/SelfProvisioning.cab
FF - ProfilePath - c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\npRescue.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
MSConfigStartUp-!AVG Anti-Spyware - c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
MSConfigStartUp-DbWinEn - c:\windows\system32\ypgfqvuz.exe
MSConfigStartUp-IMprocess - c:\program files\Instant Messenger Names\IM-svr.EXE
MSConfigStartUp-MSFox - c:\docume~1\USERAC~1\LOCALS~1\Temp\a.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 06:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys spvw.sys hal.dll >>UNKNOWN [0x8598F944]<<
kernel: MBR read successfully
detected MBR rootkit HOOKS:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75b9f28
\Driver\ACPI -> ACPI.sys @ 0xf7326cb8
\Driver\atapi -> atapi.sys @ 0xf72e1b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: SiS 900-Based PCI Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf71ecb0a
PacketIndicateHandler -> NDIS.sys @ 0xf71f7a21
SendHandler -> NDIS.sys @ 0xf71ec949
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(532)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(856)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\slserv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-02 06:52:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-02 10:52

Pre-Run: 33,711,702,016 bytes free
Post-Run: 33,722,482,688 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E8010BFE5BE0C42DCE93EBC246EAED95
Hi again. Please do these steps in order.

1. Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
2. Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer:

http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Post the log from SUPERAntiSpyware when you've accomplished that.

4. Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

5. Post the following in your next reply:
  • MBAM log
  • SAS log
  • ESET log
And, please tell me how your computer is doing.Here are my logs.

MALWARE BYTES

Malwarebytes' Anti-Malware 1.43
Database version: 3458
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

01/02/2010 4:57:20 PM
mbam-log-2010-02-01 (16-57-20).txt

Scan type: Quick Scan
Objects scanned: 118882
Time elapsed: 13 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 37
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 62

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\xml.xml (Worm.Allaple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Worm.Allaple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IMAdvertiser (Adware.SearchTwo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslAgent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\System\CurrentControlSet\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\System\CurrentControlSet\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\turbonet (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\systemcheck2 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\akl (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\akl\akl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\akl\uninstall.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Program Files\akl\unsetup.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\ADAPT_Installer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtoolb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\[emailprotected]k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winSystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\winSystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.SUPERANTI SPYWARE
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/02/2010 at 05:58 PM

Application Version : 4.33.1000

Core Rules Database Version : 4548
Trace Rules Database Version: 2360

Scan type : Quick Scan
Total Scan Time : 00:27:28

Memory items scanned : 541
Memory threats detected : 0
Registry items scanned : 554
Registry threats detected : 0
File items scanned : 16130
File threats detected : 12

Adware.Tracking Cookie
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt
ESET

[emailprotected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=dfe16a8708cf9d489892f4e80efe9c4b
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-02 11:07:46
# local_time=2010-02-02 07:07:46 (-0400, Atlantic Standard Time)
# country="Canada"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 6861 6861 0 0
# compatibility_mode=768 16777215 100 0 41122462 41122462 0 0
# compatibility_mode=1024 16777175 100 0 3218276 3218276 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=78970
# found=0
# cleaned=0
# scan_time=3071
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done
To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
1665.

Solve : Trojan caused Win Vista problems?

Answer»

I'm new to this site, but I've been told it's the best place to go for help. I had AVG on my HP notebook for a very long time, however a trojan snuck past it and now I'm getting errors left and right. When I would double click on AVG, Mozilla, or any other program, I would get a box that said "Open With - Choose the program you want to USE to open this file: " and my only choices were Adobe Reader 8.1 or Firefox. By chosing Firefox (to open a web page) another box would pop up that says "Opening firefox.exe - You have chosen to open firefox.exe which is a: Application from C:\Program Files\Mozilla Firefox - Would you like to save this file?" and I would have the option to Save or Cancel. I had no option to "Always use the selected file to open this program" or I would have just checked that box and solved that problem... Going hand in hand with this minor inconvenience is a problem with my Windows program (the actual part I'm worried about). When I try to open things in my Control Panel I get the message "C:\Windows\system32\rundll32.exe Application not found ". Therefore, I am unable to navigate through several areas of my control panel (to my ability anyway).

My COMPUTER came with Win Vista installed and I don't have any disks to use if that's what's required at this point. I would just really appreciate a hint or two as to where I should go from here with this problem. I'm clueless. I have run Kaspersky now that I had to take AVG off the computer from the error messages I kept getting and Kaspersky tells me that there are no more Trojans or other problems on my machine.

Hijack This says :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:12 PM, on 2/2/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HJT\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: HP PRINT Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [QlbCtrl] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [OnScreenDisplay] "C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
O4 - HKLM\..\Run: [WAWifiMessage] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [NvCplDaemon] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [notepad] rundll32.exe C:\Windows\system32\config\SYSTEM~1\ntload.dll,[emailprotected]
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: HP Smart SELECT - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdcserv.exe
O23 - Service: lxdc_device - - C:\Windows\system32\lxdccoms.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NlsSrv32.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SName - Unknown owner - C:\Windows\system32\borCFileName.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6988 bytes


Looking forward to what you think...
Thanks
Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when DONE, post the log back here.

1666.

Solve : avast help?

Answer»

I use Avast Virus program and it is FREE

But it keeps finding all of these Viruses so I scan and Fix all and run it in Safe Mode and do the same thing.

It still wont get rid of them.
Does anyone KNOW of a good FREE Virus program???
PS yes I did the updateFirst we need to know what Avast is complaining about. It's not good to do a BUNCH of changes to an INFECTED computer.

Scan your computer with Panda ActiveScan

* Once you are on the Panda site click the Scan your PC now button.
* A new window will open...click the Scan Now button.
* If it wants to install an ActiveX component allow it.
* It will start downloading the files it requires for the scan. (Note: It may take a couple of minutes)
* You may get a warning from Internet Explorer that Panda is ready to install, please allow it.
* The scan will BEGIN. Please be patient as it can take an hour or more to complete.
* When the scan completes, if anything malicious is detected, click the Export to: button (LOOKS like a little Notepad).
* Save the ActiveScan.txt to a convenient location like your desktop.
* Note: You do not need to select any of the Disinfect options. We will remove any threats manually.

* Post the contents of the ActiveScan report in your next reply.I did the scan like you told me to and it found 32 Infected Items.

It was only at 20 percent and I had to stop because it was taking all day.

I have no time left so I will have to get this out somehow.
No problem.Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayI need a good free Mailware program

Is SbyBot good and free or any of them??

1667.

Solve : Recomended Antivirus and Firewall.?

Answer»

As I recall there was a page somewhere here that listed the latest and greatest antivirus and firwalls. I cannot seem to find it, if it still exists.

I am working on a 1ghz dell laptop with 256mb ram. ANYTHING not to heavy you can recomend? Thanks!Microsoft Security Essentials is very lightweight and protects very well. http://www.microsoft.com/Security_Essentials/

As for a FIREWALL. If you aren't doing any online banking, PayPal etc, then the WINDOWS firewall will be sufficient. Any third party firewall will likely slow down the computer.Thanks for the reply. The computer will be used for online banking and such other things.You might try a few of these and see which one works the best with your setup.

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo HopSurf..", Ask.com search provider" and "Make Comodo HopSurf.com Search my homepage"
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

Comodo or Online Armor might be the ONES to try first.Thank you very MUCH for the speedy replys!!Your welcome.

1668.

Solve : How can I get a back trace to catch a hacker?

Answer»

Last night a hacker got into my MAIN computer and changed all my SETTINGS and DISABLED my devices and is now trying to communicate with me thru yahoo messenger. He disabled his username he says was for my protection. I had Zone Alarm FIREWALL, AVG antivirus, and Threat fire antivirus but he was still able to get into my computer. My ZoneAlarm doesn't have the back trace feature and I can't find any info who to CONTACT to do a back trace if he attempts to contact me thru messenger again. Any help appreciated. THANKSPlease go to this link and follow the directions and post the required logs.

1669.

Solve : anti-virus question?

Answer»

If I'm using AVG Free version, and I've got RESIDENT Shield enabled, should it be disabled before I run a scan with say, Malwarebytes?I don't disable mine.

Alan &LT;>< Yes, i used to have two different sorts of anti-virus scanners that WOULD detect the other as viruses if they were both active, so i simply turned one off and it seemed to work fine

don't know if it will absolutely work in this case, but it is worth a tryUse AVAST ! Be SMART

Get Better Results Than AVG





AVAST USER


You do not have to turn off your protection to run MBAM

1670.

Solve : Internet Explorer very hard to open?

Answer»

For some time we have suffered from redirects when browsing. This problem was becoming more persistent. We also had a recurring message about a threat on a WIN file which AVG was patching but could not remove.
Over the last few days it was becoming nearly impossible to get IE to connect. When IE was double clicked it flashed on briefly then closed almost immediately with a message that it had encountered a problem and needed to close.
I installed SP3 for XP and IE8 but this made no difference. I have now completed all Malware removal steps and attach logs.
Both users can now access the internet from their desktops.
I will be grateful for any other steps I should take

[Saving space, attachment deleted by admin]Hello moreagh.

You had some pretty nasty stuff on the computer so I need to warn you of the potential hazards.

The computer was infected by a worm and backdoor trojan(s), which has Backdoor Functionality. This can give intruders complete control of the computer, logging key strokes, stealing information, etc.

You are strongly advised to do the following immediately!

* Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
* From a clean computer, change [color=redall[/color] of your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
* Because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure it can ever again be trusted.
* Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

To help you make a more informed decision, please read the following articles:

* Danger: Remote Access Trojans.
* When should I re-format? How should I reinstall?
* How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.
Please let me know your decision and we'll get started with clean up if that's what you choose.


If you decide to continue with cleaning please follow the below steps.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • O4 - HKLM\..\Run: [lphcafoj0e7er] C:\WINDOWS\system32\lphcafoj0e7er.exe
  • O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdpjv.exe] C:\WINDOWS\system32\kdpjv.exe
.
Important: Close all open windows EXCEPT for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
C:\WINDOWS\system32\kdpjv.exe
C:\WINDOWS\system32\lphcafoj0e7er.exe


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while DRAGGING the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

Thanks for the help.
I'll go with trying to clean the system.
I've DONE everything described however when combofix began to execute it asked me to disable the AVG antivirus scanner or risk damage to the machine.
Is it possible to disable this? If so how? Quote from: moreagh on February 03, 2010, 10:04:17 AM
Is it possible to disable this? If so how?

See here. http://www.bleepingcomputer.com/forums/topic114351.htmlThese are the Combofix logs.
I have noticed that Windows Firewall is not active and the system will not let me turn it on. Is this because this is the base computer for a wireless network

[Saving space, attachment deleted by admin]Quote
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *disabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}

You can't turn it on because OneCare is still there. I suggest uninstalling both Windows Live OneCare and Windows Live OneCare firewall.


Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

Go to Start > Run and type notepad.exe then click OK

Copy the text in the Code box below and paste it into Notepad.

Code: [Select]REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
In Notepad go to File > Save as...

Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop.

There should now be a file on the Desktop that looks like this

Double-click fixme.reg it and ALLOW it to merge with the Registry.

You may not see anything happen but give it a few seconds or so to finish.

Make sure that you tell me if you receive a success message about adding the above
to the registry. If you do not get a success message, it did not work.


Now delete the fixme.reg file from the Desktop.

----------

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* RESET the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Log
Merging with the registry was a success.
I also have Windows Firewall again.
ESETScan file attached

[Saving space, attachment deleted by admin]Looks good. How is the computer running now?

For a good free firewall. Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo HopSurf..", Ask.com search provider" and "Make Comodo HopSurf.com Search my homepage"
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

Computer running very well.
Good connections
Sharp response
No virus alerts
No redirects

I am really grateful for your help. The steps have been extremely clear, accurate and easy to follow.
Are there any of the programs I should now delete or any that I should now use on a regular basis in case of recurring problems?
Thanks again
RobertYour welcome.

Final suggestions.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1671.

Solve : here are my logs as requested?

Answer»

16:31:37:218 3128TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
16:31:37:218 3128================================================================================
16:31:37:218 3128SystemInfo:

16:31:37:218 3128OS Version: 5.1.2600 ServicePack: 3.0
16:31:37:218 3128Product type: Workstation
16:31:37:218 3128ComputerName: BOOBOO
16:31:37:218 3128UserName: tony
16:31:37:218 3128Windows directory: C:\WINDOWS
16:31:37:218 3128Processor architecture: Intel x86
16:31:37:218 3128Number of processors: 2
16:31:37:218 3128Page size: 0x1000
16:31:37:218 3128Boot type: Normal boot
16:31:37:218 3128================================================================================
16:31:37:234 3128UnloadDriverW: NtUnloadDriver error 2
16:31:37:234 3128ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
16:31:37:234 3128MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
16:31:37:234 3128UtilityInit: KLMD drop and load success
16:31:37:234 3128KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
16:31:37:234 3128UtilityInit: KLMD open success
16:31:37:234 3128UtilityInit: Initialize success
16:31:37:234 3128
16:31:37:234 3128ScanningServices ...
16:31:37:234 3128CreateRegParser: Registry parser init started
16:31:37:234 3128DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
16:31:37:234 3128CreateRegParser: DisableWow64Redirection error
16:31:37:234 3128wfopen_ex: Trying to open file C:\WINDOWS\system32\config\SYSTEM
16:31:37:234 3128MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043
16:31:37:234 3128wfopen_ex: MyNtCreateFileW error 32 (C0000043)
16:31:37:234 3128wfopen_ex: Trying to KLMD file open
16:31:37:234 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system
16:31:37:234 3128wfopen_ex: File opened ok (Flags 2)
16:31:37:234 3128CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 394970
16:31:37:234 3128wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
16:31:37:234 3128MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043
16:31:37:234 3128wfopen_ex: MyNtCreateFileW error 32 (C0000043)
16:31:37:234 3128wfopen_ex: Trying to KLMD file open
16:31:37:234 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software
16:31:37:234 3128wfopen_ex: File opened ok (Flags 2)
16:31:37:234 3128CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 394A18
16:31:37:234 3128EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
16:31:37:234 3128CreateRegParser: EnableWow64Redirection error
16:31:37:234 3128CreateRegParser: RegParser init completed
16:31:37:671 3128GetAdvancedServicesInfo: Raw services enum returned 376 services
16:31:37:687 3128fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
16:31:37:687 3128fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
16:31:37:687 3128
16:31:37:687 3128ScanningKernel memory ...
16:31:37:687 3128KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
16:31:37:687 3128DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 8714C348
16:31:37:687 3128DetectCureTDL3: KLMD_GetDeviceObjectList returned 4 DevObjects
16:31:37:687 3128
16:31:37:687 3128DetectCureTDL3: DEVICE_OBJECT: 871DF958
16:31:37:687 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 871DF958
16:31:37:687 3128KLMD_ReadMem: Trying to ReadMemory 0x871DF958[0x38]
16:31:37:687 3128DetectCureTDL3: DRIVER_OBJECT: 8714C348
16:31:37:687 3128KLMD_ReadMem: Trying to ReadMemory 0x8714C348[0xA8]
16:31:37:687 3128KLMD_ReadMem: Trying to ReadMemory 0xE18BC8B8[0x18]
16:31:37:687 3128DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
16:31:37:687 3128DetectCureTDL3: IrpHandler (0) addr: F75C2BB0
16:31:37:687 3128DetectCureTDL3: IrpHandler (1) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (2) addr: F75C2BB0
16:31:37:687 3128DetectCureTDL3: IrpHandler (3) addr: F75BCD1F
16:31:37:687 3128DetectCureTDL3: IrpHandler (4) addr: F75BCD1F
16:31:37:687 3128DetectCureTDL3: IrpHandler (5) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (6) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (7) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler ( addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (9) addr: F75BD2E2
16:31:37:687 3128DetectCureTDL3: IrpHandler (10) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (11) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (12) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (13) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (14) addr: F75BD3BB
16:31:37:687 3128DetectCureTDL3: IrpHandler (15) addr: F75C0F28
16:31:37:687 3128DetectCureTDL3: IrpHandler (16) addr: F75BD2E2
16:31:37:687 3128DetectCureTDL3: IrpHandler (17) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (18) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (19) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (20) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (21) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (22) addr: F75BEC82
16:31:37:687 3128DetectCureTDL3: IrpHandler (23) addr: F75C399E
16:31:37:687 3128DetectCureTDL3: IrpHandler (24) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (25) addr: 804F4562
16:31:37:687 3128DetectCureTDL3: IrpHandler (26) addr: 804F4562
16:31:37:687 3128TDL3_FileDetect: Processing driver: Disk
16:31:37:687 3128TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:687 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:703 3128TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
16:31:37:703 3128
16:31:37:703 3128DetectCureTDL3: DEVICE_OBJECT: 87148C68
16:31:37:703 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 87148C68
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x87148C68[0x38]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT: 8714C348
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x8714C348[0xA8]
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0xE18BC8B8[0x18]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
16:31:37:703 3128DetectCureTDL3: IrpHandler (0) addr: F75C2BB0
16:31:37:703 3128DetectCureTDL3: IrpHandler (1) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (2) addr: F75C2BB0
16:31:37:703 3128DetectCureTDL3: IrpHandler (3) addr: F75BCD1F
16:31:37:703 3128DetectCureTDL3: IrpHandler (4) addr: F75BCD1F
16:31:37:703 3128DetectCureTDL3: IrpHandler (5) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (6) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (7) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler ( addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (9) addr: F75BD2E2
16:31:37:703 3128DetectCureTDL3: IrpHandler (10) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (11) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (12) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (13) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (14) addr: F75BD3BB
16:31:37:703 3128DetectCureTDL3: IrpHandler (15) addr: F75C0F28
16:31:37:703 3128DetectCureTDL3: IrpHandler (16) addr: F75BD2E2
16:31:37:703 3128DetectCureTDL3: IrpHandler (17) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (18) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (19) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (20) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (21) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (22) addr: F75BEC82
16:31:37:703 3128DetectCureTDL3: IrpHandler (23) addr: F75C399E
16:31:37:703 3128DetectCureTDL3: IrpHandler (24) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (25) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (26) addr: 804F4562
16:31:37:703 3128TDL3_FileDetect: Processing driver: Disk
16:31:37:703 3128TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:703 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:703 3128TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
16:31:37:703 3128
16:31:37:703 3128DetectCureTDL3: DEVICE_OBJECT: 871E76F8
16:31:37:703 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 871E76F8
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x871E76F8[0x38]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT: 8714C348
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x8714C348[0xA8]
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0xE18BC8B8[0x18]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
16:31:37:703 3128DetectCureTDL3: IrpHandler (0) addr: F75C2BB0
16:31:37:703 3128DetectCureTDL3: IrpHandler (1) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (2) addr: F75C2BB0
16:31:37:703 3128DetectCureTDL3: IrpHandler (3) addr: F75BCD1F
16:31:37:703 3128DetectCureTDL3: IrpHandler (4) addr: F75BCD1F
16:31:37:703 3128DetectCureTDL3: IrpHandler (5) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (6) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (7) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler ( addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (9) addr: F75BD2E2
16:31:37:703 3128DetectCureTDL3: IrpHandler (10) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (11) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (12) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (13) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (14) addr: F75BD3BB
16:31:37:703 3128DetectCureTDL3: IrpHandler (15) addr: F75C0F28
16:31:37:703 3128DetectCureTDL3: IrpHandler (16) addr: F75BD2E2
16:31:37:703 3128DetectCureTDL3: IrpHandler (17) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (18) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (19) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (20) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (21) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (22) addr: F75BEC82
16:31:37:703 3128DetectCureTDL3: IrpHandler (23) addr: F75C399E
16:31:37:703 3128DetectCureTDL3: IrpHandler (24) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (25) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (26) addr: 804F4562
16:31:37:703 3128TDL3_FileDetect: Processing driver: Disk
16:31:37:703 3128TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:703 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys
16:31:37:703 3128TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
16:31:37:703 3128
16:31:37:703 3128DetectCureTDL3: DEVICE_OBJECT: 870D9AB8
16:31:37:703 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 870D9AB8
16:31:37:703 3128DetectCureTDL3: DEVICE_OBJECT: 870EC9E8
16:31:37:703 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 870EC9E8
16:31:37:703 3128DetectCureTDL3: DEVICE_OBJECT: 87148940
16:31:37:703 3128KLMD_GetLowerDeviceObject: Trying to get lower device object for 87148940
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x87148940[0x38]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT: 8714BF38
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0x8714BF38[0xA8]
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0xE18B6968[0x1A]
16:31:37:703 3128DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
16:31:37:703 3128DetectCureTDL3: IrpHandler (0) addr: F73C96F2
16:31:37:703 3128DetectCureTDL3: IrpHandler (1) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (2) addr: F73C96F2
16:31:37:703 3128DetectCureTDL3: IrpHandler (3) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (4) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (5) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (6) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (7) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler ( addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (9) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (10) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (11) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (12) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (13) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (14) addr: F73C9712
16:31:37:703 3128DetectCureTDL3: IrpHandler (15) addr: F73C5852
16:31:37:703 3128DetectCureTDL3: IrpHandler (16) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (17) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (18) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (19) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (20) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (21) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (22) addr: F73C973C
16:31:37:703 3128DetectCureTDL3: IrpHandler (23) addr: F73D0336
16:31:37:703 3128DetectCureTDL3: IrpHandler (24) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (25) addr: 804F4562
16:31:37:703 3128DetectCureTDL3: IrpHandler (26) addr: 804F4562
16:31:37:703 3128KLMD_ReadMem: Trying to ReadMemory 0xF73C6864[0x400]
16:31:37:703 3128TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
16:31:37:703 3128TDL3_FileDetect: Processing driver: atapi
16:31:37:703 3128TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\drivers\atapi.sys
16:31:37:703 3128KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\drivers\atapi.sys
16:31:37:734 3128TDL3_FileDetect: C:\WINDOWS\system32\drivers\atapi.sys - Verdict: Clean
16:31:37:734 3128
16:31:37:734 3128Completed
16:31:37:734 3128
16:31:37:734 3128Results:
16:31:37:734 3128Memory objects infected / cured / cured on reboot:0 / 0 / 0
16:31:37:734 3128Registry objects infected / cured / cured on reboot:0 / 0 / 0
16:31:37:734 3128File objects infected / cured / cured on reboot:0 / 0 / 0
16:31:37:734 3128
16:31:37:734 3128MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
16:31:37:734 3128UtilityDeinit: KLMD(ARK) unloaded successfully
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:

  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done
To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
btw last night...I was recommended by a friend to use Kapersky online scanner...it said I only had 1 threat C:\Documents and Settings\tony\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen1"

so i went thru all my files in outlook and deleted them.....will that be sufficient?

did everthing you asked and here is the request:

Results of screen317's Security Check version 0.99.1
Windows XP Service PACK 3
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall ENABLED!
Avira AntiVir Personal - Free Antivirus
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
CCleaner
WISE Disk Cleaner 4.84
Wise Registry Cleaner 4 Free 4.92
Java(TM) 6 Update 17
Adobe Flash Player 10
Adobe Reader 7.0
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Avira Antivir avgnt.exe
Avira Antivir avguard.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
It should be fine.

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==

Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Firewall
  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.
AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to MAINTAIN protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
See this page for more info about malware and prevention.Jay

thank you so much for all your help and suggestions!
1672.

Solve : riddled with viruses please help?

Answer»

Hi

I would really appreciate someones help PLEASE, i have followed all the steps advised in the top thread and will post the logs. It is my mum-in-laws pc that i am having problems with, i have some knowledge of pc's but more to do with software and hardware. The pc did not have any anti VIRUS software on it and serveral members of the family had access to it, it became riddled with viruses and the background screen changed itself to a green screen with a warning sign that the computer had been infected, it also came up with serveral errors about spywear and TROJANS and one of the family members kept klicking on them! They were unable to access the internet and serveral applications, aswell TASK manager advised that admin had disabled it. After following your steps the background has been sorted and the errors have stopped, however i am still unable to get it back onto the internet. i have also since installed mcafee. would someone be able to help please and check if everything else seems ok from what i have done so far? your help will be greatly appreciated!!! thanks Kel

[Saving space, attachment deleted by admin]Hello kel913.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • R3 - Default URLSearchHook is missing
  • F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
  • O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
  • O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
  • O4 - HKLM\..\Run: [SGPUpdater] C:\Program Files\Search Guard PlusU\sgpUpdaters.exe
  • O4 - HKLM\..\Run: [FBSearch] C:\Program Files\Search Guard Plus\SearchGuardPlus.exe
.
Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

Go to Add or Remove Programs and uninstall:

  • Yontoo Layers Client for Internet Explorer
  • Search Guard Plus
.
----------

A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.

* Please download LSPFix
* Run the LSPFix.exe that you have just finished downloading.
* Check the I know what I'm doing box.
* In the Keep box you should see one or more instances of winhelper86.dll
* Select every instance of winhelper86.dll and move each one to the Remove box by clicking the >> button.
* If the winhelper86.dll file only appears on the right side then just click fix checked and close the program.
* When you are done click Finish>>

Is the connection back? If not continue to the next step.

----------

Download and run WinSockFix
This is a two step process that will Back up the Registry and Reset the Winsock Stack.

  • Double click on WinsockXPFix.exe to open.
  • On the Winsock and TCP Repair Utility screen, click "ReG-Backup"
  • On the ERDNT Welcome screen, click "OK".
  • On the Backup to: screen, click "OK".
  • On the Folder does not exist question screen click "Yes".
  • You will see a status screen as your registry is being backed up.
  • On the Registry backup is complete! screen, click "OK" and you will go back to the main window.
  • On the Winsock and TCP Repair Utility screen, click "Fix".
  • On the Apply the VB_Winsock fix? screen click "Yes".
  • The screen will display a status message "repair completed please reboot."
  • On the Repair Completed screen click "OK" to reboot your computer.
  • If your computer was not using DHCP, you will need to reconfigure TCP/IP.
  • Hopefully you should have connectivity restored.
.
Note: Resetting the Winsock in SP2 might remove third-party LSPs and restores Winsock to factory default setting. Existing programs that uses their own LSPs may need to be reinstalled. Example: Google Desktop Search.

Is the connection back? If not continue to the next step.

----------

Go Start > Run and type in:cmd then click OK

In the Command Prompt window type in following commands, and press Enter after each one:

Code: [Select]ipconfig /flushdnsCode: [Select]ipconfig /registerdnsCode: [Select]ipconfig /releaseCode: [Select]ipconfig /renew
Note the space before the forward slash /

Restart the computer.

Is the connection back?

Continue to the next step if it is or isn't and let me know in the next post.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix

Thank you so much for your help. I followed all the instructions and regained access to the internet after the first fix so i did not try the other two and moved straight to the combofix, after the combofix had finished and i had save the log the following error POPPED up in task bar:

Windows delayed write failed windows was unable to save all the data fot the file \...\DP(1)0-0+5. The data has been lost. this error may have been caused by a failure of the computer hardware or network connection. please try to save this file elsewhere.

I havent touched the laptop since, i will just wait for your reply. i have attached the combofix logs as requested! thank you so much again for your help. Kel

[Saving space, attachment deleted by admin]1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
dhexq


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Please go to Start > Run and copy/paste the following blue text, then press Enter:

C:\QooBox\Add-Remove Programs.txt

A text file should open. Please post the contents of that file in your next reply.

----------All done there didnt seem to be any problems this time, have posted logs as requested! thanks so much again for your help! Kel

[Saving space, attachment deleted by admin]Go to Add or Remove Programs and uninstall:

  • Viewpoint Media Player

----------

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Log
Hi, thanks for that, i have completed all the above steps however when the eset antivirus was scanning it threw up serveral boxes of details of the trojans it had deleted (about 10 Id say), but it only gave me an option to delete the messages or close them, i closed them thinking that it would give me a full report at the end but at the end it said no viruses detected and only gave me a finish option?! So i dont kno if i had done something wrong? so i dont have the logs for you sorry, do you want me to run it again? thanks v much Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayHello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayThanks for you help but I'm trying to fix the laptop for a family member so am hoping to use free software, it's not my place to buy any software for the laptop so if as a last resort evilfantasy says the only way to fix it is to buy some software then I will leave it up to them to deal with that. Thanks Hi.

Please disregard any advice given except from me.

Did you download ESET or run the online scanner?

Try this.

Scan your computer with Panda ActiveScan

* Once you are on the Panda site click the Scan your PC now button.
* A new window will open...click the Scan Now button.
* If it wants to install an ActiveX component allow it.
* It will start downloading the files it requires for the scan. (Note: It may take a couple of minutes)
* You may get a warning from Internet Explorer that Panda is ready to install, please allow it.
* The scan will begin. Please be patient as it can take an hour or more to complete.
* When the scan completes, if anything malicious is detected, click the Export to: button (looks like a little Notepad).
* Save the ActiveScan.txt to a convenient location like your desktop.
* Note: You do not need to select any of the Disinfect options. We will remove any threats manually.

* Post the contents of the ActiveScan report in your next reply.

Thanks I ran the ESET online scanner

I have ran the Panda scanner now and attached logs! Thanks V much

[Saving space, attachment deleted by admin]Looks good. How is the computer running now?

Disable/Enable the System Restore Utility to flush old infected restore points

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hey, i have completed all of the above! the laptop is running great now, seems to be no more problems! i cant thank you enough for your help! it is really appreciated! Your welcome.

Safe surfing...
1673.

Solve : C:\windows\system32\sshnas21.dll infected, Trojan Horse?

Answer»

Hello!

AVG is telling me that my C:\Windows\System32\sshnas21.dll is infected with Trojan horse PSW.Generic7.BGKK, and that it cannot be removed.

Any help would be appreciatedThat's a malicious file and there are likely others.

Start here and post the 3 logs when complete.All steps completed, here are the logs!

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/04/2010 at 10:55 AM

Application Version : 4.33.1000

Core Rules Database Version : 4552
Trace Rules Database Version: 2364

Scan type : Complete Scan
Total Scan Time : 11:14:47

Memory items scanned : 765
Memory threats detected : 3
Registry items scanned : 6288
Registry threats detected : 1
File items scanned : 67848
File threats detected : 14

Trojan.Agent/Gen-SSHNas[FakeAlert]
C:\WINDOWS\SYSTEM32\SSHNAS21.DLL
C:\WINDOWS\SYSTEM32\SSHNAS21.DLL

Trojan.Dropper/Win-NV
C:\WINDOWS\MSA.EXE
C:\WINDOWS\MSA.EXE

Trojan.Agent/Gen-CDesc[NewF]
C:\USERS\VEGAR\APPDATA\LOCAL\TEMP\WFX.EXE
C:\USERS\VEGAR\APPDATA\LOCAL\TEMP\WFX.EXE
[BMIMZMHMFM] C:\USERS\VEGAR\APPDATA\LOCAL\TEMP\WFX.EXE

Adware.Tracking Cookie
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Vegar\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt


--------------------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.44
Database version: 3688
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

04.02.2010 15:51:30
mbam-log-2010-02-04 (15-51-30).txt

Scan type: Quick Scan
Objects scanned: 100705
Time elapsed: 16 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\BMIMZMHMFM (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

--------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:52:29, on 04.02.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ASUS\Asus WebStorage\BackupService.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EeeStorageBackup] C:\Program Files\ASUS\Asus WebStorage\BackupService.exe
O4 - HKLM\..\Run: [liveUpdate] AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [HotKeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxExt] C:\windows\system32\IgfxExt.exe /RegServer
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETTVERKSTJENESTE')
O4 - Global Startup: HotKeyMon.lnk = C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blogg dette - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blogg dette i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

--
End of file - 7023 bytes

If you already have ComboFix be sure to DELETE it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, ETC) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixHere is the Combofix-log:

ComboFix 10-02-04.01 - Vegar 04.02.2010 22:32:22.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.47.1044.18.2038.1085 [GMT 1:00]
Kjører fra: c:\users\Vegar\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\temp
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HotKeyMon.lnk
c:\windows\system32\Thumbs.db

Infisert kopi av c:\windows\system32\DRIVERS\atapi.sys ble funnet og desinfisert [translation: Infected copy of c:\...\atapi.sys was found and disinfected]
Gjenopprettet kopi fra - c:\combofix\HarddiskVolumeShadowCopy2_!Windows!System32!drivers!atapi.sys [translation: restored copy from - c:\...]
.
((((((((((((((((((((((((((( Filer Opprettet Fra 2010-01-04 til 2010-02-04 )))))))))))))))))))))))))))))))))
.

2010-02-04 21:46 . 2010-02-04 21:46--------d-----w-c:\users\Default\AppData\Local\temp
2010-02-04 21:46 . 2010-02-04 21:48--------d-----w-c:\users\Vegar\AppData\Local\temp
2010-02-04 18:38 . 2010-02-04 18:38--------d-----w-c:\program files\Trend Micro
2010-02-04 16:21 . 2010-02-04 16:21--------d-----w-C:\JavaRa
2010-02-04 16:16 . 2010-02-04 16:16--------d-----w-c:\program files\Common Files\Java
2010-02-04 16:10 . 2010-02-04 16:09411368----a-w-c:\windows\system32\deploytk.dll
2010-02-04 16:09 . 2010-02-04 16:09--------d-----w-c:\program files\Java
2010-02-04 14:27 . 2010-02-04 14:27--------d-----w-c:\users\Vegar\AppData\Roaming\Malwarebytes
2010-02-04 14:26 . 2010-01-07 15:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-04 14:26 . 2010-02-04 14:26--------d-----w-c:\programdata\Malwarebytes
2010-02-04 14:26 . 2010-01-07 15:0719160----a-w-c:\windows\system32\drivers\mbam.sys
2010-02-04 14:26 . 2010-02-04 14:26--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-02-03 22:23 . 2010-02-03 22:2352224----a-w-c:\users\Vegar\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-03 22:22 . 2010-02-03 22:22117760----a-w-c:\users\Vegar\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-03 22:19 . 2010-02-03 22:19--------d-----w-c:\programdata\SUPERAntiSpyware.com
2010-02-03 22:18 . 2010-02-03 22:18--------d-----w-c:\program files\SUPERAntiSpyware
2010-02-03 22:17 . 2010-02-03 22:18--------d-----w-c:\users\Vegar\AppData\Roaming\SUPERAntiSpyware.com
2010-02-03 22:15 . 2010-02-03 22:15--------d-----w-c:\program files\Common Files\Wise INSTALLATION Wizard
2010-02-03 22:02 . 2010-02-03 22:02--------d-----w-c:\program files\CCleaner
2010-02-03 21:03 . 2010-02-03 21:03691696----a-w-c:\windows\system32\drivers\sptd.sys
2010-02-03 21:00 . 2010-02-04 10:00--------d-----w-c:\program files\DAEMON Tools Lite
2010-02-03 21:00 . 2010-02-04 21:07--------d-----w-c:\users\Vegar\AppData\Roaming\DAEMON Tools Lite
2010-02-03 21:00 . 2010-02-03 21:00--------d-----w-c:\programdata\DAEMON Tools Lite
2010-02-03 20:31 . 2010-02-03 20:32--------d-----w-C:\OFFICE
2010-02-03 11:38 . 2010-02-03 11:38--------d-----w-c:\users\Vegar\AppData\Local\Diagnostics
2010-02-03 06:26 . 2010-01-30 21:14--------d-----w-C:\Microsoft Office 2007
2010-02-02 21:35 . 2010-02-03 06:30--------d-----w-c:\users\Vegar\Nedlastinger
2010-02-02 21:32 . 2010-02-02 21:32175----a-w-c:\users\Vegar\AppData\Roaming\Azureus\restart.bat
2010-02-02 21:27 . 2010-02-02 21:27--------d-----w-c:\programdata\Azureus
2010-02-02 21:27 . 2010-02-03 20:30--------d-----w-c:\users\Vegar\AppData\Roaming\Azureus
2010-02-02 21:24 . 2010-02-03 20:31--------d-----w-c:\program files\Vuze
2010-02-02 21:24 . 2010-02-02 21:24--------d-----w-c:\program files\Common Files\i4j_jres
2010-02-02 21:07 . 2010-02-03 06:45--------d-----w-C:\$AVG
2010-02-02 21:07 . 2010-02-02 21:0712464----a-w-c:\windows\system32\avgrsstx.dll
2010-02-02 21:07 . 2010-02-02 21:07360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2010-02-02 21:07 . 2010-02-02 21:07333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2010-02-02 21:07 . 2010-02-02 21:0728424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2010-02-02 21:07 . 2010-02-04 16:55--------d-----w-c:\windows\system32\drivers\Avg
2010-02-02 21:07 . 2010-02-02 21:07--------d-----w-c:\program files\AVG
2010-02-02 21:07 . 2010-02-02 21:07--------d-----w-c:\programdata\avg9
2010-02-02 20:59 . 2010-01-14 10:12181120------w-c:\windows\system32\MpSigStub.exe
2010-01-31 12:33 . 1999-03-06 11:386144----a-w-c:\windows\system32\drivers\ASUSHWIO.SYS
2010-01-31 12:24 . 2009-09-10 05:52257024----a-w-c:\windows\system32\msv1_0.dll
2010-01-31 12:07 . 2009-10-29 07:222048----a-w-c:\windows\system32\tzres.dll
2010-01-30 23:35 . 2010-02-01 23:20--------d-----w-c:\program files\Microsoft Silverlight
2010-01-30 23:35 . 2009-08-05 21:4854632----a-w-c:\windows\system32\drivers\fssfltr.sys
2010-01-30 22:55 . 2010-02-03 17:08--------d-----w-c:\users\Vegar\Tracing
2010-01-30 22:55 . 2010-01-30 22:55--------d-----w-c:\users\Vegar\AppData\Local\Windows Live Writer
2010-01-30 22:55 . 2010-01-30 22:55--------d-----w-c:\users\Vegar\AppData\Roaming\Windows Live Writer
2010-01-30 20:48 . 2009-10-31 05:452614272----a-w-c:\windows\explorer.exe
2010-01-30 20:48 . 2009-10-28 06:17285696----a-w-c:\windows\system32\winlogon.exe
2010-01-30 20:48 . 2009-08-29 06:5734816----a-w-c:\windows\system32\msasn1.dll
2010-01-30 20:48 . 2009-10-02 04:06728648----a-w-c:\windows\system32\drivers\dxgkrnl.sys
2010-01-30 20:48 . 2009-09-03 07:041320960----a-w-c:\windows\system32\CertEnroll.dll
2010-01-30 20:48 . 2009-08-19 07:20507568----a-w-c:\windows\system32\winload.exe
2010-01-30 20:48 . 2009-08-19 07:20442920----a-w-c:\windows\system32\winresume.exe
2010-01-30 20:48 . 2009-08-29 06:5412625408----a-w-c:\windows\system32\wmploc.DLL
2010-01-30 20:47 . 2009-10-19 14:10108544----a-w-c:\windows\system32\t2embed.dll
2010-01-30 20:47 . 2009-10-19 14:1070656----a-w-c:\windows\system32\fontsub.dll
2010-01-30 20:47 . 2009-07-30 04:44293888----a-w-c:\windows\system32\atmfd.dll
2010-01-30 20:45 . 2009-12-19 09:02977920----a-w-c:\windows\system32\wininet.dll
2010-01-30 20:28 . 2010-01-30 20:28--------d-----w-c:\users\Vegar\AppData\Local\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 20:32 . 2009-07-14 04:52--------d-----w-c:\program files\Windows Sidebar
2010-02-02 20:32 . 2009-07-14 02:37--------d-----w-c:\program files\Windows Mail
2010-02-02 20:32 . 2009-07-14 04:52--------d-----w-c:\program files\Windows Photo Viewer
2010-02-02 20:32 . 2009-07-14 07:49--------d-----w-c:\program files\Windows Journal
2010-02-02 20:32 . 2009-07-14 04:52--------d-----w-c:\program files\Windows Defender
2010-02-02 20:31 . 2009-07-14 04:52--------d-----w-c:\program files\DVD Maker
2010-02-02 17:37 . 2009-06-20 18:5574124----a-w-c:\windows\system32\perfc014.dat
2010-02-02 17:37 . 2009-06-20 18:55448210----a-w-c:\windows\system32\perfh014.dat
2010-02-02 06:12 . 2009-12-25 10:0379136----a-w-c:\users\Vegar\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-01 16:32 . 2009-08-31 14:13--------d-----w-c:\programdata\Microsoft Help
2010-01-31 12:22 . 2009-08-31 14:15--------d-----w-c:\program files\Microsoft Works
2010-01-30 23:34 . 2009-12-25 10:10--------d-----w-c:\program files\Windows Live
2009-12-25 10:14 . 2009-12-25 10:10--------d-----w-c:\program files\Microsoft
2009-12-25 10:13 . 2009-12-25 10:13--------d-----w-c:\program files\Microsoft Sync Framework
2009-12-25 10:12 . 2009-12-25 10:12--------d-----w-c:\program files\Microsoft SQL Server Compact Edition
2009-12-25 10:10 . 2009-12-25 10:10--------d-----w-c:\program files\Windows Live SkyDrive
2009-12-25 10:07 . 2009-12-25 10:07--------d-----w-c:\program files\Common Files\Windows Live
2009-06-10 21:26 . 2009-07-14 02:049633792--sha-r-c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42396800--sha-w-c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension1]
@="{fe25455d-b4c2-4e32-97d2-92632ec1c224}"
[HKEY_CLASSES_ROOT\CLSID\{fe25455d-b4c2-4e32-97d2-92632ec1c224}]
2009-06-10 21:23278864----a-w-c:\windows\System32\mscoree.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension2]
@="{1fae2d88-a78e-4f03-909f-be818a3c1ce6}"
[HKEY_CLASSES_ROOT\CLSID\{1fae2d88-a78e-4f03-909f-be818a3c1ce6}]
2009-06-10 21:23278864----a-w-c:\windows\System32\mscoree.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-08-25 402608]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-20 1545512]
"HotkeyService"="AsusSender.exe" [2009-09-11 33768]
"SuperHybridEngine"="AsusSender.exe" [2009-09-11 33768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"EeeStorageBackup"="c:\program files\ASUS\Asus WebStorage\BackupService.exe" [2009-07-31 947472]
"LiveUpdate"="AsusSender.exe" [2009-09-11 33768]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-07-20 83240]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248]
"HotKeyMon"="AsusSender.exe" [2009-09-11 33768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-10-15 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-10-15 354840]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SRS Premium Sound.lnk - c:\windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe [2009-8-31 156880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [02.02.2010 22:07 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\drivers\avgtdix.sys [02.02.2010 22:07 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05.01.2010 07:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.01.2010 07:56 74480]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\System32\drivers\vwififlt.sys [14.07.2009 00:52 48128]
R2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [31.08.2009 15:09 219136]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [02.02.2010 22:07 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [02.02.2010 22:07 285392]
R3 igd;igd;c:\windows\System32\drivers\igdkmd32.sys [10.10.2009 09:04 635552]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\System32\drivers\L1C62x86.sys [18.08.2009 14:24 51712]
S3 fssfltr;fssfltr;c:\windows\System32\drivers\fssfltr.sys [31.01.2010 00:35 54632]
S3 fsssvc;Windows Live Tryggere for familien-tjenesten;c:\program files\Windows Live\Family Safety\fsssvc.exe [05.08.2009 22:48 704864]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05.01.2010 07:56 7408]
S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [03.02.2010 22:03 691696]
.
.
------- Tilleggsskanning -------
.
uStart Page = hxxp://asus.msn.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Vegar\AppData\Roaming\Mozilla\Firefox\Profiles\9qgas2eo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.startsiden.no/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut. enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi n", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - TOMME PEKERE FJERNET - - - -

Toolbar-Locked - (no file)
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe


.
--------------------- LÅSTE REGISTERNØKLER ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

- - - - - - - > 'Explorer.exe'(5348)
c:\program files\ASUS\Asus WebStorage\LogicNP.EZShellExtensions.dll
c:\windows\assembly\GAC_32\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll
.
------------------------ Andre Kjørende Prosesser ------------------------
.
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\windows\system32\conhost.exe
c:\program files\Asus\LiveUpdate\LiveUpdate.exe
c:\program files\EeePC\HotkeyService\HotkeyService.exe
c:\program files\EeePC\SHE\SuperHybridEngine.exe
c:\program files\EeePC\HotkeyService\HotKeyMon.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Tidspunkt ferdig: 2010-02-04 22:53:38 - maskinen ble startet på nytt
ComboFix-quarantined-files.txt 2010-02-04 21:53

Pre-Run: 82390867968 byte ledig
Post-Run: 82298265600 byte ledig

- - End Of File - - CE42D1426E38CAF7B033CA8EDCAC9AE0
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.This is the resulting log:

Results of screen317's Security Check version 0.99.1
Windows 7 (UAC is enabled)
``````````````````````````````
Antivirus/Firewall Check:

AVG Free 9.0
WMIC entry does not exist for antivirus; attempting automatic update.
``````````````````````````````
Anti-malware/Other Utilities Check:

SUPERAntiSpyware Free Edition
CCleaner
Java(TM) 6 Update 18
Java Auto Updater
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 9.1 MUI
``````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
AVG avgemc.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
Looks good.

If there are no more malware issues we can finish up now.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.

* Click START then RUN
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter.

The above procedure will:
* Delete: ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Secunia Software Inspector to check for out of date software.

* Click Start Now
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very much Your welcome.

Safe surfing...

1674.

Solve : Application cannot be executed. The file "" is infected. HALPHALPHALP?

Answer»

I need help getting rid of this virus/malware/rogue. It's ruining my life.ok a couple of questions to get a clearer IDEA of the problem

do you have anti-virus software installed?
if so what program?
is it up to date?
when does this message appear, on STARTUP (GUI) or on trying to access a specific file?
does this appear when you boot into safe mode in windows? (if not use msconfig or windows defenders "software explorer" to disable 3rd party applications from STARTING at system boot and re-enable one at a time until you encounter this error again).
ALTERNATIVELY if you know what program this error is referring to try to repair the installation to see if that does anything OR un-install then re-install the program.

try malwarebytes anti-malware OR spybot search & destroy to scan for malware etc. See if they find anything. If you need anti-virus there are plenty of programs out there (free and subscription). I'm no security expert but i don't think there's much of a DIFFERENCE between the free one(s) and pay-for-use anti-virus programs.that sounds really familiar. sounds like "internet Security 2010" infections. its a tricky one but running combofix can really give you a good start. here is a tutorial on how to use it
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
maybe after thats done i suggest a malwarebytes scan with eset online scan. keep posting

1675.

Solve : Virus Concern?

Answer»

Hi Jay. I will most certainly update this PC and unload and make sure that the programs that you SUGGESTED are used. I can't thank you enough for your patience ,diligence and expertise in these virus matters. Without your help I don't know where I WOULD have gone or what else I would have done? Sure HOPE that I don't have to bother you again for a long, long time. This was a terrible SITUATION for me but you made it a very LEARNING experience, and I think that you made this whole situation as easy for me as you possibly could have.

Thank you, thank you ,thank you, overthehill You're welcome.

1676.

Solve : Malware - Can't open any program or get online...?

Answer»

I am running Windows XP service pack 3. I have had AVG free, SuperAntiSpyware, Malwarebytes Anti-malware, and CC Cleaner installed on my computer for over a year. They are up-to-date.
However I cannot access any of my programs, nor can I go online with my computer. As soon as my computer is turned on, an antivirus soft icon shows up in my TASKBAR and prevents me from opening any program or file. I get repeated error messages and warnings telling me that my computer is infected and do I want to purchase this antivirus-soft software. I don't. I want to access my own programs, but I am locked out of everything.
Where do I go from here? I don't know how to start my computer in safe-MODE (yes, unfortunately, I AM that ignorant). If you could give me an idea on how to get started, or how to access my own anti-virus programs, I would forever be grateful.
Thank you so very much in advance.
DeniseHello, your comment has been removed. Please do not post malware ADVICE, or post here in the malware forum, unless you need help. ~ DragonMaster JaySituation now more drastic.

Cannot boot up the computer. This is what I get when I turn it on:

The option for xp recovery console or microsoft windows professional. It automatically starts with microsoft windows professional. After a few seconds the following choices are given: boot up in Safe Mode
Safe Mode with Networking
Safe Mode with Command Prompt
Last Known Good Configuration
Start Windows Normally

Choosing ANY one of those puts me right back into the xp recovery console or microsoft windows professional screen.

The computer never boots up. I am caught in a vicious vortex. What now?

Help!!!!!Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayHello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayHello agnostida, and welcome to CH!

These are links to Anti-virus vendors that offer free LiveCD or Rescue CD files that are used to boot from for repair of unbootable and damaged systems, rescue data, scan the SYSTEM for virus infections. Burn it as an image to a disk to get a bootable CD. All (except Avira) are in the ISO Image file format. Avira uses an EXE that has built-in CD burning capability.

If you are not sure how to burn an image, please read How to write a CD/DVD image or ISO. If you need a FREE utility to burn the ISO image, download and use ImgBurn.

Let me know how it goes.Thank you so very much for your help!

So, I took a look at the programs you suggested and then decided that this endeavor was beyond me. Actually, I would have given it a go had there not been data on my computer that I very much did not want to lose. I'll have to start backing up more than twice a month!

I took my laptop in to a local place and they were able to save my data by removing my hard drive and doing a voodoo dance, or whatever it is that needs to be done with these things. You would know more than I. The virus has been removed and the laptop restored to factory settings, which in itself is a pain, since the factory settings are now years out-of-date and were glitchy to begin with. So I probably will be back lurking in the different FORUMS trying to figure out how to de-bug and clean-up things like my start-up, etc...

But thank you for taking the time to help - it really was a help - I was able to make a decision based on the information, and that in itself, was invaluable.

You all are the greatest!!!!!Ok
1677.

Solve : Adware.Zango?

Answer»

I can't SEEM to duplicate it. I have MBAM on with IP protection and it's not happening here. STRANGE.I have had no more IP's blocked. I wonder if it had summit to do with the update of MBt's.
not sure, but yes strange, thanks for the help with the other problems i had. PC is working sound. It's 2 in the morning here in ENG so it's time for sum zzzzzzzzz's

cheers EFYour welcome.

Safe surfing...

1678.

Solve : corrupted exes (control.exe mmc.exe)?

Answer»

I don't know what virus I have, but every time I try to open the Add/Remove Programs it tells me that control.exe can't be opened. I ran Malwarebytes, it removed something called cleansweep, and I thought the problem was gone. Later on when I attempted to follow an online guide for modifying Remote Desktop (this took place after I realized something wasn't right with my computer, so its not the catalyst), I tried to open gpedit.msc and it told me that mmc.exe was missing a dll (MRoD.dll). I tested control.exe again, and that is also not working. So, I don't have any issue with pop ups or programs forcing me to buy them, but a whole bunch of essential exes dont seem to work right. Any insight as to what this is?

[Saving space, attachment deleted by admin]Hi.

Hopefully you can figure out a way to subscribe to this topic. A a BMN user you shouldn't add your email to your profile and therefore can't get the updates when I reply. I reply I would hope you are getting a notice so I don't end up wasting my time. It would be better if you created an account. This is a secure forum and we do not spam whatsoever. Besides using an open account isn't very secure IMHO.

Let me know what you think.
Hey, thanks for the reply. I did create an account because I do find myself in need of malware assistance every so often.Thank you.

If you already have Malwarebytes be sure to update it before running the scan!

Download Malwarebytes' Anti-Malware (MBAM)

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to the following:

* Update Malwarebytes' Anti-Malware
* Launch Malwarebytes' Anti-Malware

* Then click Finish
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy and Paste the entire report in your next reply.

Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.

----------

Next post please add:

  • Malwarebytes log
  • Both DDS logs
Malwarebytes' Anti-Malware 1.44
Database version: 3717
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/10/2010 11:43:48 AM
mbam-log-2010-02-10 (11-43-47).txt

Scan type: Full Scan (C:\|)
Objects scanned: 321688
Time elapsed: 3 hour(s), 40 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/10/2003 10:48:56 AM
System Uptime: 2/7/2010 10:56:50 PM (46 hours ago)

Motherboard: Compaq | | 07E4h
Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | XU1 PROCESSOR | 2657/533mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 233 GiB total, 118.968 GiB free.
E: is CDROM ()
G: is CDROM ()
H: is FIXED (NTFS) - 932 GiB total, 670.86 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/100 VM Network Connection
Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0
Manufacturer: Intel
Name: Intel(R) PRO/100 VM Network Connection
PNP Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0
Service: E100B

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================


7-Zip 4.65
AAC Decoder
ACID Pro 7.0
AcronisMigrateEasy
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 9.2
Adobe Shockwave Player 11.5
Advertising Center
AllToAVI v4 r5394
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaImpression
ArcSoft PhotoImpression 5
ArcSoft VideoImpression 2
Ares 2.1.2
Aspell English Dictionary-0.50-2
AutoUpdate
AVG 9.0
AviSynth 2.5
BitTyrant
Bonjour
Calculator Powertoy for Windows XP
CamStudio
CamStudio Lossless Codec
CCleaner
Combined Community Codec Pack 2009-09-09
DC++ 0.750
Dev-C++ 5 beta 9 release (4.9.9.2)
Digital Camera
DivX Codec
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
DolbyFiles
DVD Flick 1.3.0.7
DVD Shrink 3.2
EA Download Manager
EA Download Manager UI
Fiesta
FreeMind
GIMP 2.6.7
GNU Aspell 0.50-3
GTK+ Runtime 2.14.7 rev a (remove only)
GUI Design Studio 3.6.95.0
Guifications Plugin (remove only)
H.264 Decoder
HandBrake 0.9.3
High-Logic FontCreator 6.0
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
HP Standard Port Monitor
HyperCam 2
Image Resizer Powertoy for Windows XP
Intel(R) Extreme Graphics Driver
Intel(R) PRO Ethernet Adapter and Software
InterVideo DeviceService
iPodRip
iTunes
Java 2 Runtime Environment, SE v1.4.0_01
Java Web Start
Java(TM) 6 Update 3
Kazaa Lite K++ v2.4.3
KeyScrambler
LogMeIn Hamachi
Malwarebytes' Anti-Malware
MapleStory
MediaCoder 0.6.1
MEGA-DSC
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office XP Professional with FrontPage
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft WSE 3.0 Runtime
Miro
MKV Splitter
MKVtoolnix 2.9.8
Mozilla Firefox (3.5.7)
MUSTEK 1200 UB v2.1
Nero ControlCenter
Nero Installer
Nero Suite
NETGEAR WG111v2 wireless USB 2.0 adapter
Notepad++
Orbit
PeerGuardian 2.0
Pidgin
Pokemon PC 2.0
Project64 1.6
PurgeFox - 4.01
QuickTime
RGSS-RTP Standard
RPG Maker 2000 1.05
RPG Maker 2003 v1.08
RPG Maker VX 1.02
RPG Maker VX RTP
RPG Maker XP - Postality Knights Edition ENHANCED
RTP 1.32 Add-On for RM2k
RTP de RPG Maker 2003
RTP for RM2K (Png, Wav, Midi, Fonts)
save2pc Pro 3.51
Scenario RPGMaker 2003
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB972270)
Smart Install Maker 5.02
SoulSeek 157 NS 13e
SoundMAX
SUPER © Version 2009.bld.36 (June 10, 2009)
SUPERAntiSpyware Professional
TES Construction Set
The Sims™ 3
Torrent Searcher 9.0
TreeSize Free V2.3.3
TrueCrypt
Tweak UI
Unlocker 1.8.8
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976749)
VC80CRTRedist - 8.0.50727.4053
Videora iPod classic Converter 5.03
Videora Trial Version 2.15
VirtualDubMOD 1.5.10.3 US
VLC media player 1.0.3
VMware ThinApp
VobSub v2.23 (Remove Only)
Vuze
WebFldrs XP
Window Washer
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Support Tools
Windows XP Service Pack 3
WinFF 1.0.4
WinPcap 4.0
Xvid 1.2.2 final uninstall
XviD4PSP 5.0
Yahoo! Install Manager
Yahoo! Widgets

==== Event Viewer Messages From Past Week ========

2/9/2010 7:39:08 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer MOMLUVSDAD that believes that it is the master browser for the domain on transport NetBT_Tcpip_{5874CD5F-02BD-4F2. The master browser is stopping or an election is being forced.
2/9/2010 1:42:37 PM, information: Windows File Protection [64004] - The protected system file termsrv.dll could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ].
2/7/2010 4:45:01 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/7/2010 4:41:57 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm SASDIFSV SASKUTIL truecrypt
2/7/2010 4:41:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/7/2010 10:18:22 PM, error: NetDDE [206] - Listen failed: 15:
2/7/2010 10:18:02 PM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.
2/5/2010 7:02:51 AM, error: PSched [14103] - QoS [Adapter {5874CD5F-02BD-4F2C-8B14-55138A3A0C42}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
2/5/2010 11:57:12 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: After starting, the service hung in a start-pending state.
2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Fast User Switching Compatibility service depends on the Terminal Services service which failed to start because of the following error: After starting, the service hung in a start-pending state.
2/5/2010 11:57:12 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/5/2010 11:50:40 PM, error: Service Control Manager [7000] - The npkcrypt service failed to start due to the following error: The system cannot find the path specified.
2/5/2010 1:24:33 PM, error: Service Control Manager [7034] - The Capture Device Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:32 PM, error: Service Control Manager [7034] - The Window Washer Engine service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:30 PM, error: Service Control Manager [7034] - The StarWind iSCSI Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:29 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:27 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:25 PM, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:20 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE DSDM service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:24:16 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective ACTION (Restart the service) after the unexpected termination of the Windows Media Player Network Sharing Service service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The LogMeIn Hamachi 2.0 Tunneling Engine service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The B's Recorder GOLD Library General Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:18 PM, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:15 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/5/2010 1:23:12 PM, error: Service Control Manager [7034] - The AVG E-mail Scanner service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:11 PM, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
2/5/2010 1:23:11 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/4/2010 11:03:49 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
2/4/2010 11:02:52 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/3/2010 5:49:46 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0023C32129DA. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
2/3/2010 5:49:09 AM, error: Service Control Manager [7000] - The LogMeIn Hamachi 2.0 Tunneling Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/3/2010 5:49:08 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LogMeIn Hamachi 2.0 Tunneling Engine service to connect.
2/3/2010 1:34:15 PM, error: Srv [2011] - The server's configuration parameter "irpstacksize" is too small for the server to use a local device. Please increase the value of this parameter.

==== End Of File ===========================





DDS (Ver_09-12-01.01) - NTFSx86
Run by Alex at 20:24:37.98 on Tue 02/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.66 [GMT -5:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Alex\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uInternet Settings,ProxyServer = 83.133.119.38:8080
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: CKeyScramblerBHO Object: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe
mRun: [DrvLsnr] "c:\program files\analog devices\soundmax\DrvLsnr.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Download All with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_all.htm
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Download with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_link.htm
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: Download FLV video content with IDM - c:\documents and settings\Alex\my documents\random junk\programs\internet download manager\IEGetVL.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37868.274537037
DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_01-win.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\Alex\applic~1\mozilla\firefox\profiles\um5wf9ps.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2009-12-30 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-12-30 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-30 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-30 28424]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-30 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-12-30 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-12-30 285392]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-12-30 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-12-30 5832712]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-12-3 236368]
R2 StarWindService;StarWind iSCSI Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-1 217600]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-12-30 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-12-30 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-12-30 25736]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2007-8-9 113896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-12-3 19160]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-12-12 272128]
R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [2007-8-8 223128]
S0 gxal;gxal;c:\windows\system32\drivers\naaajasa.sys --> c:\windows\system32\drivers\naaajasa.sys [?]
S2 PowerManager;Power Manager;c:\windows\svchost.exe --> c:\windows\svchost.exe [?]
S3 aic32p;aic32p;\??\c:\windows\system32\drivers\ipfmpo.sys --> c:\windows\system32\drivers\ipfmpo.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104]
S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [2001-1-2 19677]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [2007-12-8 15104]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [2009-11-29 627072]
S3 XDva281;XDva281;\??\c:\windows\system32\xdva281.sys --> c:\windows\system32\XDva281.sys [?]

=============== Created Last 30 ================

2010-02-09 19:20:170d-----w-c:\program files\Trend Micro
2010-02-05 18:21:230d-----w-c:\docume~1\Alex\applic~1\Subversion
2010-02-05 18:19:320d-----w-c:\program files\GUI Design Studio
2010-02-03 10:47:380d-----w-c:\program files\LogMeIn Hamachi
2010-01-29 21:12:580d-----w-C:\ProgramData
2010-01-29 21:12:580d-----w-c:\docume~1\alluse~1\applic~1\Electronic Arts
2010-01-29 21:08:44447752----a-r-c:\windows\system32\vp6vfw.dll
2010-01-29 21:08:400d-----w-c:\program files\Microsoft WSE
2010-01-28 04:50:2222297----a-w-c:\documents and settings\Alex\.recently-used.xbel
2010-01-27 01:03:390d-----w-c:\docume~1\alluse~1\applic~1\Kazaa
2010-01-27 00:27:380d-----w-c:\docume~1\Alex\applic~1\Kazaa Lite
2010-01-27 00:27:330d-----w-c:\program files\Kazaa Lite K++
2010-01-26 23:56:470d-----w-C:\My Shared Folder
2010-01-26 23:56:460d-----w-c:\program files\Torrent Searcher 9.0
2010-01-26 07:27:29766----a-w-c:\windows\DSC.ico
2010-01-26 07:27:297431----a-w-c:\windows\Tw504b.src
2010-01-26 07:27:2965536----a-w-c:\windows\PCCam.exe
2010-01-26 07:27:29515803----a-w-c:\windows\system32\drivers\CA504bv.sys
2010-01-26 07:27:2919456----a-w-c:\windows\system32\Dext504b.ax
2010-01-26 07:27:2914381----a-w-c:\windows\Tw504b.ini
2010-01-26 07:27:29131072----a-w-c:\windows\system32\SP5X_32.DLL
2010-01-26 07:27:2910986----a-w-c:\windows\system32\drivers\Bulk504b.sys
2010-01-26 07:27:290d-----w-c:\windows\MEGA-DSC
2010-01-25 10:58:18479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-24 17:23:470d-----w-c:\program files\Pidgin
2010-01-24 17:23:030d-----w-c:\program files\common files\GTK
2010-01-24 07:39:240d-----w-c:\docume~1\Alex\applic~1\NetMedia Providers
2010-01-24 06:51:350d-----w-c:\program files\Vstplugins
2010-01-24 06:51:040d-----w-c:\program files\Sony
2010-01-24 06:44:500d-----w-c:\program files\Sony Setup
2010-01-14 06:34:290d-----w-c:\program files\Yahoo!
2010-01-12 22:40:560d-----w-c:\docume~1\Alex\applic~1\AVG9
2010-01-11 02:34:120d-----w-c:\docume~1\alluse~1\applic~1\Azureus
2010-01-11 02:33:440d-----w-c:\docume~1\Alex\applic~1\Azureus
2010-01-11 02:28:530d-----w-c:\program files\Vuze

==================== Find3M ====================

2010-01-07 21:07:1438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:0419160----a-w-c:\windows\system32\drivers\mbam.sys
2009-12-30 20:51:3425608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys
2009-12-30 20:51:3412464----a-w-c:\windows\system32\avgrsstx.dll
2009-12-30 20:51:33360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-12-30 20:51:33161800----a-w-c:\windows\system32\drivers\avgrkx86.sys
2009-12-30 20:51:24333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-12-30 20:49:1850968----a-w-c:\windows\system32\avgfwdx.dll
2009-12-30 20:49:1830104----a-w-c:\windows\system32\drivers\avgfwdx.sys
2009-12-30 09:22:29223440----a-w-c:\windows\system32\drivers\truecrypt.sys
2009-12-21 19:14:05916480----a-w-c:\windows\system32\wininet.dll
2009-12-20 06:06:3979416----a-w-c:\windows\fonts\Becker-Bold.ttf
2009-12-20 06:06:3955432----a-w-c:\windows\fonts\Becker_Bold.ttf
2009-12-13 17:02:5992594----a-w-c:\windows\fonts\CCWiccanSansInt-Regular.PFB
2009-12-13 17:01:5848972----a-w-c:\windows\fonts\CCAltogetherOoky-Capitals.ttf
2009-12-13 17:00:5860835----a-w-c:\windows\fonts\CCExterminate-AllOfThem.PFB
2009-12-13 16:59:5845876----a-w-c:\windows\fonts\CCCutthroatInt-Regular.ttf
2009-12-12 22:46:1221035----a-w-c:\windows\system32\drivers\AegisP.sys
2009-12-09 18:57:52306688----a-w-c:\windows\IsUninst.exe
2009-12-08 23:33:172554----a-w-c:\windows\system32\tmp.reg
2009-12-08 20:48:01380928----a-w-c:\windows\SynCor.exe
2009-12-08 20:48:01299520----a-w-c:\windows\uninst.exe
2009-12-05 17:02:3345816----a-w-c:\windows\fonts\euronymous-fo+st.ttf
2009-12-03 01:37:4046504----a-w-c:\windows\fonts\Formal_436_BT.ttf
2009-12-02 11:18:3655324----a-w-c:\windows\fonts\Cooper_Md_BT_Medium.ttf
2009-12-02 11:13:1176000----a-w-c:\windows\fonts\ANNA____.ttf
2009-11-30 01:08:17507392----a-w-c:\windows\system32\AutoPartNt.exe
2009-11-30 00:42:4837888----a-w-c:\windows\system32\setupnt.dll
2009-11-30 00:42:47126976----a-w-c:\windows\system32\snapapi.dll
2009-11-14 00:47:3290112----a-w-c:\windows\system32\dpl100.dll
2009-11-14 00:47:28856064----a-w-c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28856064----a-w-c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28847872----a-w-c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28843776----a-w-c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28839680----a-w-c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28696320----a-w-c:\windows\system32\DivX.dll
2006-05-03 09:06:54163328--sha-r-c:\windows\system32\flvDX.dll
2009-08-23 00:35:38952--sha-w-c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47:1631232--sh--r-c:\windows\system32\msfDX.dll
2008-03-16 12:30:52216064--sha-r-c:\windows\system32\nbDX.dll

============= FINISH: 20:27:47.01 ===============
Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
gxal
aic32p

DDS::
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-02-10.01 - Alex 02/10/2010 15:40:14.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.101 [GMT -5:00]
Running from: c:\documents and settings\Alex\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alex\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\temp
c:\program files\temp\Admin.exe
c:\program files\temp\Message.ini
c:\program files\temp\MSG.INI
c:\program files\temp\MSG_CHS.INI
c:\program files\temp\MSG_CHT.INI
c:\program files\temp\MSG_KOR.INI
C:\Thumbs.db
c:\windows\patchw.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vm.exe
c:\windows\system32\WS2Fix.exe

Infected copy of c:\windows\system32\Drivers\atapi.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\atapi.sys

Infected copy of c:\windows\system32\mmc.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mmc.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_AIC32P
-------\Legacy_POWERMANAGER
-------\Service_aic32p
-------\Service_gxal
-------\Service_PowerManager


((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.

2010-02-10 20:13 . 2010-02-10 20:13411368----a-w-c:\windows\system32\deploytk.dll
2010-02-09 19:20 . 2010-02-09 19:20--------d-----w-c:\program files\Trend Micro
2010-02-09 18:50 . 2010-02-10 17:32--------d-----w-c:\documents and settings\Administrator\Application Data\Orbit
2010-02-07 21:47 . 2010-02-07 21:47--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-02-07 21:41 . 2010-02-07 21:41--------d-sh--w-c:\documents and settings\Administrator\IETldCache
2010-02-06 05:08 . 2010-02-06 05:08--------d-----w-c:\program files\Common Files\Adobe AIR
2010-02-05 18:21 . 2010-02-05 18:21--------d-----w-c:\documents and settings\Alex\Application Data\Subversion
2010-02-05 18:19 . 2010-02-05 18:20--------d-----w-c:\program files\GUI Design Studio
2010-02-03 10:49 . 2010-02-09 22:11--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\LogMeIn Hamachi
2010-02-03 10:49 . 2010-02-10 21:00--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\LogMeIn Hamachi
2010-02-03 10:47 . 2010-02-03 10:47--------d-----w-c:\program files\LogMeIn Hamachi
2010-01-29 21:12 . 2010-02-06 05:10--------d-----w-c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-29 21:12 . 2010-01-29 21:12--------d-----w-C:\ProgramData
2010-01-29 21:08 . 2008-09-04 20:11447752----a-r-c:\windows\system32\vp6vfw.dll
2010-01-29 21:08 . 2010-01-29 21:08--------d-----w-c:\program files\Microsoft WSE
2010-01-29 20:49 . 2010-01-29 21:09--------d-----w-c:\program files\Electronic Arts
2010-01-27 01:03 . 2010-01-27 01:03--------d-----w-c:\documents and settings\All Users\Application Data\Kazaa
2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\documents and settings\Alex\Application Data\Kazaa Lite
2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\program files\Kazaa Lite K++
2010-01-26 23:56 . 2010-01-26 23:56--------d-----w-C:\My Shared Folder
2010-01-26 23:56 . 2010-01-26 23:59--------d-----w-c:\program files\Torrent Searcher 9.0
2010-01-26 07:27 . 2010-01-26 07:27--------d-----w-c:\windows\MEGA-DSC
2010-01-26 07:27 . 2002-10-21 16:37515803----a-w-c:\windows\system32\drivers\CA504bv.sys
2010-01-26 07:27 . 2002-09-27 15:3465536----a-w-c:\windows\PCCam.exe
2010-01-26 07:27 . 2002-07-25 16:1910986----a-w-c:\windows\system32\drivers\Bulk504b.sys
2010-01-26 07:27 . 2002-01-19 20:33131072----a-w-c:\windows\system32\SP5X_32.DLL
2010-01-25 10:58 . 2010-01-29 21:11479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-24 17:23 . 2010-02-07 23:32--------d-----w-c:\program files\Pidgin
2010-01-24 17:23 . 2010-01-24 17:23--------d-----w-c:\program files\Common Files\GTK
2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\NetMedia Providers
2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\Publish Providers
2010-01-24 07:38 . 2010-01-24 07:38--------d-----w-c:\documents and settings\Alex\Application Data\Sony
2010-01-24 07:34 . 2010-01-24 07:40--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Sony
2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Vstplugins
2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Sony
2010-01-24 06:44 . 2010-01-24 06:44--------d-----w-c:\program files\Sony Setup
2010-01-14 06:34 . 2010-01-14 06:34--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Yahoo
2010-01-14 06:34 . 2010-01-14 06:35--------d-----w-c:\program files\Yahoo!
2010-01-12 22:40 . 2010-01-12 22:40--------d-----w-c:\documents and settings\Alex\Application Data\AVG9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 21:03 . 2007-04-29 04:21--------d-----w-c:\documents and settings\Alex\Application Data\Orbit
2010-02-10 20:15 . 2008-01-04 21:35--------d-----w-c:\program files\Common Files\Java
2010-02-10 20:12 . 2003-03-11 14:13--------d-----w-c:\program files\Java
2010-02-10 17:19 . 2009-12-02 00:39--------d-----w-c:\documents and settings\Alex\Application Data\vlc
2010-02-10 16:43 . 2007-11-03 03:03--------d-----w-c:\documents and settings\Alex\Application Data\.purple
2010-02-06 19:29 . 2009-07-17 02:50--------d-----w-c:\documents and settings\Alex\Application Data\dvdcss
2010-02-03 09:30 . 2009-07-20 13:11--------d-----w-c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-03 09:29 . 2009-07-20 13:11--------d-----w-c:\program files\DVD Shrink
2010-02-03 09:23 . 2007-08-11 15:44--------d-----w-c:\documents and settings\Alex\Application Data\DVD Flick
2010-01-29 20:49 . 2003-03-10 15:01--------d--h--w-c:\program files\InstallShield Installation Information
2010-01-28 03:08 . 2007-11-04 03:13--------d-----w-c:\documents and settings\Alex\Application Data\gtk-2.0
2010-01-25 10:58 . 2007-03-26 02:508224-c--a-w-c:\documents and settings\Alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-25 10:50 . 2010-01-11 02:33--------d-----w-c:\documents and settings\Alex\Application Data\Azureus
2010-01-23 03:38 . 2009-08-11 01:10--------d-----w-c:\documents and settings\Alex\Application Data\Audacity
2010-01-20 08:21 . 2009-12-15 05:53--------d-----w-c:\documents and settings\Alex\Application Data\BitTyrant
2010-01-12 10:01 . 2009-12-04 02:44--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-01-11 02:34 . 2010-01-11 02:34--------d-----w-c:\documents and settings\All Users\Application Data\Azureus
2010-01-11 02:30 . 2010-01-11 02:28--------d-----w-c:\program files\Vuze
2010-01-09 17:06 . 2010-01-09 17:06--------d-----w-c:\program files\VMware
2010-01-07 21:07 . 2009-12-04 02:4438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-12-04 02:4419160----a-w-c:\windows\system32\drivers\mbam.sys
2010-01-03 06:13 . 2010-01-03 06:13--------d-----w-c:\documents and settings\Alex\Application Data\Participatory Culture Foundation
2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Combined Community Codec Pack
2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Participatory Culture Foundation
2010-01-03 06:03 . 2009-12-28 04:10--------d-----w-c:\program files\Aegisub
2010-01-03 02:28 . 2010-01-03 02:25--------d-----w-c:\program files\Common Files\ArcSoft
2010-01-03 02:28 . 2010-01-03 02:24--------d-----w-c:\program files\ArcSoft
2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\Alex\Application Data\ArcSoft
2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\All Users\Application Data\ArcSoft
2010-01-02 06:56 . 2009-08-21 20:18--------d-----w-c:\documents and settings\NetworkService\Application Data\gtk-2.0
2010-01-02 03:14 . 2010-01-02 03:14--------d-----w-c:\documents and settings\NetworkService\Application Data\Orbit
2010-01-01 20:34 . 2010-01-01 20:33--------d-----w-c:\program files\P2PChan
2010-01-01 18:34 . 2009-08-10 07:30--------d-----w-c:\program files\Unlocker
2009-12-31 16:50 . 2001-08-23 12:00353792----a-w-c:\windows\system32\drivers\srv.sys
2009-12-31 05:07 . 2008-05-25 15:50--------d-----w-c:\program files\MediaCoder
2009-12-30 21:53 . 2009-12-30 20:17--------d-----w-c:\program files\SUPERAntiSpyware
2009-12-30 20:51 . 2009-12-30 20:5125608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys
2009-12-30 20:51 . 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll
2009-12-30 20:51 . 2009-12-30 20:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-12-30 20:51 . 2009-12-30 20:51161800----a-w-c:\windows\system32\drivers\avgrkx86.sys
2009-12-30 20:51 . 2009-12-30 20:51333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-12-30 20:51 . 2009-12-30 20:5128424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-12-30 20:49 . 2009-12-30 20:4950968----a-w-c:\windows\system32\avgfwdx.dll
2009-12-30 20:49 . 2009-12-30 20:4930104----a-w-c:\windows\system32\drivers\avgfwdx.sys
2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\program files\AVG
2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-12-30 19:56 . 2009-11-07 21:11--------d-----w-c:\program files\CCleaner
2009-12-30 19:30 . 2009-11-08 03:46--------d-----w-c:\documents and settings\Alex\Application Data\TrueCrypt
2009-12-30 09:22 . 2009-12-30 09:22--------d-----w-c:\documents and settings\All Users\Application Data\TrueCrypt
2009-12-30 09:22 . 2009-11-07 20:51223440----a-w-c:\windows\system32\drivers\truecrypt.sys
2009-12-30 01:46 . 2007-07-18 20:31--------d-----w-c:\documents and settings\Alex\Application Data\DMCache
2009-12-29 16:41 . 2009-08-25 02:42--------d-----w-c:\documents and settings\Alex\Application Data\WinFF
2009-12-29 14:19 . 2009-12-13 06:29--------d-----w-c:\program files\Xvid
2009-12-29 05:05 . 2009-12-29 05:05--------d-----w-c:\program files\eRightSoft
2009-12-28 07:47 . 2007-08-10 20:32--------d-----w-c:\program files\DVD Flick
2009-12-28 07:36 . 2009-07-20 11:44--------d-----w-c:\program files\Common Files\Webroot Shared
2009-12-28 04:10 . 2009-12-28 04:10--------d-----w-c:\documents and settings\Alex\Application Data\Aegisub
2009-12-28 03:59 . 2007-06-23 18:03--------d-----w-c:\documents and settings\Alex\Application Data\uTorrent
2009-12-27 06:48 . 2009-12-14 11:461620552----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-27 05:21 . 2009-12-27 05:21--------d-----w-c:\documents and settings\All Users\Application Data\Speed Soft
2009-12-26 03:13 . 2009-12-26 03:13--------d-----w-c:\documents and settings\Alex\Application Data\JAM Software
2009-12-23 05:59 . 2009-12-23 05:58--------d-----w-c:\program files\VirtualDubMOD
2009-12-22 16:48 . 2009-12-15 22:28--------d-----w-c:\program files\MP3Gain
2009-12-21 19:14 . 2003-03-10 21:03916480----a-w-c:\windows\system32\wininet.dll
2009-12-21 14:20 . 2009-12-21 14:20--------d-----w-c:\documents and settings\Alex\Application Data\Obsidium
2009-12-21 11:31 . 2009-12-21 11:31--------d-----w-c:\program files\FDRLab
2009-12-18 07:01 . 2009-12-18 07:01--------d-----w-c:\program files\Outspark
2009-12-17 05:22 . 2007-04-04 01:57--------d-----w-c:\program files\DivX
2009-12-17 05:22 . 2009-12-17 05:21--------d-----w-c:\program files\Common Files\DivX Shared
2009-12-16 18:43 . 2003-03-10 21:00343040----a-w-c:\windows\system32\mspaint.exe
2009-12-16 02:55 . 2009-12-15 05:53--------d-----w-c:\program files\BitTyrant
2009-12-16 00:03 . 2009-12-16 00:03--------d-----w-c:\program files\JAM Software
2009-12-14 07:08 . 2001-08-23 12:0033280----a-w-c:\windows\system32\csrsrv.dll
2009-12-13 22:44 . 2009-12-13 22:33--------d-----w-c:\program files\Winnydows
2009-12-13 06:41 . 2009-12-13 06:40--------d-----w-c:\program files\StaxRip
2009-12-13 06:28 . 2009-07-19 00:09--------d-----w-c:\program files\AviSynth 2.5
2009-12-13 04:56 . 2009-12-13 04:56--------d-----w-c:\documents and settings\All Users\Application Data\Soulseek
2009-12-13 04:55 . 2009-12-03 02:31--------d-----w-c:\documents and settings\Alex\Application Data\DC++
2009-12-12 22:46 . 2009-12-12 22:4621035----a-w-c:\windows\system32\drivers\AegisP.sys
2009-12-12 22:46 . 2009-12-12 22:46--------d-----w-c:\program files\NETGEAR
2009-12-09 18:57 . 2009-12-09 18:57306688----a-w-c:\windows\IsUninst.exe
2009-12-08 20:48 . 2009-12-08 20:48299520----a-w-c:\windows\uninst.exe
2009-12-08 20:48 . 2009-12-08 20:48380928----a-w-c:\windows\SynCor.exe
2009-12-08 19:27 . 2001-08-23 12:002189184----a-w-c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2001-08-17 13:482066048----a-w-c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2001-08-23 12:00455424----a-w-c:\windows\system32\drivers\mrxsmb.sys
2009-11-30 01:08 . 2009-11-30 01:08507392----a-w-c:\windows\system32\AutoPartNt.exe
2009-11-30 00:42 . 2009-11-30 00:4237888----a-w-c:\windows\system32\setupnt.dll
2009-11-30 00:42 . 2009-11-30 00:4282464----a-w-c:\windows\system32\drivers\snapman.sys
2009-11-30 00:42 . 2009-11-30 00:42126976----a-w-c:\windows\system32\snapapi.dll
2009-11-27 17:11 . 2003-12-28 19:1717920----a-w-c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2003-12-28 19:171291776----a-w-c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2001-08-23 12:0028672----a-w-c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:368704----a-w-c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2003-03-10 21:0011264----a-w-c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2003-03-10 20:5684992----a-w-c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2001-08-17 22:3648128----a-w-c:\windows\system32\iyuv_32.dll
2006-05-03 09:06 . 2009-07-20 18:12163328--sha-r-c:\windows\system32\flvDX.dll
2009-08-23 00:35 . 2009-07-18 01:03952--sha-w-c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2009-12-29 05:0631232--sh--r-c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-12-28 05:58216064--sha-r-c:\windows\system32\nbDX.dll
.

------- Sigcheck -------

[-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2009-12-28 1201152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2002-04-20 69632]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-09-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-09-30 126976]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2007-8-9 1667072]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-12-30 20:32548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-12-08 20:44136192----a-w-c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Program Files\\WinPcap\\rpcapd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"h:\\dls\\romz\\emuz\\VisualBoyAdvance\\VisualBoyAdvance.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\BitTyrant\\Azureus.exe"=
"c:\\Program Files\\Webroot\\Washer\\wwDisp.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\Analog Devices\\SoundMAX\\DrvLsnr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"=
"c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"=
"c:\\Program Files\\Mozilla Firefox\\crashreporter.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [12/30/2009 3:51 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/30/2009 3:51 PM 161800]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/4/2007 12:29 PM 685816]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/30/2009 3:51 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/30/2009 3:51 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 74480]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12/30/2009 3:50 PM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/30/2009 3:50 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [12/30/2009 3:50 PM 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [12/30/2009 3:50 PM 5832712]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 12:27 PM 1074568]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/3/2009 9:44 PM 236368]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [7/20/2009 6:44 AM 598856]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [12/30/2009 3:50 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [12/30/2009 3:50 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [12/30/2009 3:50 PM 25736]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [8/9/2007 4:43 PM 113896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/3/2009 9:44 PM 19160]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [12/12/2009 5:46 PM 272128]
R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [8/8/2007 6:35 AM 223128]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104]
S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [1/2/2001 11:53 PM 19677]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 12:31 PM 42000]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [12/8/2007 12:20 PM 15104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [11/29/2009 10:41 AM 627072]
S3 XDva281;XDva281;\??\c:\windows\system32\XDva281.sys --> c:\windows\system32\XDva281.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-08 c:\windows\Tasks\Malwarebytes' Scheduled Update for Alex.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-12-09 21:07]
.
.
------- Supplementary Scan -------
.
uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uInternet Settings,ProxyServer = 83.133.119.38:8080
IE: &Download All with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_all.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_link.htm
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download FLV video content with IDM - c:\documents and settings\Alex\My Documents\Random Junk\Programs\Internet Download Manager\IEGetVL.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-HP Standard Port Monitor - c:\program files\Hewlett-Packard\HP Standard Port Monitor\Uninst.isu
AddRemove-RTP - c:\program files\ASCII\RPG Maker 2003\RTP2\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-10 16:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8338C8AC]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf886af28
\Driver\ACPI -> ACPI.sys @ 0xf86dbcb8
\Driver\atapi -> atapi.sys @ 0xf8670b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1252)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3796)
c:\windows\system32\WININET.dll
c:\program files\Unlocker\UnlockerHook.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\netdde.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Orbitdownloader\orbitnet.exe
.
**************************************************************************
.
COMPLETION time: 2010-02-10 16:19:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-10 21:19

Pre-Run: 131,014,467,584 BYTES free
Post-Run: 131,102,572,544 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 8E4CA6C6ECEEAF982CBAD80F99CEB77C






control.exe still wont open properlySuspicious file scan

Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and logs posted for each one)

* Copy the file path in the below Code box:
Code: [Select]c:\windows\system32\termsrv.dll* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

----------

Download Rooter.exe to your desktop.

* Double click Rooter.exe to start the tool.
* A DOS window will appear and show the scan progress.
* Once complete a notepad file containing the report will open.
* Copy & paste the results in your next reply.
* Close notepad and Rooter will close.

A log will also save at C:\Rooter.txt

----------

Please download SystemLook from one of the below links and save it to your desktop.

Link #1
Link #2

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

* Double-click SystemLook.exe to run it.
* Copy the contents of the following codebox into the main textfield.

Code: [Select]:filefind
control.exe

* Click the Look button to start the scan.
* Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).
* When finished, a notepad window will open with the results of the scan. Please post the log.

The log can also be found on your desktop entitled SystemLook.txthttp://virusscan.jotti.org/en/scanresult/0663266c49f1f2e26f95a158057ef980252cb626/de634f82628724248ed5d969856b86d2ba830f65



Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 2 Stepping 7, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 8.0.6001.18702
Mozilla Firefox 3.5.7 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:232 Go - Free:122 Go )
E:\ [CD_Rom]
G:\ [CD_Rom]
H:\ [Fixed-NTFS] .. ( Total:931 Go - Free:672 Go )
.
Scan : 17:30.12
Path : C:\Documents and Settings\Alex\Desktop\Rooter.exe
User : Alex ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (828)
______ \??\C:\WINDOWS\system32\csrss.exe (1228)
______ \??\C:\WINDOWS\system32\winlogon.exe (1252)
______ C:\WINDOWS\system32\services.exe (1296)
______ C:\WINDOWS\system32\lsass.exe (1308)
______ C:\WINDOWS\system32\svchost.exe (1480)
______ C:\WINDOWS\system32\svchost.exe (1548)
______ C:\WINDOWS\System32\svchost.exe (288)
______ C:\WINDOWS\System32\svchost.exe (368)
______ C:\Program Files\AVG\AVG9\avgchsvx.exe (456)
______ C:\Program Files\AVG\AVG9\avgrsx.exe (464)
______ C:\WINDOWS\system32\svchost.exe (544)
______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (764)
______ C:\WINDOWS\system32\spoolsv.exe (1604)
Locked AVGIDSAgent.exe (1644)
______ C:\WINDOWS\System32\svchost.exe (1820)
______ C:\WINDOWS\system32\netdde.exe (1860)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (796)
Locked avgwdsvc.exe (856)
Locked avgfws9.exe (668)
______ C:\WINDOWS\system32\bgsvcgen.exe (1040)
______ C:\Program Files\Bonjour\mDNSResponder.exe (1076)
______ C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (1156)
______ C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (1652)
Locked avgam.exe (1132)
______ C:\WINDOWS\System32\svchost.exe (1880)
______ C:\Program Files\Java\jre6\bin\jqs.exe (2036)
______ C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (2252)
______ C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (2968)
______ C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (3364)
______ C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (3804)
______ C:\WINDOWS\System32\svchost.exe (2296)
______ C:\WINDOWS\System32\MsPMSPSv.exe (2348)
______ C:\Program Files\Webroot\Washer\WasherSvc.exe (2392)
______ C:\Program Files\Windows Media Player\WMPNetwk.exe (2988)
______ C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (3420)
______ C:\WINDOWS\system32\hkcmd.exe (2628)
______ C:\Program Files\Unlocker\UnlockerAssistant.exe (2424)
______ C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (4028)
______ C:\Program Files\Common Files\Java\Java Update\jusched.exe (2268)
______ C:\Program Files\Webroot\Washer\wwDisp.exe (3260)
______ C:\Program Files\Orbitdownloader\orbitdm.exe (2896)
______ C:\Program Files\Orbitdownloader\orbitnet.exe (1680)
______ C:\WINDOWS\explorer.exe (3796)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2548)
______ C:\Program Files\AVG\AVG9\avgemc.exe (2064)
______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (2996)
______ C:\Program Files\AVG\AVG9\avgnsx.exe (2508)
______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (1408)
______ C:\WINDOWS\system32\notepad.exe (3772)
______ C:\Documents and Settings\Alex\Desktop\Rooter.exe (2524)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:250056221184)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\Malwarebytes' Scheduled Update for Alex.job
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
.
----------------------\\ Scan completed at 17:32.05
.
C:\Rooter$\Rooter_1.txt - (10/02/2010 | 17:32.05).c



SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 17:34 on 10/02/2010 by Alex (Administrator - Elevation successful)

========== filefind ==========

Searching for "control.exe"
C:\WINDOWS\system32\control.exe--a--- 77824 bytes[12:00 23/08/2001][12:00 23/08/2001] 1B2DE306FEC245B54340ADEF6AF3A460
C:\WINDOWS\system32\dllcache\control.exe--a--c 8192 bytes[12:00 23/08/2001][12:00 23/08/2001] 4C6785E3D2E45EE87CB995190A0C7737

-=End Of File=-Scan this file at Jotti and post the link to the results.

C:\WINDOWS\system32\control.exehttp://virusscan.jotti.org/en/scanresult/d8b344f1308fb523d6e57e18e8116d5db04805a5

Most of the scanners seem to think I have sality or some variant of it (which is strange, considering I got rid of Sality.AA about 4 months ago)You didn't get rid of all of it. Sality is very hard to cure and often takes a complete reformat and reinstall to get rid of it.

Let's see if this will work.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

SkipFix::

FCopy::
C:\WINDOWS\system32\dllcache\control.exe | C:\WINDOWS\system32\control.exe


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-02-10.01 - Alex 02/10/2010 18:20:38.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.127 [GMT -5:00]
Running from: c:\documents and settings\Alex\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alex\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\system32\dllcache\control.exe --> c:\windows\system32\control.exe
.
((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.

2010-02-10 22:30 . 2010-02-10 22:32--------d-----w-C:\Rooter$
2010-02-10 20:13 . 2010-02-10 20:13411368----a-w-c:\windows\system32\deploytk.dll
2010-02-09 19:20 . 2010-02-09 19:20--------d-----w-c:\program files\Trend Micro
2010-02-09 18:50 . 2010-02-10 17:32--------d-----w-c:\documents and settings\Administrator\Application Data\Orbit
2010-02-07 21:47 . 2010-02-07 21:47--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-02-07 21:41 . 2010-02-07 21:41--------d-sh--w-c:\documents and settings\Administrator\IETldCache
2010-02-06 05:08 . 2010-02-06 05:08--------d-----w-c:\program files\Common Files\Adobe AIR
2010-02-05 18:21 . 2010-02-05 18:21--------d-----w-c:\documents and settings\Alex\Application Data\Subversion
2010-02-05 18:19 . 2010-02-05 18:20--------d-----w-c:\program files\GUI Design Studio
2010-02-03 10:49 . 2010-02-09 22:11--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\LogMeIn Hamachi
2010-02-03 10:49 . 2010-02-10 23:26--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\LogMeIn Hamachi
2010-02-03 10:47 . 2010-02-03 10:47--------d-----w-c:\program files\LogMeIn Hamachi
2010-01-29 21:12 . 2010-02-06 05:10--------d-----w-c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-29 21:12 . 2010-01-29 21:12--------d-----w-C:\ProgramData
2010-01-29 21:08 . 2008-09-04 20:11447752----a-r-c:\windows\system32\vp6vfw.dll
2010-01-29 21:08 . 2010-01-29 21:08--------d-----w-c:\program files\Microsoft WSE
2010-01-29 20:49 . 2010-01-29 21:09--------d-----w-c:\program files\Electronic Arts
2010-01-27 01:03 . 2010-01-27 01:03--------d-----w-c:\documents and settings\All Users\Application Data\Kazaa
2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\documents and settings\Alex\Application Data\Kazaa Lite
2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\program files\Kazaa Lite K++
2010-01-26 23:56 . 2010-01-26 23:56--------d-----w-C:\My Shared Folder
2010-01-26 23:56 . 2010-01-26 23:59--------d-----w-c:\program files\Torrent Searcher 9.0
2010-01-26 07:27 . 2010-01-26 07:27--------d-----w-c:\windows\MEGA-DSC
2010-01-26 07:27 . 2002-10-21 16:37515803----a-w-c:\windows\system32\drivers\CA504bv.sys
2010-01-26 07:27 . 2002-09-27 15:3465536----a-w-c:\windows\PCCam.exe
2010-01-26 07:27 . 2002-07-25 16:1910986----a-w-c:\windows\system32\drivers\Bulk504b.sys
2010-01-26 07:27 . 2002-01-19 20:33131072----a-w-c:\windows\system32\SP5X_32.DLL
2010-01-25 10:58 . 2010-01-29 21:11479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-01-24 17:23 . 2010-02-07 23:32--------d-----w-c:\program files\Pidgin
2010-01-24 17:23 . 2010-01-24 17:23--------d-----w-c:\program files\Common Files\GTK
2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\NetMedia Providers
2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\Publish Providers
2010-01-24 07:38 . 2010-01-24 07:38--------d-----w-c:\documents and settings\Alex\Application Data\Sony
2010-01-24 07:34 . 2010-01-24 07:40--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Sony
2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Vstplugins
2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Sony
2010-01-24 06:44 . 2010-01-24 06:44--------d-----w-c:\program files\Sony Setup
2010-01-14 06:34 . 2010-01-14 06:34--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Yahoo
2010-01-14 06:34 . 2010-01-14 06:35--------d-----w-c:\program files\Yahoo!
2010-01-12 22:40 . 2010-01-12 22:40--------d-----w-c:\documents and settings\Alex\Application Data\AVG9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 23:25 . 2007-04-29 04:21--------d-----w-c:\documents and settings\Alex\Application Data\Orbit
2010-02-10 20:15 . 2008-01-04 21:35--------d-----w-c:\program files\Common Files\Java
2010-02-10 20:14 . 2010-02-10 20:14348160----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\msvcr71.dll
2010-02-10 20:14 . 2010-02-10 20:14503808----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\msvcp71.dll
2010-02-10 20:14 . 2010-02-10 20:1461440----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-50e0af3d-n\decora-sse.dll
2010-02-10 20:14 . 2010-02-10 20:14499712----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\jmc.dll
2010-02-10 20:14 . 2010-02-10 20:1412800----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-50e0af3d-n\decora-d3d.dll
2010-02-10 20:12 . 2003-03-11 14:13--------d-----w-c:\program files\Java
2010-02-10 17:19 . 2009-12-02 00:39--------d-----w-c:\documents and settings\Alex\Application Data\vlc
2010-02-10 16:43 . 2007-11-03 03:03--------d-----w-c:\documents and settings\Alex\Application Data\.purple
2010-02-10 16:41 . 2010-02-10 16:411791----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\bos.oscar.aol.com
2010-02-10 16:41 . 2010-02-10 16:411505----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\slogin.oscar.aol.com
2010-02-10 03:42 . 2010-02-10 03:421691----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\api.screenname.aol.com
2010-02-06 19:29 . 2009-07-17 02:50--------d-----w-c:\documents and settings\Alex\Application Data\dvdcss
2010-02-06 05:00 . 2010-02-06 05:0938784----a-w-c:\documents and settings\Alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-06 05:00 . 2010-02-06 05:0938784----a-w-c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-03 09:30 . 2009-07-20 13:11--------d-----w-c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-03 09:29 . 2009-07-20 13:11--------d-----w-c:\program files\DVD Shrink
2010-02-03 09:23 . 2007-08-11 15:44--------d-----w-c:\documents and settings\Alex\Application Data\DVD Flick
2010-01-29 21:08 . 2010-01-29 21:0810134----a-r-c:\documents and settings\Alex\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2010-01-29 20:49 . 2003-03-10 15:01--------d--h--w-c:\program files\InstallShield Installation Information
2010-01-28 03:08 . 2007-11-04 03:13--------d-----w-c:\documents and settings\Alex\Application Data\gtk-2.0
2010-01-25 19:32 . 2010-02-08 02:57114360----a-w-c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2010-01-25 10:58 . 2007-03-26 02:508224-c--a-w-c:\documents and settings\Alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-25 10:50 . 2010-01-11 02:33--------d-----w-c:\documents and settings\Alex\Application Data\Azureus
2010-01-23 03:38 . 2009-08-11 01:10--------d-----w-c:\documents and settings\Alex\Application Data\Audacity
2010-01-20 08:21 . 2009-12-15 05:53--------d-----w-c:\documents and settings\Alex\Application Data\BitTyrant
2010-01-14 21:28 . 2010-01-27 16:201260800----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-14 21:28 . 2010-01-27 16:203777280----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-12 10:01 . 2009-12-04 02:44--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-01-12 10:00 . 2009-12-13 10:015115824----a-w-c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-11 02:34 . 2010-01-11 02:34--------d-----w-c:\documents and settings\All Users\Application Data\Azureus
2010-01-11 02:30 . 2010-01-11 02:28--------d-----w-c:\program files\Vuze
2010-01-09 17:06 . 2010-01-09 17:06--------d-----w-c:\program files\VMware
2010-01-07 21:07 . 2009-12-04 02:4438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-12-04 02:4419160----a-w-c:\windows\system32\drivers\mbam.sys
2010-01-03 06:13 . 2010-01-03 06:13--------d-----w-c:\documents and settings\Alex\Application Data\Participatory Culture Foundation
2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Combined Community Codec Pack
2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Participatory Culture Foundation
2010-01-03 06:03 . 2009-12-28 04:10--------d-----w-c:\program files\Aegisub
2010-01-03 02:28 . 2010-01-03 02:25--------d-----w-c:\program files\Common Files\ArcSoft
2010-01-03 02:28 . 2010-01-03 02:24--------d-----w-c:\program files\ArcSoft
2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\Alex\Application Data\ArcSoft
2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\All Users\Application Data\ArcSoft
2010-01-02 06:56 . 2009-08-21 20:18--------d-----w-c:\documents and settings\NetworkService\Application Data\gtk-2.0
2010-01-02 03:14 . 2010-01-02 03:14--------d-----w-c:\documents and settings\NetworkService\Application Data\Orbit
2010-01-01 20:34 . 2010-01-01 20:33--------d-----w-c:\program files\P2PChan
2010-01-01 18:34 . 2009-08-10 07:30--------d-----w-c:\program files\Unlocker
2009-12-31 16:50 . 2001-08-23 12:00353792----a-w-c:\windows\system32\drivers\srv.sys
2009-12-31 08:51 . 2009-12-30 20:3579488----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-31 05:14 . 2009-12-30 20:2852224----a-w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-31 05:14 . 2009-12-30 20:20117760----a-w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-31 05:07 . 2008-05-25 15:50--------d-----w-c:\program files\MediaCoder
2009-12-30 21:53 . 2009-12-30 20:17--------d-----w-c:\program files\SUPERAntiSpyware
2009-12-30 20:51 . 2009-12-30 20:5125608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys
2009-12-30 20:51 . 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll
2009-12-30 20:51 . 2009-12-30 20:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-12-30 20:51 . 2009-12-30 20:51161800----a-w-c:\windows\system32\drivers\avgrkx86.sys
2009-12-30 20:51 . 2009-12-30 20:51333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-12-30 20:51 . 2009-12-30 20:5128424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-12-30 20:49 . 2009-12-30 20:4950968----a-w-c:\windows\system32\avgfwdx.dll
2009-12-30 20:49 . 2009-12-30 20:4930104----a-w-c:\windows\system32\drivers\avgfwdx.sys
2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\program files\AVG
2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com
2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-12-30 19:56 . 2009-11-07 21:11--------d-----w-c:\program files\CCleaner
2009-12-30 19:30 . 2009-11-08 03:46--------d-----w-c:\documents and settings\Alex\Application Data\TrueCrypt
2009-12-30 09:22 . 2009-12-30 09:22--------d-----w-c:\documents and settings\All Users\Application Data\TrueCrypt
2009-12-30 09:22 . 2009-11-07 20:51223440----a-w-c:\windows\system32\drivers\truecrypt.sys
2009-12-30 01:46 . 2007-07-18 20:31--------d-----w-c:\documents and settings\Alex\Application Data\DMCache
2009-12-29 16:41 . 2009-12-29 16:41464----a-w-c:\documents and settings\Alex\Application Data\WinFF\ff091229114117.bat
2009-12-29 16:41 . 2009-08-25 02:42--------d-----w-c:\documents and settings\Alex\Application Data\WinFF
2009-12-29 14:19 . 2009-12-13 06:29--------d-----w-c:\program files\Xvid
2009-12-29 05:05 . 2009-12-29 05:05--------d-----w-c:\program files\eRightSoft
2009-12-28 07:47 . 2007-08-10 20:32--------d-----w-c:\program files\DVD Flick
2009-12-28 07:36 . 2009-07-20 11:44--------d-----w-c:\program files\Common Files\Webroot Shared
2009-12-28 04:32 . 2009-12-08 20:2060928----a-w-c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\installer\setup.exe
2009-12-28 04:10 . 2009-12-28 04:10--------d-----w-c:\documents and settings\Alex\Application Data\Aegisub
2009-12-28 03:59 . 2007-06-23 18:03--------d-----w-c:\documents and settings\Alex\Application Data\uTorrent
2009-12-27 06:48 . 2009-12-14 11:461620552----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-27 05:21 . 2009-12-27 05:21--------d-----w-c:\documents and settings\All Users\Application Data\Speed Soft
2009-12-26 03:13 . 2009-12-26 03:13--------d-----w-c:\documents and settings\Alex\Application Data\JAM Software
2009-12-23 05:59 . 2009-12-23 05:58--------d-----w-c:\program files\VirtualDubMOD
2009-12-22 16:48 . 2009-12-15 22:28--------d-----w-c:\program files\MP3Gain
2009-12-22 01:48 . 2009-12-22 01:481201----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\login.facebook.com
2009-12-21 19:14 . 2003-03-10 21:03916480------w-c:\windows\system32\wininet.dll
2009-12-21 14:20 . 2009-12-21 14:20--------d-----w-c:\documents and settings\Alex\Application Data\Obsidium
2009-12-21 11:31 . 2009-12-21 11:31--------d-----w-c:\program files\FDRLab
2009-12-18 07:01 . 2009-12-18 07:01--------d-----w-c:\program files\Outspark
2009-12-17 05:22 . 2007-04-04 01:57--------d-----w-c:\program files\DivX
2009-12-17 05:22 . 2009-12-17 05:21--------d-----w-c:\program files\Common Files\DivX Shared
2009-12-16 18:43 . 2003-03-10 21:00343040----a-w-c:\windows\system32\mspaint.exe
2009-12-16 02:55 . 2009-12-15 05:53--------d-----w-c:\program files\BitTyrant
2009-12-16 00:03 . 2009-12-16 00:03--------d-----w-c:\program files\JAM Software
2009-12-14 07:08 . 2001-08-23 12:0033280----a-w-c:\windows\system32\csrsrv.dll
2009-12-14 03:19 . 2009-12-14 03:1978336----a-w-c:\documents and settings\Alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-13 22:44 . 2009-12-13 22:33--------d-----w-c:\program files\Winnydows
2009-12-13 06:41 . 2009-12-13 06:40--------d-----w-c:\program files\StaxRip
2006-05-03 09:06 . 2009-07-20 18:12163328--sha-r-c:\windows\system32\flvDX.dll
2009-08-23 00:35 . 2009-07-18 01:03952--sha-w-c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2009-12-29 05:0631232--sh--r-c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-12-28 05:58216064--sha-r-c:\windows\system32\nbDX.dll
.

------- Sigcheck -------

[-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2009-12-28 1201152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2002-04-20 69632]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-09-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-09-30 126976]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2007-8-9 1667072]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-12-30 20:32548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-12-08 20:44136192----a-w-c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Program Files\\WinPcap\\rpcapd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"h:\\dls\\romz\\emuz\\VisualBoyAdvance\\VisualBoyAdvance.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\BitTyrant\\Azureus.exe"=
"c:\\Program Files\\Webroot\\Washer\\wwDisp.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\Analog Devices\\SoundMAX\\DrvLsnr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"=
"c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"=
"c:\\Program Files\\Mozilla Firefox\\crashreporter.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [12/30/2009 3:51 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/30/2009 3:51 PM 161800]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/4/2007 12:29 PM 685816]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/30/2009 3:51 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/30/2009 3:51 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 74480]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12/30/2009 3:50 PM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/30/2009 3:50 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [12/30/2009 3:50 PM 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [12/30/2009 3:50 PM 5832712]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 12:27 PM 1074568]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/3/2009 9:44 PM 236368]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [7/20/2009 6:44 AM 598856]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [12/30/2009 3:50 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [12/30/2009 3:50 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [12/30/2009 3:50 PM 25736]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [8/9/2007 4:43 PM 113896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/3/2009 9:44 PM 19160]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [12/12/2009 5:46 PM 272128]
R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [8/8/2007 6:35 AM 223128]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104]
S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [1/2/2001 11:53 PM 19677]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 12:31 PM 42000]
S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [12/8/2007 12:20 PM 15104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [11/29/2009 10:41 AM 627072]
S3 XDva281;XDva281;\??\c:\windows\system32\XDva281.sys --> c:\windows\system32\XDva281.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-08 c:\windows\Tasks\Malwarebytes' Scheduled Update for Alex.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-12-09 21:07]
.
.
------- Supplementary Scan -------
.
uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uInternet Settings,ProxyServer = 83.133.119.38:8080
IE: &Download All with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_all.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_link.htm
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download FLV video content with IDM - c:\documents and settings\Alex\My Documents\Random Junk\Programs\Internet Download Manager\IEGetVL.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-10 18:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8338C8AC]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8845f28
\Driver\ACPI -> ACPI.sys @ 0xf86b6cb8
\Driver\atapi -> atapi.sys @ 0xf864bb40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1280)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3024)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\netdde.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2010-02-10 18:38:28 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-10 23:38
ComboFix2.txt 2010-02-10 21:19

Pre-Run: 131,112,927,232 bytes free
Post-Run: 131,073,851,392 bytes free

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 245C9D80C4F7FF37AAD040A286EFFD43



it seems to have worked. nothings unexpectedly terminating, control.exe and mmc.exe both work. thanks for the help!The termsrv.dll is also infected so it needs replaced.

Enable viewing of hidden system files & folders XP

1. Click Start.
2. Select Control Panel.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide extensions for known file types option.
7. Uncheck the Hide protected operating system files (recommended) option.
8. Click Apply.
9. Click OK.

----------

Go here and download the termsrv.dll to your desktop. http://www.dlldump.com/download-dll-files_new.php/dllfiles/T/termsrv.dll/5.1.2600.2180/download.html

Then find the infected file located in the system32 folder.

c:\windows\system32\termsrv.dll Right click it and choose Rename. Rename it to termsrv.old

Then immediately go to the desktop and right click on the termsrv.dll and choose Cut.

Go back to the system32 folder. At the top of the screen choose Edit > Paste.

Let me know when that is done.
1679.

Solve : Re: logon.exe, is it a virus/trojan??

Answer»

It is not a virus, it is a file that helps RUN your computer. I HAPPEN to be missing this file (that's how I found this forum), and it told me for several days that it could not find the file. NOw, it has locked me out of the computer. don't delete it, or you will have the same PROBLEM. a little hint, if your computer says it cannot find a file, immediatly replace it, and instead of SHUTTING your computer down, put it on standby until you can fix it. HOPE this helps!


PS It is in use by windows, so it will not show up in your process list.Moved to a new topic. That was an old thread.

Quote

jqsnotify.exe the procedure entry point [emailprotected]@Z

The procedure entry point [emailprotected]@Z could not be located in the dynamic link library msvcrt.dll

Did you get it fixed?
1680.

Solve : Hello I cant use any other search engine but search.com cant remove problem?

Answer» THANK you so much evil my COMPUTER hasnt RUN this well in a very long time AWSOME easy to FALLOW advice thank you againYour welcome.

Safe surfing.
1681.

Solve : Help! Removal of Trojan.Packed.NsAnti virus ~ log attached?

Answer» HI
My business desktop installted with enterprise version of Symantec antivirus program is infected with Trojan.Packed.NsAnti virus. It is triggering manual scan the entire day, quarantining LOTS of tmp files. Have ATTACHED the log generated using Micro Hijack this. Pls advise asap.



[Saving space, attachment deleted by admin]Is this business desktop belonging to an organization or company?Yes, it belongs to an organisation. IT do not support virus removal, I need to reimage my PC to get rid of the virus.I'm sorry to turn down the help, but we help home users for free, but for BUSINESSES we will not help. We are here for home users, sorry.
1682.

Solve : Virus prevents computer from booting normally?

Answer»

Just this morning my computer was working fine. All of a sudden I get a message that i have a trojan (AVG free notified me) i click heal and forget about it. Then i get a message saying "fuck3.exe has stopped working". I'm thinking that it's a virus or something so i start a scan. In the first few seconds of the scan i get about 30 trojans that pop up on the AVG free .

I cancel the scan and go to restart the computer . when it restarts normally, it goes past the XP loading screen and ends up with a black screen and wont go to the user accounts. The only way i can get to the desktop is by starting in safemode. I downloaded malwarebytes' anti malware and scanned for viruses. I got a bunch of and deleted them except one that I can't delete without restarting, but i cant restart normally because it just ends up with that black screen. It's really frustrating.

The virus seems to affect the internet as well. If i do a google search for virus help, and click the link I get routed to some *censored* site. If i copy the link directly and paste it into the browser it works fine, so it's been ALMOST impossible to get help online.

the trojan that i can't delete without restarting is called "uacinit.dll" in the system32 folder. I would appreciate any ideas of how to be able to boot normally or how to remove the trojan. Ive been working at it for hours and I still can't boot the computer normally. Try using combofix and delete some of those unwanted entries in your registry editor. Next, download registry mechanic, scan your registry if you see some problems just click repair. Last THING is download an ATF cleaner for windows xp and firefox only, just clean everything. See if this would fix your problem. okay i'll try downloading those programs and report back.Okay this might have a simple answer but when i'm RUNNING combofix its asking me to turn off AVG free. The program doesn't seem to be running but it tells me to disable it. How do I do this?Quote from: KingPincer on March 23, 2009, 04:00:38 AM

Try using combofix and delete some of those unwanted entries in your registry editor. Next, download registry mechanic, scan your registry if you see some problems just click repair. Last thing is download an ATF cleaner for windows xp and firefox only, just clean everything. See if this would fix your problem.
I gotta thank you man. I think my computer is virus free now. You are a life saver! Bad news. After Doing all that the guy above asked, and after a full virus scan that deleted 3 trojans, my computer seemed to work fine. It restarted a couple times without hiccups. I tried restarting it again and now it won't. It does the same thing, goes to user accounts and then to a black screen. It only goes to the desktop on safemode. Do I have to repeat the steps above or what? hey can u help me 2?
i have the same problem but my computer wont even let me go into safe mode
it doesnt go to the loggin in screen it juss goes black for 10 secs then restarts n does the same thing over n over againI've got the same issue. Any help is appreciated.
1683.

Solve : Application cannot be executed... My case, pls help?

Answer»

Hi,

I have read all posts with the same issue. I also TRIED Combofix.

But I cannot run any application. After I downloaded, I opened it to run but the warning "application cannot be executed. ...exe file is infected" popped up and the application closed.

I also have Antivirus warning and AUTOMATICALLY opened IE to xxx web site .

Any help is highly appreciated.

Please. I still need help. Pls.

I am receiving Application cannot be executed" warning and I can do nothing with it. I've tried downloaded many SOFTWARE that I've read in other posts but after DOWNLOADING, I could not run it because the popup would prevent me to do so and close the application right away.

I also received warning from Antivirus Soft and it keeps opening IE to xxx websites.

Anyone pls help me...Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log BACK here.

1684.

Solve : AntiVirus Plus etc?

Answer»

Not many options here.

Create a bootable CD

Download this ISO file to the Desktop and burn it to a CD as an ISO.

To burn the file, install the free version of DeepBurner Free

Place a blank CD in your computer.

Start DeepBurner and select Burn ISO Image then click Next (you may need to maximize the DeepBurner window)

Under the window where it says Image file you have to select the rc.iso file you just DOWNLOADED. (click the little button to the right)

Once the file is selected click Burn ISO

With the ISO CD you just burned in the CD drive restart the computer.
Click to select any options that are required to start the computer from the CD drive if you are prompted.
When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER

Type: chkdsk /r and press Enter (NOTE the space between the chkdsk and /r)

To exit the Recovery Console and restart the computer, type exit at the command prompt, and then press ENTER
I've burned that iso file and do i keep the cd in this computer and do the restarting etc or put it into the computer i want to fix now?Put the burned disk in the other computer.

When starting you will need to tap F12 to get to the boot menu and choose to boot from the disk.ok booted up computer using cd and it takes me to a blue screen with 3 options:

To SET up WINDOWS xp now,press enter

To repair a windows xp installation using recovery console, press r

To quit setup without installing windows xp, press f3

which one is it i have to go on (sorry for being a bit slow lol, dont want to do anythin wrong )Quote

To repair a windows xp installation using recovery console, press r
ok it then says which windows installation would you like to log onto?

it only accepts one digit.What do you mean by it only accepts one digit?i TRIED to put that code thing in but after ive typed the "c" it doesnt let me type anything else, so not sure what to do at this stageAre you supposed to type R not C?How many Windows installs is it showing ? ?
Have you tried using the up/down arrow to highlight the selection and hit Enter ? ?

Sounds like you have a 2nd install of Windows from your repair efforts...nevermind my own stupidity there haha got it loading now and its 60% complete, need to go out just now will be back later, thanks guysCool. Keep us posted.no luck, when i restarted i still cant get on without it logging me straight back off:(with no harm ment. i really suggest this. the os is fine. its just a modified registry key that was hijacked by the infection. Again NO HARM MENT...

http://www.ehow.com/how_4527843_onlog-off-loop-windows-xp.htmlThat is a generic article and isn't going to help here. Besides. What they are asking to be done is THE SAME as what we are trying! Only here there is an open dialog here....

@ Alan Rfc1

Can you answer the questions Patio asked please. I'm really thinking you are looking at a reinstall.

Quote from: patio on January 27, 2010, 11:41:22 AM
How many Windows installs is it showing ? ?
Have you tried using the up/down arrow to highlight the selection and hit Enter ? ?

Sounds like you have a 2nd install of Windows from your repair efforts...
1685.

Solve : I've got a trojan hourse (or two) and can't get shot of it. "psw.generic7.bemv"?

Answer»

Quote

PS I'm stll geting the ocational website loading up unrequested any ideas ( didn't get this before the malware problem)
Which browser are you using?Hi SD, I'm using FireFox v3.6 with add-ons Adblock Plus, AVG Safe Guard ColorfulTabs, NoScript, Personas, Skype, WOT, plus some Java Console

This Morning I got this message:
see attached:-

I've checked Task Manager "Services" and Process ID 816 is PlugPlay and DcomLaunch again!

I'm suspecting I'm going to have to go down the clean install route. Is there a good/safe way of partitioning my C: drive with out losing the data and then moving my data across to the new drive without bring the infection across.


[Saving space, attachment deleted by admin]Update and run SAS and MBAM again. Just hold off on the re-format. I'm going to check with Evil about this new problem. Do you visit the website 'samdadsupport.com'?Nope I've not clicked on samdadsupport.com.

I've tried leaving firefox open and not using the computer for say 45mins and nothing happens but within 5mins of using it I get a new tab load up with various websites (that either NoScript or WOT warns me of danger.) this only happens once a secsion. I know its not the end of the world compared to the mess I was in when I first contacted you guys (thanks again for the help) but I'm still a bit woried that I have a problem.

I've not been clicking on anything and websites like this try and open.

___NO_CLICK_____http://www.ukprizedraw.co.uk/default.aspx?campid=105&affid=2741&subid=2284

I have already run SAS but it did not find any thing I will run MBAM again this weekend. Delete ComboFix and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Temporarily disable your ANTIVIRUS and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

Folder::
c:\users\Jamie\AppData\Roaming\lowsec

RegLockDel::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Download GooredFix from one of the locations below and save it to your desktop

Download Mirror #1
Download Mirror #2

* Ensure all Firefox windows are closed.
* To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
* When prompted to run the scan, click Yes.
* GooredFix will check for INFECTIONS, and then a log will appear.

Post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

----------

Download Rooter.exe to your desktop.

* Double click Rooter.exe to start the tool.
* A DOS window will appear and show the scan progress.
* Once complete a notepad file containing the report will open.
* Copy & paste the results in your next reply.
* Close notepad and Rooter will close.

A log will also save at C:\Rooter.txt

----------

Next post please add:

  • ComboFix log
  • GooredFix log
  • Rooter log
Followed your instructions to the letter. I have now turned back-on, AVG, AdAware and Spybot.




ComboFix 10-02-07.06 - Jamie 08/02/2010 9:27.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2036.1111 [GMT 0:00]
Running from: c:\users\Jamie\Desktop\ComboFix.exe
Command switches used :: c:\users\Jamie\Desktop\CFScript.txt
FW: Sunbelt Personal Firewall *disabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Jamie\AppData\Roaming\lowsec
c:\users\Jamie\AppData\Roaming\lowsec\local.ds
c:\users\Jamie\AppData\Roaming\lowsec\user.ds

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.

2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\Public\AppData\Local\temp
2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\IUSR_NMPR\AppData\Local\temp
2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\Default\AppData\Local\temp
2010-02-04 16:25 . 2010-02-05 17:48--------d-----w-c:\program files\SpywareBlaster
2010-02-02 15:11 . 2010-02-08 09:53--------d-----w-c:\users\Jamie\AppData\Local\temp
2010-01-29 15:23 . 2010-01-27 17:1915880----a-w-c:\windows\system32\lsdelete.exe
2010-01-28 14:10 . 2010-01-28 14:10--------d-----w-c:\program files\DiskCheckup
2010-01-28 14:10 . 2010-01-28 14:10--------d-----w-c:\windows\Sun
2010-01-27 16:44 . 2009-07-16 13:33157696----a-w-c:\users\Jamie\JavaRa.exe
2010-01-26 15:15 . 2010-02-04 16:28--------d-----w-c:\programdata\Spybot - Search & Destroy
2010-01-26 15:15 . 2010-01-26 15:18--------d-----w-c:\program files\Spybot - Search & Destroy
2010-01-26 10:23 . 2010-01-26 10:28--------d-----w-c:\program files\a-squared Free
2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\users\Jamie\AppData\Roaming\Malwarebytes
2010-01-25 21:08 . 2010-01-07 16:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\programdata\Malwarebytes
2010-01-25 21:08 . 2010-01-07 16:0719160----a-w-c:\windows\system32\drivers\mbam.sys
2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\programdata\SUPERAntiSpyware.com
2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com
2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\program files\SUPERAntiSpyware
2010-01-25 20:44 . 2010-01-25 20:44--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2010-01-25 17:17 . 2009-12-02 13:1964288----a-w-c:\windows\system32\drivers\Lbd.sys
2010-01-25 16:58 . 2010-01-25 16:59--------dc-h--w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-25 16:58 . 2010-01-25 16:58--------d-----w-c:\program files\Lavasoft
2010-01-21 16:57 . 2010-01-21 16:57--------d-----w-c:\users\Jamie\AppData\Local\HandBrake
2010-01-21 16:57 . 2010-01-21 16:57--------d-----w-c:\users\Jamie\AppData\Roaming\HandBrake
2010-01-20 00:52 . 2010-01-20 00:54--------d-----w-C:\ConverterOutput
2010-01-20 00:52 . 2004-10-12 14:42262144----a-w-c:\windows\system32\TomsMoComp_ff.dll
2010-01-20 00:52 . 2004-10-12 14:402255360----a-w-c:\windows\system32\libavcodec.dll
2010-01-20 00:52 . 2004-10-05 16:16395776----a-w-c:\windows\system32\libmplayer.dll
2010-01-20 00:52 . 2004-10-04 01:50112640----a-w-c:\windows\system32\libmpeg2_ff.dll
2010-01-20 00:52 . 2004-09-10 13:5034820----a-w-c:\windows\system32\ffdshow.reg
2010-01-20 00:52 . 2010-01-20 00:52--------d-----w-c:\program files\Cucusoft
2010-01-19 22:36 . 2010-02-04 17:10--------d-----w-c:\users\Jamie\AppData\Roaming\Auslogics
2010-01-19 22:36 . 2010-02-04 17:09--------d-----w-c:\program files\Auslogics
2010-01-14 16:20 . 2009-10-19 13:38156672----a-w-c:\windows\system32\t2embed.dll
2010-01-14 16:20 . 2009-10-19 13:3572704----a-w-c:\windows\system32\fontsub.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 09:55 . 2008-05-15 22:40--------d-----w-c:\programdata\Kontiki
2010-02-06 00:34 . 2009-11-24 16:04--------d-----w-c:\users\Jamie\AppData\Roaming\vlc
2010-02-05 13:55 . 2009-09-24 09:1519944----a-w-c:\windows\system32\drivers\atapi.sys
2010-02-05 09:19 . 2010-01-25 20:45117760----a-w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-04 17:17 . 2010-01-25 17:16389784----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-04 17:17 . 2010-01-25 17:093803208----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 17:17 . 2010-01-25 17:08823928----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-04 17:17 . 2010-01-25 17:061181328----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-04 16:11 . 2008-04-29 17:0275912----a-w-c:\users\Jamie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-02 14:10 . 2009-06-03 17:06--------d-----w-c:\users\Jamie\AppData\Roaming\uTorrent
2010-01-29 16:22 . 2008-04-10 16:32--------d-----w-c:\program files\Google
2010-01-28 14:03 . 2008-12-15 09:38411368----a-w-c:\windows\system32\deploytk.dll
2010-01-27 16:38 . 2008-04-10 16:26--------d-----w-c:\program files\Java
2010-01-27 16:37 . 2008-04-10 16:26--------d-----w-c:\program files\Common Files\Java
2010-01-25 20:45 . 2010-01-25 20:4552224----a-w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-25 16:58 . 2009-11-05 09:53--------d-----w-c:\programdata\Lavasoft
2010-01-22 11:28 . 2008-11-10 22:391----a-w-c:\users\Jamie\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-21 17:38 . 2008-04-29 17:18--------d-----w-c:\program files\Mozilla Thunderbird
2010-01-21 16:57 . 2009-03-05 23:05--------d-----w-c:\program files\HandBrake
2010-01-21 16:01 . 2009-08-12 19:27--------d-----w-c:\program files\Microsoft Silverlight
2010-01-19 23:59 . 2009-07-20 09:22--------d-----w-c:\program files\Common Files\Adobe
2010-01-14 16:57 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
2010-01-14 11:12 . 2009-10-02 17:01181120------w-c:\windows\system32\MpSigStub.exe
2010-01-12 22:27 . 2009-09-18 11:45--------d-----w-c:\users\Jamie\AppData\Roaming\Skype
2010-01-12 22:20 . 2009-09-18 11:47--------d-----w-c:\users\Jamie\AppData\Roaming\skypePM
2010-01-09 20:12 . 2008-05-05 14:00--------d-----w-c:\users\Jamie\AppData\Roaming\dvdcss
2010-01-02 06:38 . 2010-01-22 11:18916480----a-w-c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 11:1871680----a-w-c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 11:18109056----a-w-c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 11:18133632----a-w-c:\windows\system32\ieUnatt.exe
2009-12-29 13:39 . 2009-12-29 13:39--------d-----w-c:\program files\QuickTime
2009-12-29 13:39 . 2009-12-29 13:39--------d-----w-c:\programdata\Apple Computer
2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\program files\Common Files\Apple
2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\program files\Apple Software Update
2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\programdata\Apple
2009-12-29 13:22 . 2009-09-18 11:44--------d-----r-c:\program files\Skype
2009-12-29 13:14 . 2009-12-29 13:14--------d-----w-c:\program files\Secunia
2009-12-14 20:56 . 2008-06-28 11:05--------d-----w-c:\programdata\Roxio
2009-12-10 17:35 . 2009-12-10 17:35--------d-----w-c:\program files\Stardock
2009-12-10 17:35 . 2009-12-10 17:35--------d-----w-c:\program files\Common Files\Stardock
2009-12-10 17:31 . 2008-04-29 17:18--------d-----w-c:\users\Jamie\AppData\Roaming\Thunderbird
2009-12-07 14:10 . 2010-01-25 16:582953352-c--a-w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-12-04 10:34 . 2009-12-04 10:34784136----a-w-c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-25 17:42 . 2009-11-25 17:42291696----a-w-c:\users\Jamie\AppData\Roaming\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTR_8.0.50727.762.exe
2009-11-17 13:33 . 2009-07-28 09:28319456----a-w-c:\windows\DIFxAPI.dll
2009-11-10 10:33 . 2009-06-03 15:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-12-24 16:07 . 2008-12-22 09:46119808----a-w-c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-09-25 16:41 . 2009-09-25 16:411044480----a-w-c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41200704----a-w-c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-11 00:11 . 2008-04-10 23:588192--sha-w-c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-18 17920]
"NMSSupport"="c:\program files\Common Files\INTEL\IntelDH\NMS\Support\IntelHCTAgent.exe" [2007-06-27 439512]
"CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2007-06-27 215256]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-24 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 16384]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-04-25 280064]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-04-27 7420448]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-05 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-05 150552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2008-04-10 77824]

c:\users\Jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Broadband Download Monitor.lnk - c:\program files\Broadband Download Monitor\bdm.exe [2008-3-7 688128]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-12-10 3444008]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Software Director Scheduler.lnk - c:\program files\Common Files\Cloanto\Software Director\softdir.exe [2009-8-11 288328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
"EnableVirtualization"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):78,da,8f,f3,df,3d,ca,01

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [25/01/2010 17:17 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [03/06/2009 15:51 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [03/06/2009 15:51 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 07:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 07:56 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [26/01/2010 10:23 1858144]
R2 AERTFilters;Andrea RT FILTERS Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [17/11/2009 13:33 81920]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [27/10/2009 16:44 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [27/10/2009 16:43 285392]
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [12/02/2007 10:46 208896]
R2 NMSCore;Intel(R) NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [27/06/2007 09:14 317656]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [18/02/2007 19:34 5376]
R2 QualityManager;Intel(R) Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe [27/06/2007 09:17 272600]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13/11/2009 11:31 92008]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [28/05/2009 08:12 598856]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [10/04/2008 16:29 5632]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 07:56 7408]
S2 gupdate1c9f354452512a9;Google Update Service (gupdate1c9f354452512a9);c:\program files\Google\Update\GoogleUpdate.exe [22/06/2009 16:12 133104]
S3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [27/06/2007 09:15 39640]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [30/09/2008 07:30 21504]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\System32\drivers\ggflt.sys [09/06/2009 16:58 13224]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/04/2008 16:32 30192]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/12/2009 13:19 1181328]
S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [17/06/2009 12:20 12648]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [09/01/2009 10:42 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [09/01/2009 10:44 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [09/01/2009 10:44 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [09/01/2009 10:50 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [09/01/2009 10:54 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [09/01/2009 10:49 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [09/01/2009 10:51 110120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobileREG_MULTI_SZ wcescomm rapimgr
LocalServiceRestrictedREG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-02-08 c:\windows\Tasks\AutoSmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-19 15:30]

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 16:12]

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 16:12]

2010-02-02 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-19 15:30]

2010-02-08 c:\windows\Tasks\User_Feed_Synchronization-{FA4F8ED9-C3D2-43A5-B120-BB37897806F4}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.atcomet.com/b/
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://connect2.pb.com/dana-cached/sc/JuniperSetupClient.cab
FF - ProfilePath - c:\users\Jamie\AppData\Roaming\Mozilla\Firefox\Profiles\tga7fkpk.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut. enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi n", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 09:53
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\users\Jamie\AppData\Local\Temp\Cab18FC.tmp 29771 bytes
c:\users\Jamie\AppData\Local\Temp\Tar18FD.tmp 77580 bytes

scan completed successfully
hidden files: 2

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(4896)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\program files\Portrait Displays\Pivot Software\winphook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\IntelDH\CCU\AlertService.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Kontiki\KService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
c:\program files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\conime.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Portrait Displays\Pivot Software\floater.exe
c:\program files\Intel\IntelDH\CCU\CCU_Engine.exe
c:\program files\Secunia\PSI\psi.exe
.
**************************************************************************
.
Completion time: 2010-02-08 09:58:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-08 09:58

Pre-Run: 193,404,383,232 bytes free
Post-Run: 193,377,882,112 bytes free

- - End Of File - - AC84C96F6CA637E54AFB508ABA734AEE












GooredFix by jpshortstuff (08.01.10.1)
Log created at 10:12 on 08/02/2010 (Jamie)
Firefox version 3.6 (en-GB)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [17:15 29/04/2008]
{B13721C7-F507-4982-B2E5-502A71474FED} [11:45 18/09/2009]
{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [10:30 05/03/2009]
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [17:21 26/03/2009]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [07:40 31/08/2009]
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [14:04 28/01/2010]

C:\Users\Jamie\Application Data\Mozilla\Firefox\Profiles\tga7fkpk.default\extensions\
[emailprotected] [08:42 18/01/2010]
{0545b830-f0aa-4d7e-8820-50a4629a56fe} [16:47 04/02/2010]
{20a82645-c095-46ed-80e3-08825760534b} [07:31 11/07/2009]
{73a6fe31-595d-460b-a920-fcc0f8843232} [10:17 05/02/2010]
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [13:13 26/01/2010]
{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash [10:22 10/12/2009]
{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [08:42 18/01/2010]
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [20:12 09/01/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord" [17:18 09/05/2008]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [16:43 27/10/2009]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [15:53 09/06/2009]

-=E.O.F=-










Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows Vista Home Edition (6.0.6002) Service Pack 2
[32_bits] - x86 Family 6 Model 15 Stepping 13, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[MpsSvc] RUNNING (state:4)
Windows Firewall -> Enabled
Windows Defender -> Disabled !
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.6001.18882
Mozilla Firefox 3.6 (en-GB)
.
C:\ [Fixed-NTFS] .. ( Total:288 Go - Free:180 Go )
D:\ [Fixed-NTFS] .. ( Total:9 Go - Free:6 Go )
E:\ [CD_Rom]
F:\ [Fixed-FAT32] .. ( Total:232 Go - Free:30 Go )
G:\ [CD_Rom]
.
Scan : 10:13.27
Path : C:\Users\Jamie\Desktop\Rooter.exe
User : Jamie ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
______ \SystemRoot\System32\smss.exe (424)
______ C:\Windows\system32\csrss.exe (500)
______ C:\Windows\system32\wininit.exe (544)
______ C:\Windows\system32\csrss.exe (556)
______ C:\Windows\system32\services.exe (588)
______ C:\Windows\system32\lsass.exe (604)
______ C:\Windows\system32\lsm.exe (612)
______ C:\Windows\system32\winlogon.exe (656)
______ C:\Windows\system32\svchost.exe (816)
______ C:\Windows\system32\svchost.exe (880)
______ C:\Windows\System32\svchost.exe (1012)
______ C:\Windows\System32\svchost.exe (1044)
______ C:\Windows\system32\svchost.exe (1060)
Locked audiodg.exe (1168)
______ C:\Windows\system32\svchost.exe (1192)
______ C:\Windows\system32\SLsvc.exe (1212)
______ C:\Windows\system32\svchost.exe (1244)
______ C:\Windows\system32\svchost.exe (1424)
______ C:\Windows\System32\spoolsv.exe (1628)
______ C:\Windows\system32\svchost.exe (1652)
______ C:\Program Files\a-squared Free\a2service.exe (1804)
______ C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (1860)
______ C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (1880)
______ C:\Program Files\AVG\AVG9\avgwdsvc.exe (1896)
______ C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe (1920)
______ C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe (1948)
______ C:\Program Files\Kontiki\KService.exe (260)
______ C:\Program Files\AVG\AVG9\avgnsx.exe (1000)
______ C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (972)
______ C:\Windows\system32\svchost.exe (464)
______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe (1732)
______ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (688)
______ C:\Windows\system32\svchost.exe (2060)
______ C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (2088)
______ C:\Windows\System32\svchost.exe (2120)
______ C:\Windows\system32\SearchIndexer.exe (2204)
______ C:\Program Files\Webroot\Washer\WasherSvc.exe (2240)
______ C:\Program Files\AVG\AVG9\avgemc.exe (2316)
______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (2348)
______ C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (2368)
______ C:\Windows\system32\taskeng.exe (2520)
______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (2528)
______ C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (2852)
______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe (2896)
______ C:\Program Files\AVG\AVG9\avgchsvx.exe (2984)
______ C:\Program Files\AVG\AVG9\avgrsx.exe (2992)
______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (3020)
______ C:\Windows\system32\svchost.exe (3756)
______ C:\Windows\system32\Dwm.exe (156)
______ C:\Windows\system32\taskeng.exe (1724)
______ C:\Windows\Explorer.EXE (3904)
______ C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe (732)
______ C:\Windows\system32\taskeng.exe (720)
______ C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (3388)
______ C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (1980)
______ C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (3700)
______ C:\Windows\WindowsMobile\wmdSync.exe (2232)
______ C:\Program Files\Dell Support Center\bin\sprtcmd.exe (2676)
______ C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe (2912)
______ C:\Program Files\Portrait Displays\HP My Display\dthtml.exe (1828)
______ C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (3516)
______ C:\Windows\System32\igfxtray.exe (608)
______ C:\Windows\System32\hkcmd.exe (2592)
______ C:\Windows\System32\igfxpers.exe (3988)
______ C:\Program Files\Java\jre1.6.0\bin\jusched.exe (2804)
______ C:\Windows\ehome\ehtray.exe (476)
______ C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (3964)
______ C:\Program Files\Webroot\Washer\wwDisp.exe (1132)
______ C:\Windows\system32\igfxsrvc.exe (3900)
______ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (4208)
______ C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe (4216)
______ C:\Program Files\Broadband Download Monitor\bdm.exe (4224)
______ C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (4232)
______ C:\Windows\ehome\ehmsas.exe (4404)
______ C:\Program Files\Portrait Displays\Pivot Software\floater.exe (4620)
______ C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (4716)
______ C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (4752)
______ C:\Program Files\Secunia\PSI\psi.exe (5008)
______ C:\Windows\system32\conime.exe (5112)
______ C:\Users\Jamie\Desktop\Rooter.exe (5096)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:57544704)
\Device\Harddisk0\Partition2 (Start_Offset:57671680 | Length:10737418240)
\Device\Harddisk0\Partition3 --[ MBR ]-- (Start_Offset:10795089920 | Length:309276442624)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\AutoSmartDefrag.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
C:\Windows\Tasks\SmartDefrag.job
C:\Windows\Tasks\User_Feed_Synchronization-{FA4F8ED9-C3D2-43A5-B120-BB37897806F4}.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 10:13.36
.
C:\Rooter$\Rooter_1.txt - (08/02/2010 | 10:13.36)


atapi.sys

Please download SystemLook from one of the below links and save it to your desktop.

Link #1
Link #2

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

* Double-click SystemLook.exe to run it.
* Copy the contents of the following codebox into the main textfield.

Code: [Select]:filefind
*atapi*

* Click the Look button to start the scan.
* Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer).
* When finished, a notepad window will open with the results of the scan. Please post the log.

The log can also be found on your desktop entitled SystemLook.txtDisabled AVG, Spybot, Adaware, and SAS

Ran System look as requested.

Switch back on AVG, Spybot, Adaware, and SAS





SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 11:34 on 09/02/2010 by Jamie (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi*"
C:\Qoobox\Quarantine\C\Windows\System32\drivers\atapi.sys.vir--a--- 19944 bytes[09:15 24/09/2009][13:55 05/02/2010] F0CE0B2BD34E63C0D57139F0AE1C6747
C:\Users\Public\Documents\Amiga Files\System\dir\System\Devs\atapi.device--a--- 13172 bytes[17:29 11/08/2009][04:16 23/09/2003] D0396596015EAC86FB19552FE356F691
C:\Windows\ERDNT\cache\atapi.sys--a--- 19944 bytes[11:04 01/02/2010][13:55 05/02/2010] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\inf\iteatapi.inf--a--- 33660 bytes[10:25 02/11/2006][10:25 02/11/2006] E4EB9FDA7CA1965653EAB8C109CCE546
C:\Windows\inf\iteatapi.PNF--a--- 17916 bytes[10:25 02/11/2006][12:51 02/11/2006] 73DF176A398D10A2338BBD40B56EF72E
C:\Windows\System32\DriverStore\en-US\iteatapi.inf_loc--a--- 308 bytes[12:40 02/11/2006][12:40 02/11/2006] DBC002F0F2C65A0519A1BD24D84B22C2
C:\Windows\System32\DriverStore\FileRepository\iteatapi.inf_431397fb\iteatapi.inf--a--- 33660 bytes[10:25 02/11/2006][06:35 02/11/2006] E4EB9FDA7CA1965653EAB8C109CCE546
C:\Windows\System32\DriverStore\FileRepository\iteatapi.inf_431397fb\iteatapi.sys--a--- 35944 bytes[10:25 02/11/2006][09:50 02/11/2006] BCED60D16156E428F8DF8CF27B0DF150
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys--a--- 21688 bytes[23:58 10/04/2008][23:58 10/04/2008] 9E7E85EC61D1C9C3171CC08427108863
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5da5d093\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 61CA2C1E145809813C28752298CF9843
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] E03E8C99D15D0381E02743C36AFC7C6F
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_6c3af7d3\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 7EB55F6BEFB392BD312CD0CD5263305D
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] B35CFCEF838382AB6490B321C87EDF17
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] A779CA2C76DA4FCB595E692C05E8E4EB
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys--a--- 19944 bytes[09:15 24/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys--a--- 19048 bytes[10:25 02/11/2006][09:49 02/11/2006] 4F4FCB8B6EA06784FB6D475B7EC7300F
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys--a--- 21560 bytes[07:30 30/09/2008][07:41 19/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\System32\drivers\atapi.sys------ 19944 bytes[09:15 24/09/2009][13:55 05/02/2010] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\System32\drivers\iteatapi.sys--a--- 35944 bytes[07:36 02/11/2006][09:50 02/11/2006] BCED60D16156E428F8DF8CF27B0DF150
C:\Windows\System32\en-US\WinSATAPI.dll.mui--a--- 6144 bytes[12:41 02/11/2006][12:41 02/11/2006] 64BDEA749C5954CECAB7EC5E9CC24D39
C:\Windows\System32\WinSATAPI.dll--a--- 383488 bytes[07:31 30/09/2008][07:36 19/01/2008] 3FCB7347D2DE38488C85A31EA7838A3C
C:\Windows\winsxs\Manifests\x86_iteatapi.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20cdea2c37532736.manifest--a--- 1913 bytes[12:39 02/11/2006][12:39 02/11/2006] 99D99FA87B40A9FB8F9284AD0D7A71C9
C:\Windows\winsxs\x86_iteatapi.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20cdea2c37532736\iteatapi.inf_loc--a--- 308 bytes[12:40 02/11/2006][12:40 02/11/2006] DBC002F0F2C65A0519A1BD24D84B22C2
C:\Windows\winsxs\x86_microsoft-windows-w..emassessmenttoolapi_31bf3856ad364e35_6.0.6000.16386_none_e167a01dfaaf52f2\WinSATAPI.dll--a--- 382976 bytes[12:34 02/11/2006][12:34 02/11/2006] D5289700FAD39825C8A7BB20B7FC0A0D
C:\Windows\winsxs\x86_microsoft-windows-w..emassessmenttoolapi_31bf3856ad364e35_6.0.6001.18000_none_e39e6219f79a63c6\WinSATAPI.dll--a--- 383488 bytes[07:31 30/09/2008][07:36 19/01/2008] 3FCB7347D2DE38488C85A31EA7838A3C
C:\Windows\winsxs\x86_microsoft-windows-w..nttoolapi.resources_31bf3856ad364e35_6.0.6000.16386_en-us_86f384ab3e5358a7\WinSATAPI.dll.mui--a--- 6144 bytes[12:41 02/11/2006][12:41 02/11/2006] 64BDEA749C5954CECAB7EC5E9CC24D39
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] A779CA2C76DA4FCB595E692C05E8E4EB
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16470_none_db063634249c06f4\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 7EB55F6BEFB392BD312CD0CD5263305D
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] B35CFCEF838382AB6490B321C87EDF17
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] 5653737BAD8C6C10136451C195C19881
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys--a--- 21688 bytes[23:58 10/04/2008][23:58 10/04/2008] 9E7E85EC61D1C9C3171CC08427108863
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20580_none_db8503133dc1c2af\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 61CA2C1E145809813C28752298CF9843
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] E03E8C99D15D0381E02743C36AFC7C6F
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys--a--- 21560 bytes[07:30 30/09/2008][07:41 19/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys--a--- 19944 bytes[09:15 24/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4

-=End Of File=-* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Log
F:\My docs backup 2008 04 29\Programs\files\click_me_insults.htmlprobably a variant of JS/Seeker.AF trojancleaned by deleting - quarantined


F: is my external USB backup drive that was thankfully not connected when all this trouble started.If there are no more malware issues we can finish up now.


Use the Secunia Software Inspector to check for out of date software.

* Click Start Now
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Cheers for all the help guys.Your welcome.

Safe surfing...
1686.

Solve : Virus effect hep with explorer / file manager?

Answer»

Hi All

Windows 7 OS

I have had a virus or trojan which i think I have got rid of but am left with the after effects. I don't know what the virus was.

It has left a problem with explorer / file manager, I cant create a new folder by pressing the new folder button, probably other effects as well not yet seen. It was stopping me seeing a directory holding infected files, cured now.

Is it possible to re-install just this part of the OS without having to do a full system restor which would cause problems for me

Thanks for any help
JohnPlease visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.Thank's for the prompt reply

I was forced to reinstall the OS as even restor had been corrupted. Luckily the update option seems to have kept my software and settings intact. I have also installed bit defender antivirus as windows security essentials was obviously not up to the job.

OK. I have run the scan and will attach the log. I had to run it twice as I hadn't disabled the anti virus.

It looks like there are still some issues to be resolved

Thanks for your time and help
JohnLog File


ComboFix 10-02-01.03 - John 1 02/02/2010 13:41:14.2.1 - x86
Microsoft Windows 7 Ultimate 6.1.7100.0.1252.44.1033.18.2039.1258 [GMT 0:00]
Running from: c:\users\John 1\Downloads\Anti Spy and Virus files\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.

2010-02-02 13:54 . 2010-02-02 13:54--------d-----w-c:\users\Public\AppData\Local\temp
2010-02-02 13:54 . 2010-02-02 13:54--------d-----w-c:\users\Default\AppData\Local\temp
2010-02-02 13:39 . 2010-02-02 13:40--------d-----w-C:\32788R22FWJFW
2010-02-02 13:26 . 2010-02-02 13:54--------d-----w-c:\users\John 1\AppData\Local\temp
2010-02-02 12:45 . 2010-02-02 09:05--------d-----w-c:\windows\Panther
2010-02-02 12:32 . 2010-02-02 05:49--------d-----w-C:\$WINDOWS.~Q
2010-02-02 12:24 . 2010-02-02 12:28--------d-----w-C:\$INPLACE.~TR
2010-02-02 09:39 . 2009-07-08 21:53194560----a-w-c:\windows\system32\ListSvc.dll
2010-02-02 09:29 . 2009-07-18 03:28299520----a-w-c:\windows\system32\wmpdxm.dll
2010-02-02 09:27 . 2009-09-10 03:10306688----a-w-c:\windows\system32\drivers\srv2.sys
2010-02-02 09:10 . 2010-02-02 09:10102072----a-w-c:\users\John 1\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-02 06:03 . 2010-02-02 09:48--------d-----w-c:\windows\system32\wbem\Performance
2010-02-02 05:46 . 2010-02-02 05:4621924----a-w-c:\windows\system32\emptyregdb.dat
2010-02-02 04:52 . 2010-02-02 04:52--------d-----w-c:\windows\system32\URTTEMP
2010-02-02 04:51 . 2010-02-02 09:28--------d-sh--w-c:\windows\Installer
2010-02-02 04:50 . 2010-02-02 05:00--------d-----w-c:\program files\CONEXANT
2010-02-02 04:50 . 2010-02-02 04:50--------d-----w-c:\windows\system32\RTCOM
2010-02-02 04:49 . 2010-02-02 04:49--------d-----w-c:\program files\Synaptics
2010-02-01 21:15 . 2010-02-02 05:06--------d-----w-c:\program files\Trend Micro
2010-02-01 16:19 . 2010-02-01 16:19132----a-w-c:\windows\system32\rezumatenoi.dat
2010-02-01 16:15 . 2010-02-02 05:00--------d-----w-c:\program files\Common Files\Windows Live
2010-02-01 16:14 . 2010-02-02 05:05--------d-----w-c:\program files\Microsoft
2010-02-01 15:32 . 2010-02-01 15:320----a-w-C:\pcwords2.dat
2010-02-01 15:32 . 2010-02-01 15:320----a-w-C:\pcwords.dat
2010-02-01 15:23 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\BitDefender
2010-02-01 15:23 . 2010-02-02 05:07--------d-----w-c:\programdata\BitDefender
2010-02-01 15:23 . 2010-02-02 04:58--------d-----w-c:\program files\BitDefender
2010-02-01 15:22 . 2010-02-02 04:59--------d-----w-c:\program files\Common Files\BitDefender
2010-01-30 14:34 . 2010-02-02 05:01--------d-----w-c:\program files\Glary Utilities
2010-01-30 13:51 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\GlarySoft
2010-01-28 19:30 . 2009-09-14 09:2114848----a-w-c:\windows\system32\EuEpmGdi.dll
2010-01-28 19:30 . 2009-11-21 11:181673216----a-w-c:\windows\system32\BootMan.exe
2010-01-28 19:30 . 2009-09-16 16:558456----a-w-c:\windows\system32\EuGdiDrv.sys
2010-01-28 19:30 . 2009-08-26 12:4514216----a-w-c:\windows\system32\epmntdrv.sys
2010-01-28 19:30 . 2009-04-22 14:2886408----a-w-c:\windows\system32\setupempdrv03.exe
2010-01-28 19:30 . 2010-02-02 05:01--------d-----w-c:\program files\EASEUS
2010-01-27 16:22 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\InnovMetric
2010-01-27 16:22 . 2010-02-02 05:26--------d-----w-c:\users\John 1\.innovmetric
2010-01-27 16:19 . 2010-02-02 05:03--------d-----w-c:\program files\InnovMetric
2010-01-26 14:43 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\NewsLeecher
2010-01-26 14:42 . 2010-02-02 05:06--------d-----w-c:\program files\NewsLeecher
2010-01-26 01:32 . 2010-01-16 12:30278528----a-w-c:\windows\SYCLicense_100115.dll
2010-01-25 13:53 . 2010-01-25 13:5336864----a-w-c:\users\John 1\AppData\Roaming\Autodesk\AutoCAD 2010\R18.0\enu\ContextualTabSelectorRules.dll
2010-01-25 13:38 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\Autodesk
2010-01-25 13:38 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\Autodesk
2010-01-25 13:38 . 2010-02-02 05:07--------d-----w-c:\programdata\Autodesk
2010-01-25 13:38 . 2010-02-02 04:58--------d-----w-c:\program files\AutoCAD 2010
2010-01-25 13:38 . 2008-03-05 15:561420824----a-w-c:\windows\system32\D3DCompiler_37.dll
2010-01-25 13:38 . 2008-02-05 23:07462864----a-w-c:\windows\system32\d3dx10_37.dll
2010-01-25 13:37 . 2008-03-05 15:563786760----a-w-c:\windows\system32\D3DX9_37.dll
2010-01-25 13:35 . 2010-02-02 04:59--------d-----w-c:\program files\Common Files\Autodesk Shared
2010-01-25 13:35 . 2010-02-02 04:58--------d-----w-c:\program files\Autodesk
2010-01-25 00:39 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\GrabIt
2010-01-25 00:37 . 2010-02-02 05:02--------d-----w-c:\program files\GrabIt
2010-01-24 17:23 . 2008-11-07 21:082134016----a-w-c:\windows\system32\cdintf251.dll
2010-01-24 16:02 . 2007-11-15 19:21245760----a-w-c:\windows\SYCLicense071115.dll
2010-01-24 15:46 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\NewzToolz-EZ
2010-01-24 15:45 . 2010-02-02 05:06--------d-----w-c:\program files\NewzToolz-EZ
2010-01-23 16:03 . 2010-02-02 05:07--------d-----w-c:\program files\VRMesh v4.1 Studio demo
2010-01-22 22:01 . 2010-02-02 05:05--------d-----w-c:\program files\INUS Technology
2010-01-22 01:31 . 2010-02-02 04:59--------d-----w-c:\program files\Common Files\Bcgsoft
2010-01-22 01:30 . 2010-02-02 05:07--------d-----w-c:\programdata\FLEXnet
2010-01-22 01:30 . 2010-02-02 04:59--------d-----w-c:\program files\Common Files\Macrovision Shared
2010-01-22 01:21 . 2010-02-02 05:06--------d-----w-c:\program files\RapidForm INUS Technology
2010-01-21 23:22 . 2007-08-29 17:316489088----a-w-c:\temp\Rapidform XOR2.msi
2010-01-21 23:22 . 2010-01-21 23:22--------d-----w-c:\temp\program files
2010-01-21 19:34 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\Binverse
2010-01-21 19:33 . 2010-02-02 04:58--------d-----w-c:\program files\Binverse
2010-01-16 21:31 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\Nokia Ovi Suite
2010-01-16 21:31 . 2010-02-02 05:07--------d-----w-c:\programdata\Nokia
2010-01-16 21:17 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\Nokia
2010-01-16 21:17 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\Nokia
2010-01-16 21:17 . 2010-02-02 05:07--------d-----w-c:\programdata\PC Suite
2010-01-16 21:17 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\PC Suite
2010-01-16 21:17 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\NokiaAccount
2010-01-16 21:12 . 2010-02-02 05:00--------d-----w-c:\program files\Common Files\Nokia
2010-01-16 21:11 . 2010-02-02 05:01--------d-----w-c:\program files\DIFX
2010-01-16 21:11 . 2008-08-26 09:2618816----a-w-c:\windows\system32\drivers\pccsmcfd.sys
2010-01-16 21:10 . 2010-02-02 05:09--------dc----w-c:\windows\system32\DRVSTORE
2010-01-16 21:10 . 2010-02-02 05:06--------d-----w-c:\program files\PC Connectivity Solution
2010-01-16 21:06 . 2009-10-06 11:5291136----a-w-c:\windows\system32\nmwcdcls.dll
2010-01-16 21:04 . 2010-01-16 21:0412212040----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-01-16 21:04 . 2010-01-16 21:0413930312----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-01-16 21:04 . 2010-01-16 21:0477824----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2010-01-16 21:04 . 2010-01-16 21:0461440----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-01-16 21:04 . 2010-01-16 21:0458880----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-01-16 21:04 . 2010-01-16 21:0450000----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
2010-01-16 21:04 . 2010-01-16 21:0495992424----a-w-c:\programdata\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Nokia_Ovi_Suite_webinstaller_ALL.exe
2010-01-16 21:04 . 2010-02-02 05:07--------d-----w-c:\programdata\OviInstallerCache
2010-01-16 21:04 . 2010-02-02 05:06--------d-----w-c:\program files\Nokia
2010-01-16 20:55 . 2010-02-02 05:07--------d-----w-c:\programdata\Installations
2010-01-15 12:08 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\ROUTE 66 Sync
2010-01-15 12:08 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\ROUTE 66 Sync 9
2010-01-15 12:07 . 2010-02-02 05:00--------d-----w-c:\program files\Common Files\ROUTE 66
2010-01-15 12:07 . 2010-02-02 05:06--------d-----w-c:\program files\ROUTE 66
2010-01-15 11:56 . 2010-02-02 05:27--------d-----w-c:\users\John 1\AppData\Roaming\InstallShield
2010-01-14 01:30 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\Apps
2010-01-14 00:59 . 2010-02-02 05:06--------d-----w-c:\program files\ViaMichelin
2010-01-13 17:56 . 2010-02-02 05:02--------d-----w-c:\program files\Google
2010-01-13 17:55 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\Google
2010-01-13 13:07 . 2010-01-13 13:0721630----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{4E7D086E-AAA8-478B-A355-0CD63803E9CE}\ARPPRODUCTICON.exe
2010-01-13 13:07 . 2010-02-02 05:06--------d-----w-c:\program files\Trackmaker
2010-01-13 13:05 . 2010-01-13 13:0561440----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{08E0DD99-935D-4AF3-AF63-5774C3D8B1A4}\NewShortcut1_80F769F1DC2041DDA97C9B268A894D95.exe
2010-01-13 13:05 . 2010-01-13 13:0521630----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{08E0DD99-935D-4AF3-AF63-5774C3D8B1A4}\ARPPRODUCTICON.exe
2010-01-13 13:05 . 2010-02-02 05:02--------d-----w-c:\program files\GTMPRO
2010-01-13 13:04 . 2010-02-02 05:26--------d-----w-c:\users\John 1\AppData\Local\Downloaded Installations
2010-01-13 12:46 . 2010-01-13 12:463026----a-w-c:\windows\system32\drivers\hwinterface.sys
2010-01-11 20:16 . 2006-05-03 17:176144----a-w-c:\windows\system32\drivers\ZNTPORT.SYS
2010-01-11 20:16 . 2006-04-30 09:25108544----a-w-c:\windows\system32\Ntport.dll
2010-01-11 20:16 . 2010-02-02 05:05--------d-----w-c:\program files\intricad
2010-01-11 20:16 . 2009-06-19 03:2068232----a-w-c:\windows\UnDeployV.exe
2010-01-11 20:13 . 2010-01-22 15:23--------d-----w-c:\program files\oZone3D
2010-01-10 22:12 . 2009-09-01 17:01278528----a-w-c:\windows\SYCLicense_090901.dll
2010-01-10 22:12 . 2008-11-07 14:292174976----a-w-c:\windows\SKPWriter.dll
2010-01-10 22:12 . 2007-03-22 18:422359296----a-w-c:\windows\xerces-c_2_6.dll
2010-01-10 22:12 . 2010-01-08 17:203088384----a-w-c:\windows\DXLib80U.dll
2010-01-10 22:12 . 2009-12-03 10:10884736----a-w-c:\windows\SKPUtils.exe
2010-01-10 22:12 . 2009-11-12 16:002355200----a-w-c:\windows\SurfaceLib.dll
2010-01-10 22:12 . 2009-12-03 09:54917504----a-w-c:\windows\SKPLib.dll
2010-01-10 22:12 . 2010-01-08 15:443309568----a-w-c:\windows\DXLib60.dll
2010-01-10 22:12 . 2009-12-16 17:299494528----a-w-c:\windows\DDLib.dll
2010-01-10 22:12 . 2009-11-12 14:151056768----a-w-c:\windows\SYCGeo.dll
2010-01-10 22:12 . 2009-12-02 19:24532480----a-w-c:\windows\SYCGUI.dll
2010-01-10 22:11 . 2010-02-02 05:06--------d-----w-c:\program files\SYCODE
2010-01-10 17:02 . 2010-02-02 05:00--------d-----w-c:\program files\*censored* NFO Viewer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 05:28 . 2009-07-18 10:06--------d-----w-c:\users\John 1\AppData\Roaming\TomTom
2010-02-02 05:27 . 2009-06-19 18:46--------d-----w-c:\users\John 1\AppData\Roaming\Sykes Pickavant
2010-02-02 05:27 . 2009-05-11 16:59--------d-----w-c:\users\John 1\AppData\Roaming\Thunderbird
2010-02-02 05:27 . 2009-11-25 02:16--------d-----w-c:\users\John 1\AppData\Roaming\PS-Exchange
2010-02-02 05:27 . 2009-05-17 15:48--------d-----w-c:\users\John 1\AppData\Roaming\OpenOffice.org
2010-02-02 05:27 . 2009-12-08 19:17--------d-----w-c:\users\John 1\AppData\Roaming\CamBam
2010-02-02 05:27 . 2009-12-08 19:06--------d-----w-c:\users\John 1\AppData\Roaming\gtk-2.0
2010-02-02 05:27 . 2009-12-08 18:07--------d-----w-c:\users\John 1\AppData\Roaming\inkscape
2010-02-02 05:27 . 2009-11-03 23:52--------d-----w-c:\users\John 1\AppData\Roaming\ImgBurn
2010-02-02 05:27 . 2009-06-20 17:57--------d-----w-c:\users\John 1\AppData\Roaming\Cogniview
2010-02-02 05:27 . 2009-05-17 20:47--------d-----w-c:\users\John 1\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-02-02 05:07 . 2009-07-07 09:59--------d-----w-c:\programdata\SystemExplorer
2010-02-02 05:07 . 2009-12-14 21:48--------d-----w-c:\programdata\McNeel
2010-02-02 05:07 . 2009-12-02 11:05--------d-----w-c:\programdata\InstallShield
2010-02-02 05:07 . 2009-06-20 17:56--------d-----w-c:\programdata\Cogniview
2010-02-02 05:07 . 2009-12-03 11:08--------d-----w-c:\programdata\Apple Computer
2010-02-02 05:07 . 2009-12-03 11:05--------d-----w-c:\programdata\Apple
2010-02-02 05:07 . 2009-05-08 17:21--------d-----w-c:\program files\winbond
2010-02-02 05:05 . 2009-06-22 11:52--------d-----w-c:\program files\Microsoft ActiveSync
2010-02-02 05:05 . 2009-07-19 11:20--------d-----w-c:\program files\MediaCoder Audio Edition
2010-02-02 05:05 . 2009-07-16 17:14--------d-----w-c:\program files\LizardTech
2010-02-02 05:05 . 2009-05-14 20:30--------d-----w-c:\program files\Java
2010-02-02 05:05 . 2009-06-20 17:00--------d-----w-c:\program files\Investintech.com Inc
2010-02-02 05:05 . 2009-05-08 17:07--------d--h--w-c:\program files\InstallShield Installation Information
2010-02-02 05:02 . 2009-12-08 17:50--------d-----w-c:\program files\Inkscape
2010-02-02 05:02 . 2009-11-03 23:46--------d-----w-c:\program files\ImgBurn
2010-02-02 05:02 . 2009-08-02 10:02--------d-----w-c:\program files\Hitachi
2010-02-02 05:01 . 2009-12-08 19:00--------d-----w-c:\program files\GIMP-2.0
2010-02-02 05:01 . 2009-06-21 14:10--------d-----w-c:\program files\Foxit Software
2010-02-02 05:01 . 2009-11-04 10:40--------d-----w-c:\program files\Delcam
2010-02-02 05:00 . 2009-12-11 14:33--------d-----w-c:\program files\DAVID-Laserscanner
2010-02-02 05:00 . 2009-05-18 11:50--------d-----w-c:\program files\Convert
2010-02-02 05:00 . 2009-12-15 00:36--------d-----w-c:\program files\Common Files\Solidworks Shared
2010-02-02 05:00 . 2009-11-04 10:40--------d-----w-c:\program files\Common Files\SafeNet Sentinel
2010-02-02 04:59 . 2009-06-21 12:09--------d-----w-c:\program files\Common Files\L&H
2010-02-02 04:59 . 2009-05-14 20:29--------d-----w-c:\program files\Common Files\Java
2010-02-02 04:59 . 2009-05-08 17:06--------d-----w-c:\program files\Common Files\InstallShield
2010-02-02 04:59 . 2009-11-04 00:09--------d-----w-c:\program files\Common Files\EZB Systems
2010-02-02 04:59 . 2009-07-05 13:58--------d-----w-c:\program files\Common Files\Autodata Limited Shared
2010-02-02 04:59 . 2009-12-03 11:06--------d-----w-c:\program files\Common Files\Apple
2010-02-02 04:59 . 2009-11-24 19:34--------d-----w-c:\program files\Common Files\Aladdin Shared
2010-02-02 04:59 . 2009-05-17 10:54--------d-----w-c:\program files\Common Files\Adobe AIR
2010-02-02 04:59 . 2009-05-14 20:46--------d-----w-c:\program files\Common Files\Adobe
2010-02-02 04:59 . 2009-12-08 19:13--------d-----w-c:\program files\CamBam
2010-02-02 04:59 . 2009-06-20 17:56--------d-----w-c:\program files\CogniView
2010-02-02 04:59 . 2009-12-02 11:11--------d-----w-c:\program files\BobCAD-CAM
2010-02-02 04:58 . 2009-06-21 14:10--------d-----w-c:\program files\AskBarDis
2010-02-02 04:58 . 2009-11-25 02:12--------d-----w-c:\program files\ArtCAM 2008
2010-02-02 04:57 . 2009-11-26 11:13--------d-----w-c:\program files\Ares
2010-02-02 04:57 . 2009-12-03 11:05--------d-----w-c:\program files\Apple Software Update
2010-02-02 04:49 . 2010-02-02 04:490---ha-w-c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-01-30 15:42 . 2009-06-22 13:28--------d-----w-c:\program files\HotHotSoftware
2010-01-16 21:22 . 2010-01-16 21:220---ha-w-c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-01-16 21:20 . 2010-01-16 21:200---ha-w-c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-01-14 11:12 . 2009-10-12 09:56181120----a-w-c:\windows\system32\MpSigStub.exe
2010-01-08 15:05 . 2009-12-08 19:134846----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{B2265534-1B17-4626-8FB4-74EBF149D354}\_D707CE1C009F1381803C2C.exe
2010-01-08 15:05 . 2009-12-08 19:134846----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{B2265534-1B17-4626-8FB4-74EBF149D354}\_6FEFF9B68218417F98F549.exe
2010-01-08 15:05 . 2009-12-08 19:134846----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{B2265534-1B17-4626-8FB4-74EBF149D354}\_2E79741372BE45714ACB8B.exe
2010-01-08 15:05 . 2009-12-08 19:134846----a-w-c:\users\John 1\AppData\Roaming\Microsoft\Installer\{B2265534-1B17-4626-8FB4-74EBF149D354}\_21F3885A18D238E15AAE81.exe
2009-12-14 21:49 . 2009-12-14 21:49400----a-w-c:\windows\system32\drivers\egxkxz_244.set
2009-12-14 21:49 . 2009-12-14 21:49400----a-w-c:\windows\system32\drivers\biusvhm792.dat
2009-12-13 21:46 . 2009-05-07 09:42--------d-----w-c:\program files\CA
2009-12-07 18:49 . 2009-12-07 18:49105736----a-w-c:\windows\system32\drivers\bdhv.sys
2009-12-07 18:46 . 2009-12-07 18:46152456----a-w-c:\windows\system32\drivers\bdfm.sys
2009-11-24 20:07 . 2009-11-24 20:076656----a-w-c:\windows\system32\haspvdd.dll
2009-11-24 20:07 . 2009-11-24 20:0747616----a-w-c:\windows\system32\drivers\Haspnt.sys
2009-11-24 20:07 . 2009-11-24 20:07383----a-w-c:\windows\system32\haspdos.sys
2009-11-24 20:07 . 2009-11-24 20:07291328----a-w-c:\windows\system32\hlvdd.dll
2009-03-27 04:24 . 2009-04-22 05:589633792--sha-r-c:\windows\Fonts\StaticCache.dat
2009-04-22 05:19 . 2009-04-22 03:40396800--sha-w-c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7100.0_none_624b25e9a4cb0444\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SharingPrivate]
@="{08244EE6-92F0-47f2-9FC9-929BAA2E7235}"
[HKEY_CLASSES_ROOT\CLSID\{08244EE6-92F0-47f2-9FC9-929BAA2E7235}]
2009-04-22 05:21441856----a-w-c:\windows\System32\ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-10-09 102400]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 14743552]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 90112]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-26 2806784]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2010-02-01 1120704]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WWU.lnk - c:\program files\winbond\w89c33\wwu.exe [2009-11-30 931840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

R0 amdxata;amdxata;c:\windows\System32\drivers\amdxata.sys [22/04/2009 02:07 23120]
R0 CLFS;Common Log (CLFS);c:\windows\System32\clfs.sys [22/04/2009 03:08 249424]
R0 CNG;CNG;c:\windows\System32\drivers\cng.sys [22/04/2009 03:31 369056]
R0 FileInfo;File Information FS MiniFilter;c:\windows\System32\drivers\fileinfo.sys [22/04/2009 03:19 58448]
R0 fvevol;Bitlocker Drive Encryption Filter Driver;c:\windows\System32\drivers\fvevol.sys [22/04/2009 03:10 194488]
R0 hwpolicy;Hardware Policy Driver;c:\windows\System32\drivers\hwpolicy.sys [22/04/2009 03:08 13904]
R0 KSecPkg;KSecPkg;c:\windows\System32\drivers\ksecpkg.sys [22/04/2009 03:32 133200]
R0 msisadrv;msisadrv;c:\windows\System32\drivers\msisadrv.sys [22/04/2009 03:08 13904]
R0 pcw;Performance Counters for Windows Driver;c:\windows\System32\drivers\pcw.sys [22/04/2009 03:08 42576]
R0 rdyboost;ReadyBoost;c:\windows\System32\drivers\rdyboost.sys [22/04/2009 03:19 173648]
R0 spldr;Security Processor Loader Driver;c:\windows\System32\drivers\spldr.sys [22/04/2009 00:36 17488]
R0 storflt;Disk Virtual Machine Bus Acceleration Filter Driver;c:\windows\System32\drivers\vmstorfl.sys [22/04/2009 10:23 40912]
R0 vdrvroot;Microsoft Virtual Drive Enumerator Driver;c:\windows\System32\drivers\vdrvroot.sys [22/04/2009 03:44 32848]
R0 volmgr;Volume Manager Driver;c:\windows\System32\drivers\volmgr.sys [22/04/2009 03:08 52304]
R0 volmgrx;Dynamic Volume Manager;c:\windows\System32\drivers\volmgrx.sys [22/04/2009 03:09 297040]
R1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [19/10/2009 16:04 79368]
R1 blbdrive;blbdrive;c:\windows\System32\drivers\blbdrive.sys [22/04/2009 03:20 35328]
R1 CSC;Offline Files Driver;c:\windows\System32\drivers\csc.sys [22/04/2009 03:12 387584]
R1 DfsC;DFS Namespace Client Driver;c:\windows\System32\drivers\dfsc.sys [22/04/2009 03:11 78336]
R1 discache;System Attribute Cache;c:\windows\System32\drivers\discache.sys [22/04/2009 03:21 32768]
R1 hwinterface;hwinterface;c:\windows\System32\drivers\hwinterface.sys [13/01/2010 12:46 3026]
R1 nsiproxy;NSI proxy service driver.;c:\windows\System32\drivers\nsiproxy.sys [22/04/2009 03:09 16896]
R1 RDPENCDD;RDP Encoder Mirror Driver;c:\windows\System32\drivers\RDPENCDD.sys [22/04/2009 04:00 6656]
R1 RDPREFMP;Reflector Display Driver used to gain access to graphics data;c:\windows\System32\drivers\RDPREFMP.sys [22/04/2009 04:00 7168]
R1 tdx;NetIO Legacy TDI Support Driver;c:\windows\System32\drivers\tdx.sys [22/04/2009 03:09 74240]
R1 Wanarpv6;Remote Access IPv6 ARP Driver;c:\windows\System32\drivers\wanarp.sys [22/04/2009 03:53 63488]
R1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\System32\drivers\wbsecdrv.sys [08/05/2009 17:21 17664]
R1 WfpLwf;WFP Lightweight Filter;c:\windows\System32\drivers\wfplwf.sys [22/04/2009 03:52 9728]
R2 AudioEndpointBuilder;Windows Audio Endpoint Builder;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22/04/2009 03:16 20992]
R2 BFE;Base Filtering Engine;c:\windows\system32\svchost.exe -k LocalServiceNoNetwork [22/04/2009 03:16 20992]
R2 CscService;Offline Files;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22/04/2009 03:16 20992]
R2 DPS;Diagnostic Policy Service;c:\windows\System32\svchost.exe -k LocalServiceNoNetwork [22/04/2009 03:16 20992]
R2 FDResPub;Function Discovery Resource Publication;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22/04/2009 03:16 20992]
R2 gpsvc;Group Policy Client;c:\windows\system32\svchost.exe -k netsvcs [22/04/2009 03:16 20992]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [22/04/2009 03:16 20992]
R2 iphlpsvc;IP Helper;c:\windows\System32\svchost.exe -k NetSvcs [22/04/2009 03:16 20992]
R2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;c:\windows\System32\drivers\lltdio.sys [22/04/2009 03:51 48128]
R2 luafv;UAC File Virtualization;c:\windows\System32\drivers\luafv.sys [22/04/2009 03:13 86528]
R2 PEAUTH;PEAUTH;c:\windows\System32\drivers\PEAuth.sys [22/04/2009 03:33 586752]
R2 tcpipreg;TCP/IP Registry Compatibility;c:\windows\System32\drivers\tcpipreg.sys [22/04/2009 03:52 34816]
R3 1394ohci;1394 OHCI Compliant Host Controller;c:\windows\System32\drivers\1394ohci.sys [22/04/2009 03:50 162816]
R3 Appinfo;Application Information;c:\windows\system32\svchost.exe -k netsvcs [22/04/2009 03:16 20992]
R3 BDFM;BDFM;c:\windows\System32\drivers\bdfm.sys [07/12/2009 18:46 152456]
R3 bowser;Browser Support Driver;c:\windows\System32\drivers\bowser.sys [22/04/2009 03:11 69632]
R3 CertPropSvc;Certificate Propagation;c:\windows\system32\svchost.exe -k netsvcs [22/04/2009 03:16 20992]
R3 CompositeBus;Composite Bus Enumerator Driver;c:\windows\System32\drivers\CompositeBus.sys [22/04/2009 03:43 31232]
R3 fdPHost;Function Discovery Provider Host;c:\windows\system32\svchost.exe -k LocalService [22/04/2009 03:16 20992]
R3 HomeGroupProvider;HomeGroup Provider;c:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted [22/04/2009 03:16 20992]
R3 KeyIso;CNG Key Isolation;c:\windows\System32\lsass.exe [22/04/2009 03:09 22528]
R3 monitor;Microsoft Monitor Class Function Driver Service;c:\windows\System32\drivers\monitor.sys [22/04/2009 03:23 23552]
R3 mpsdrv;Windows Firewall Authorization Driver;c:\windows\System32\drivers\mpsdrv.sys [22/04/2009 03:51 60416]
R3 mrxsmb10;SMB 1.x MiniRedirector;c:\windows\System32\drivers\mrxsmb10.sys [22/04/2009 03:11 220672]
R3 mrxsmb20;SMB 2.0 MiniRedirector;c:\windows\System32\drivers\mrxsmb20.sys [22/04/2009 03:11 94720]
R3 NativeWifiP;NativeWiFi Filter;c:\windows\System32\drivers\nwifi.sys [22/04/2009 03:50 267264]
R3 RasAgileVpn;WAN Miniport (IKEv2);c:\windows\System32\drivers\agilevpn.sys [22/04/2009 03:53 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver;c:\windows\System32\drivers\rdpbus.sys [22/04/2009 04:01 18432]
R3 srv2;Server SMB 2.xxx Driver;c:\windows\System32\drivers\srv2.sys [02/02/2010 09:27 306688]
R3 srvnet;srvnet;c:\windows\System32\drivers\srvnet.sys [22/04/2009 03:12 113664]
R3 tssecsrv;Remote Desktop Services Security Filter Driver;c:\windows\System32\drivers\tssecsrv.sys [22/04/2009 04:00 30208]
R3 tunnel;Microsoft Tunnel Miniport Adapter Driver;c:\windows\System32\drivers\tunnel.sys [22/04/2009 03:52 108032]
R3 umbus;UMBus Enumerator Driver;c:\windows\System32\drivers\umbus.sys [22/04/2009 03:50 39936]
R3 W33ND;W89C33 mPCI 802.11 Wireless LAN Adapter Driver;c:\windows\System32\drivers\W33ND.SYS [08/05/2009 17:21 124160]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/01/2010 17:56 135664]
S3 AcpiPmi;ACPI Power Meter Driver;c:\windows\System32\drivers\acpipmi.sys [22/04/2009 03:13 9728]
S3 adp94xx;adp94xx;c:\windows\System32\drivers\adp94xx.sys [20/03/2009 15:22 422992]
S3 adpahci;adpahci;c:\windows\System32\drivers\adpahci.sys [22/04/2009 02:07 297552]
S3 amdsata;amdsata;c:\windows\System32\drivers\amdsata.sys [20/03/2009 15:23 77904]
S3 amdsbs;amdsbs;c:\windows\System32\drivers\amdsbs.sys [28/03/2009 04:45 159312]
S3 AppID;AppID Driver;c:\windows\System32\drivers\appid.sys [22/04/2009 03:35 50176]
S3 AppIDSvc;Application Identity;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22/04/2009 03:16 20992]
S3 arcsas;arcsas;c:\windows\System32\drivers\arcsas.sys [22/04/2009 02:07 86608]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 16:06 183880]
S3 b06bdrv;Broadcom NetXtreme II VBD;c:\windows\System32\drivers\bxvbdx.sys [20/03/2009 15:22 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [22/04/2009 02:01 229888]
S3 BDESVC;BitLocker Drive Encryption Service;c:\windows\System32\svchost.exe -k netsvcs [22/04/2009 03:16 20992]
S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;c:\windows\System32\drivers\BrFiltLo.sys [22/04/2009 04:55 13568]
S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;c:\windows\System32\drivers\BrFiltUp.sys [22/04/2009 04:56 5248]
S3 Brserid;Brother MFC Serial Port Interface Driver (WDM);c:\windows\System32\drivers\BrSerId.sys [22/04/2009 04:53 272128]
S3 BrSerWdm;Brother WDM Serial driver;c:\windows\System32\drivers\BrSerWdm.sys [22/04/2009 04:55 62336]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\System32\drivers\BrUsbMdm.sys [22/04/2009 04:55 12160]
S3 circlass;Consumer IR Devices;c:\windows\System32\drivers\circlass.sys [22/04/2009 03:49 37888]
S3 defragsvc;Disk Defragmenter;c:\windows\system32\svchost.exe -k defragsvc [22/04/2009 03:16 20992]
S3 DXGKrnl;LDDM Graphics Subsystem;c:\windows\System32\drivers\dxgkrnl.sys [22/04/2009 03:23 720384]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD;c:\windows\System32\drivers\evbdx.sys [20/03/2009 15:22 3100160]
S3 elxstor;elxstor;c:\windows\System32\drivers\elxstor.sys [20/03/2009 15:23 453712]
S3 epmntdrv;epmntdrv;c:\windows\System32\epmntdrv.sys [28/01/2010 19:30 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\System32\EuGdiDrv.sys [28/01/2010 19:30 8456]
S3 Filetrace;Filetrace;c:\windows\System32\drivers\filetrace.sys [22/04/2009 03:12 28160]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22/04/2009 03:16 20992]
S3 FsDepends;File System Dependency Minifilter;c:\windows\System32\drivers\fsdepends.sys [22/04/2009 03:12 45648]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver;c:\windows\System32\drivers\hcw85cir.sys [22/04/2009 02:52 26624]
S3 HomeGroupListener;HomeGroup Listener;c:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted [22/04/2009 03:16 20992]
S3 HpSAMD;HpSAMD;c:\windows\System32\drivers\HpSAMD.sys [22/04/2009 02:07 67152]
S3 iaStorV;iaStorV;c:\windows\System32\drivers\iaStorV.sys [15/04/2009 02:30 332368]
S3 IKEEXT;IKE and AuthIP IPsec Keying Modules;c:\windows\system32\svchost.exe -k netsvcs [22/04/2009 03:16 20992]
S3 IPBusEnum;PnP-X IP Bus Enumerator;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [22/04/2009 03:16 20992]
S3 IPMIDRV;IPMIDRV;c:\windows\System32\drivers\IPMIDrv.sys [22/04/2009 03:28 65536]
S3 iScsiPrt;iScsiPort Driver;c:\windows\System32\drivers\msiscsi.sys [22/04/2009 03:44 186960]
S3 KtmRm;KtmRm for Distributed Transaction Coordinator;c:\windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation [22/04/2009 03:16 20992]
S3 LSI_FC;LSI_FC;c:\windows\System32\drivers\lsi_fc.sys [22/04/2009 02:07 95824]
S3 LSI_SAS;LSI_SAS;c:\windows\System32\drivers\lsi_sas.sys [22/04/2009 02:07 89168]
S3 LSI_SAS2;LSI_SAS2;c:\windows\System32\drivers\lsi_sas2.sys [22/04/2009 02:07 54864]
S3 LSI_SCSI;LSI_SCSI;c:\windows\System32\drivers\lsi_scsi.sys [22/04/2009 02:07 96848]
S3 megasas;megasas;c:\windows\System32\drivers\megasas.sys [20/03/2009 15:23 30800]
S3 mpio;mpio;c:\windows\System32\drivers\mpio.sys [22/04/2009 03:44 130640]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [18/06/2009 18:48 42480]
S3 msahci;msahci;c:\windows\System32\drivers\msahci.sys [22/04/2009 03:44 27728]
S3 msdsm;msdsm;c:\windows\System32\drivers\msdsm.sys [22/04/2009 03:44 115792]
S3 mshidkmdf;Pass-through HID to KMDF Filter Driver;c:\windows\System32\drivers\mshidkmdf.sys [22/04/2009 03:49 4096]
S3 MsRPC;MsRPC;c:\windows\System32\drivers\msrpc.sys [22/04/2009 03:09 162896]
S3 MTConfig;Microsoft Input Configuration Driver;c:\windows\System32\drivers\MTConfig.sys [22/04/2009 03:45 12288]
S3 NdisCap;NDIS Capture LightWeight Filter;c:\windows\System32\drivers\ndiscap.sys [22/04/2009 03:51 27136]
S3 nfrd960;nfrd960;c:\windows\System32\drivers\nfrd960.sys [22/04/2009 02:07 44624]
S3 nvstor;nvstor;c:\windows\System32\drivers\nvstor.sys [15/04/2009 02:30 142416]
S3 ql2300;ql2300;c:\windows\System32\drivers\ql2300.sys [20/03/2009 15:23 1383504]
S3 ql40xx;ql40xx;c:\windows\System32\drivers\ql40xx.sys [22/04/2009 02:07 105552]
S3 s3cap;s3cap;c:\windows\System32\drivers\vms3cap.sys [22/04/2009 10:23 5632]
S3 scfilter;Smart card PnP Class Filter Driver;c:\windows\System32\drivers\scfilter.sys [22/04/2009 03:32 26624]
S3 sffp_mmc;SFF Storage Protocol Driver for MMC;c:\windows\System32\drivers\sffp_mmc.sys [22/04/2009 03:44 12288]
S3 SiSRaid4;SiSRaid4;c:\windows\System32\drivers\sisraid4.sys [22/04/2009 02:07 77904]
S3 Smb;Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session);c:\windows\System32\drivers\smb.sys [22/04/2009 03:52 71168]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\System32\drivers\VSTAZL3.SYS [22/04/2009 02:11 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\System32\drivers\VSTDPV3.SYS [22/04/2009 02:11 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\System32\drivers\VSTCNXT3.SYS [22/04/2009 02:11 661504]
S3 stexstor;stexstor;c:\windows\System32\drivers\stexstor.sys [22/04/2009 02:07 21072]
S3 storvsc;storvsc;c:\windows\System32\drivers\storvsc.sys [22/04/2009 10:23 28240]
S3 uliagpkx;Uli AGP Bus Filter;c:\windows\System32\drivers\ULIAGPKX.SYS [22/04/2009 03:23 57424]
S3 usbcir;eHome Infrared Receiver (USBCIR);c:\windows\System32\drivers\usbcir.sys [22/04/2009 03:49 86016]
S3 vhdmp;vhdmp;c:\windows\System32\drivers\vhdmp.sys [22/04/2009 03:44 158288]
S3 ViaC7;VIA C7 Processor Driver;c:\windows\System32\drivers\viac7.sys [22/04/2009 03:08 52736]
S3 vmbus;vmbus;c:\windows\System32\drivers\vmbus.sys [22/04/2009 10:23 175824]
S3 VMBusHID;VMBusHID;c:\windows\System32\drivers\VMBusHID.sys [22/04/2009 10:23 17920]
S3 vsmraid;vsmraid;c:\windows\System32\drivers\vsmraid.sys [20/03/2009 15:23 141904]
S3 vwifibus;Virtual WiFi Bus Driver;c:\windows\System32\drivers\vwifibus.sys [22/04/2009 03:50 19968]
S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\System32\drivers\wacompen.sys [22/04/2009 03:45 21632]
S3 Wd;Wd;c:\windows\System32\drivers\wd.sys [22/04/2009 03:08 19024]
S3 WIMMount;WIMMount;c:\windows\System32\drivers\wimmount.sys [22/04/2009 03:15 19024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
RPCSSREG_MULTI_SZ RpcEptMapper RpcSs
defragsvcREG_MULTI_SZ defragsvc
WerSvcGroupREG_MULTI_SZ wersvc
LocalServiceNoNetworkREG_MULTI_SZ DPS PLA BFE mpssvc WwanSvc
swprvREG_MULTI_SZ swprv
LocalServicePeerNetREG_MULTI_SZ PNRPSvc p2pimsvc p2psvc PnrpAutoReg
NetworkServiceAndNoImpersonationREG_MULTI_SZ KtmRm
regsvcREG_MULTI_SZ RemoteRegistry
LocalServiceAndNoImpersonationREG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS AppIDSvc FontCache fdrespub QWAVE wcncsvc Mcx2Svc SensrSvc
DcomLaunchREG_MULTI_SZ Power PlugPlay DcomLaunch
NetworkServiceNetworkRestrictedREG_MULTI_SZ PolicyAgent
sdrsvcREG_MULTI_SZ sdrsvc
WbioSvcGroupREG_MULTI_SZ WbioSrvc
wcssvcREG_MULTI_SZ WcsPlugInService
secsvcsREG_MULTI_SZ WinDefend
AxInstSVGroupREG_MULTI_SZ AxInstSV
PeerDistREG_MULTI_SZ PeerDistSvc
HsfXAudioServiceREG_MULTI_SZ HsfXAudioService
bdxREG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
CertPropSvc
SCPolicySvc
lanmanserver
gpsvc
IKEEXT
AudioSrv
FastUserSwitchingCompatibility
Nla
NWCWorkstation
SRService
Wmi
WmdmPmSp
TermService
wuauserv
BITS
ShellHWDetection
LogonHours
PCAudit
helpsvc
uploadmgr
iphlpsvc
seclogon
AppInfo
msiscsi
MMCSS
EapHost
wercplsupport
ProfSvc
hkmsvc
winmgmt
SessionEnv
schedule
browser
BDESVC
Themes
AppMgmt

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalSystemNetworkRestricted
homegrouplistener


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
WdiServiceHost
sppuinotify

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetworkService
lanmanworkstation

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalServiceNetworkRestricted
BthHFSrv
homegroupprovider

.
Contents of the 'Scheduled Tasks' folder

2010-02-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-01-30 10:21]

2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-13 17:55]

2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-13 17:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://english.ircfast.com/en/index.php?rvs=hompag
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:54
Windows 6.1.7100 NTFS

detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:54
Windows 6.1.7100 NTFS

detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:54
Windows 6.1.7100 NTFS

detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:54
Windows 6.1.7100 NTFS

detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 13:54
Windows 6.1.7100 NTFS

detected NTDLL code modification:
ZwEnumerateKey 0 != 116, ZwQueryKey 0 != 244, ZwOpenKey 0 != 182, ZwClose 0 != 50, ZwEnumerateValueKey 0 != 119, ZwQueryValueKey 0 != 266, ZwOpenFile 0 != 179, ZwQueryDirectoryFile 0 != 223, ZwQuerySystemInformation 0 != 261Initialization error
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-266026509-2478018468-2126545625-1002_Classes\VirtualStore\MACHINE\SOFTWARE\ComputerAssociates\eTrustAntivirus]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-02-02 14:00:20
ComboFix-quarantined-files.txt 2010-02-02 14:00
ComboFix2.txt 2010-02-02 13:25

Pre-Run: 18,908,688,384 bytes free
Post-Run: 18,856,767,488 bytes free

- - End Of File - - 53A5536002CC625F7933C316215932E0
Hi again. Please do these steps in order.

1. Please download TFC by OldTimer to your desktop

  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
2. Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is FOUND, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer:

http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Post the log from SUPERAntiSpyware when you've accomplished that.

4. Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

5. Post the following in your next reply:
  • MBAM log
  • SAS log
  • ESET log
And, please tell me how your computer is doing.Hi.

All scans run successfully. Last one found nothing which I presume is good.

Computer seems fine now, thanks for your help. Is there any specific scanner I ought to be using to help prevent future problems. I installed Bitdefender as it seemed to have good writeup.

Log of scans in next post

Cheers JohnMalwarebytes' Anti-Malware 1.44
Database version: 3679
Windows 6.1.7100
Internet Explorer 8.0.7100.0

02/02/2010 20:02:47
mbam-log-2010-02-02 (20-02-47).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 351046
Time elapsed: 1 hour(s), 39 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\DOWNLOADS\ke find kf151\keyfinder.exe (Application.FindKey) -> Quarantined and deleted successfully.
D:\TEMP\SecBku\20080916192916359.tmp (Application.FindKey) -> Quarantined and deleted successfully.
C:\Users\John 1\Favorites\Cheap Software from CDRBSoftware.url (Rogue.Link) -> Quarantined and deleted successfully.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/02/2010 at 09:40 PM

Application Version : 4.33.1000

Core Rules Database Version : 4548
Trace Rules Database Version: 2360

Scan type : Quick Scan
Total Scan Time : 01:00:07

Memory items scanned : 805
Memory threats detected : 0
Registry items scanned : 534
Registry threats detected : 0
File items scanned : 46002
File threats detected : 532

Adware.Tracking Cookie
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][6].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][9].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][7].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]somniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][8].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][5].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][9].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][10].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]gg.adbureau[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]yoodjklo.stats.esomniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]ts.esomniture[1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]2dj6wfmiugczglq.stats.esomniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]dj6wcmiundjwdp.stats.esomniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]pdpsfp.stats.esomniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]cl4kmd5gkp.stats.esomniture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][10].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][11].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected]iture[2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\john1[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][7].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][6].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][5].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][8].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt
D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt

Trojan.Agent/Gen-AppX
E:\NEW VOLUME\ALLDATA\ALLDATA AUTO DIAGNOSTIC 3.4\ADUTIL\HINSTALL\303\HINSTALL.1.1.1.1.EXE




[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK


Note.. Nothing Found by ESETPlease re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Run again. All Clean !!

Malwarebytes' Anti-Malware 1.44
Database version: 3690
Windows 6.1.7100
Internet Explorer 8.0.7100.0

04/02/2010 21:06:32
mbam-log-2010-02-04 (21-06-32).txt

Scan type: Quick Scan
Objects scanned: 107680
Time elapsed: 7 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
To manually create a new Restore Point
  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive i.e. C
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
OK All done

Results of screen317's Security Check version 0.99.1
Windows 7 (UAC is enabled)
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
ESET Online Scanner v3
BitDefender Antivirus 2010
WMIC entry does not exist for antivirus; attempting automatic update.
``````````````````````````````
Anti-malware/Other Utilities Check:

SUPERAntiSpyware Free Edition
HijackThis 2.0.2
Java(TM) 6 Update 17
Adobe Flash Player 10
Adobe Reader 9.2
``````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
``````````````````````````````
DNS Vulnerability Check:

Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)

`````````End of Log```````````
Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still LEAVE you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to STAY safe while browsing, to prevent re-infection.

Software recommendations

AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
Thank you for your time and help

Best wishes
JohnYou're welcome.
1687.

Solve : Someone please help.. :-(?

Answer»

I have recently acquired a virus and need some help! Ugh.. the error reading is "Application cannot be executed. The file XXXXX is infected. Do you want to activate your antivirus software now?" then a fake antivirus software alert comes up... I had this same issue a few weeks ago and thought it was gone but it's back again grr!! Any help would be AWESOME! Please download Cheetah-Anti-Rogue, and save to your Desktop.

  • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.cmd to start.
  • It will finish quickly and launch a log.
  • Post the contents of it in your next reply.
I am unable to copy the text into a window because each time i open the file it immediately closes any window I open..I was able to log off and back on and copy this:

Cheetah-Anti-Rogue v1.2.17
by DragonMaster Jay

Microsoft Windows [Version 6.0.6002]
Date: 02/08/2010 - Time: 21:24:00 - Arch.: x86


-- Malware tools check --
Trend Micro HijackThis 2.0.2
Malwarebytes' Anti-Malware
SUPERAntiSpyware
Please open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Full Scan, and press Scan. Remove selected, and post the log in your next reply.The log from malwarebytes:
Malwarebytes' Anti-Malware 1.44
Database version: 3713
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/9/2010 3:48:03 PM
mbam-log-2010-02-09 (15-48-03).txt

Scan type: Full Scan (C:\|)
Objects scanned: 270324
Time elapsed: 1 hour(s), 57 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
FILES Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



I did this scan on the 8th which detected one infected file I thought I should attach it as well:


Malwarebytes' Anti-Malware 1.44
Database version: 3640
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/8/2010 3:41:03 AM
mbam-log-2010-02-08 (03-41-03).txt

Scan type: Full Scan (C:\|)
Objects scanned: 267771
Time elapsed: 3 hour(s), 25 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Zachary\AppData\Local\Temp\e.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
To manually create a new Restore Point
  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive i.e. C
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad DOCUMENT should open automatically called checkup.txt; please post the contents of that document.
Results of screen317's Security Check version 0.99.1
Windows Vista Service Pack 2 (UAC is enabled)
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
SonicStage Mastering Studio Audio Filter Custom Preset
Trend Micro AntiVirus
Trend Micro AntiVirus
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

Spyware Doctor 7.0
SUPERAntiSpyware Free Edition
HijackThis 2.0.2
Java(TM) 6 Update 17
Java(TM) SE Runtime Environment 6
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 8.1.0
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSASCui.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````END of Log```````````
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is IMPORTANT to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==

Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Firewall
  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.
AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
See this page for more info about malware and prevention.
1688.

Solve : UACd.sys Trojan?

Answer»

Please open Malwarebytes, click the Scanner TAB, select Perform Quick Scan, and press Scan. Remove selected, and POST the log in your next reply.Hi,

it found nothing....

Malwarebytes' Anti-Malware 1.44
Database version: 3673
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

5-2-2010 19:49:24
mbam-log-2010-02-05 (19-49-24).txt

Scan type: Quick Scan
Objects scanned: 151494
Time elapsed: 5 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
To manually create a new RESTORE Point

  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive i.e. C
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Hi DM Jay,

I executed according to you instructions. The log is attached.

Thanks!

[Saving space, attachment deleted by admin]Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
SEARCH in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Firewall
  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.
AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware ACTUALLY claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
See this page for more info about malware and prevention.Hi,

Thanks for all the advice. I will enhance my PC's protection with the tools you're suggesting.

However, I am still stuck with my explorer.exe issue. As I already mentioned, if I log in to my main user account, explorer will die and restart and die and restart and so on. This makes that I can not use this user account.

You mentioned earlier that it was no biggie to get rid of that.
You did some suggestions which I carried out, in another user account however, since the infected one is rendered useless.

Please advice. Thanks!Restore Permissions for explorer.exe

Please download Inherit by sUBs
  • Drag and drop explorer.exe onto Inherit
  • This shall restore permissions to the application
  • The application should now run normally
Please indicate in your next post if this was successful.

Note: explorer.exe is located in the folder C:\windowsTried to download inherit, but got hit with the following:

C:\Users\xbox\AppData\Local\Temp\fgW_siwp.exe.part could not be saved, because the source file could not be read.

Try again later, or contact the server administrator.


Furthermore AVAST acted up. The WebShield blocked the following threat:

Object: ..../://download.bleepingcomputer.com/sUBs/MiniFixes/Inherit.exe|
Infection: Win32:Trojan-gen
Action: Connection aborted
Proces: firefox.exe


How to proceed?Disable the antivirus and try again please.

That happens all the time, but the actual tool is safe.Hi,

Did what you asked, no positive result.

Now, thinking about this, I wouldn't expect that something is wrong with explorer.exe anyway.
I have 5 user accounts on my computer and on 4 out of them it works as it should.
Only one account has this problem. Can it be that there is something wrong in the start-up procedure for this account? Again, I can not do any experiments on this user account, which might make it harder to analyze.

Any more ideas would be very much appreciated! Thanks again.

Possibly.

Log in to another user account to do this method.

Save the account files for the account that is giving the problem.

Just copy the following folder and save it to a disc, flash drive or somewhere in another username's My Documents folder.

C:\Users\{USERNAME}


{USERNAME} is the name of the problem account. Copy that folder and save it somewhere.

Then go to Control Panel > User Accounts (add or remove user accounts)

Delete the problem user account by removing it and all of its files. (Remember that you made a backup of those files)


=====

Then, create a new account with the same username, and do the same process in reverse, by going to C:\Users and pasting the backup folder in the folder (Users).

Then, restart the computer and let me know if this issue still occurs.


==

If you get Access Denied messages, let me know and we can Take Ownership of that folder.Hi,

sorry for the late reply, work kept me busy (it happens )

Followed your instructions and everything seems to be working ok again.

Let me know what I still need to do to declare my PC cured!

What ever's next, thanks a lot for all your help. I enjoyed working with you. Couldn't have done it without you!

Cheers PeterSeems clean to me.
1689.

Solve : Regarding "Read this before requesting malware removal help"?

Answer»

Hi, I have followed everything that you have said to do and can now upload the logs. I can't think of anything that brought the virus on so don't have any additional details for you. When performing the SuperAntiSpyware search, I had to cancel the first search so now have two logs. I have uploaded both of them and the log from the most recent search has been uploaded second. Also, I cannot do a system restore and it asks me to contact the domain administrator. Is there any way of being able to perform a system restore again?
Thanks very much.

[Saving space, attachment deleted by admin]Welcome to CH.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • O15 - Trusted Zone: http://*.buy-internet-security10.com
  • O15 - Trusted Zone: http://*.buy-internetsecurity10.com
  • O15 - Trusted Zone: http://*.is-soft-download.com
  • O15 - Trusted Zone: http://*.is-software-download.com
  • O15 - Trusted Zone: http://*.is-software-download25.com
  • O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
  • O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
.
Important: Close all open windows except for HijackThis and then CLICK FIX checked.

Once completed, exit HijackThis.

----------

Download Lop S&D by Eric_71 and save it to your desktop. Lop S&D will only run on Windows XP and Windows Vista

Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D.

Double click LopSD.exe - If you are using Windows Vista or Windows 7, right-click on the LopSD icon and select Run as administrator to perform this scan.

* Choose the language by typing of the corresponding letter and press Enter
* Click OK at the informative window.
* Type 2 to choose Option 2 (Delete with Hosts File Restore), then press Enter
* Wait until the end of the scan.
* A report will be generated, post the contents of it in your next reply, along with a HijackThis log.
Hey, here is a copy of he lopR log. Since I only did a system scan with HijackThis, I didn't get another log.

Thanks

[Saving space, attachment deleted by admin]Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.Hi, here are the next two posts. Thanks

[Saving space, attachment deleted by admin]Note: You got this infection from installing the sponsored software with Messenger Plus! Live.

Quote
C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27\How to use keygen.txt
C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27\Keygen.exe

Please remove Driver magician V 3.27 and any other cracked software. I can't continue helping if it is not removed.

----------

Go to Add or Remove Programs and uninstall:

  • J2SE Runtime Environment 5.0 Update 6
  • Messenger Plus! Live & Sponsor (CiD)
.
Note: You can reinstall Messenger Plus but DO NOT choose to install the sponsored software!

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
uRun: [sefjhf98jfoidsfoishgoiusgdgfgd] c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe
uRun: [smss32.exe] c:\windows\system32\smss32.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

File::
C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe
c:\windows\system32\smss32.exe
c:\windows\system32\IS15.exe
c:\windows\system32\helper32.dll
c:\windows\system32\winlogon32.exe
C:\horj.exe
C:\kkalf.exe

Folder::
c:\docume~1\fraser_2\applic~1\SystemProc
C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27
c:\program files\messenger
C:\s


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
Hi there, here is the combofix log.
Thanks

[Saving space, attachment deleted by admin]Download the below attached CFScript.txt and save it to your desktop (click on the Attached File underneath this post)

* If you are using Internet Explorer when the "File download" pop up comes click Save and choose desktop in the list of selections in that window and then click Save.
* If you are using Firefox choose Save to disk then click OK and choose desktop in the list of selections in that window and then click Save.

Close all open Web Browsers!

Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below.



This will start ComboFix. ComboFix may ASK to reboot the computer when it is finished, please allow it to do so.

A new log will be created, post the contents of Combofix.txt in your next reply.

Note: these instructions and script were created specifically for this user. If you are not this user do NOT follow these instructions or use this script as it could damage the workings of your system.

[Saving space, attachment deleted by admin]Here is the latest log. Thanks. I need to go now so I shall continue tomorrow. Thanks for all your help so far.

[Saving space, attachment deleted by admin]Quote from: fkmckenzie on February 05, 2010, 05:21:36 PM
I need to go now so I shall continue tomorrow. Thanks for all your help so far.

No problem. I'll be around.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Log
Hi, here is the ESETScan log for you.

[Saving space, attachment deleted by admin]If there are no other malware issues we can finish up now.

Use the Secunia Software Inspector to check for out of date software.

* Click Start Now
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks a lot. You have been a great help to meYour welcome.
1690.

Solve : PC Infected with 'popup' virus?

Answer» AVG will work fine with those. EVERYTHING I suggested in that last post is "PASSIVE protection" and won't interfere with AVG or the performance of your computer.
1691.

Solve : need help removing virus?

Answer»

Hello, I've recently contracted a virus of some sort that causes the following to happen:

Repetitive comments such as: Application cannot be executd. The file ** is infected.


I've followed your instructions up to this point and am now beginning this thread. Also to note is that I've done some of the stuff found in other posts yesterday prior to beginning the correct process. Therefore a bunch of stuff has been removed. Regardless, the virus still exists. So per instructions found on your website I am to the point in "Read this before requesting malware removal help" where I am to post my SUPERantispyware results log... and here it is:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/06/2010 at 11:34 AM

Application Version : 4.33.1000

Core Rules Database Version : 4561
Trace Rules Database Version: 2373

Scan type : Complete Scan
Total Scan Time : 01:30:15

Memory items scanned : 569
Memory threats detected : 0
Registry items scanned : 6531
Registry threats detected : 0
File items scanned : 85115
File threats detected : 0

Thanks for your help,
Michael
I apologize. I got a little ahead of myself and thought I was to run one program at a time... so to continue my original post, here are the requested logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/06/2010 at 11:34 AM

Application Version : 4.33.1000

Core Rules Database Version : 4561
Trace Rules Database Version: 2373

Scan type : Complete Scan
Total Scan Time : 01:30:15

Memory items scanned : 569
Memory threats detected : 0
Registry items scanned : 6531
Registry threats detected : 0
File items scanned : 85115
File threats detected : 0





-------------------------------------------------------------------------------------





Malwarebytes' Anti-Malware 1.44
Database version: 3697
Windows 5.1.2600 Service PACK 3
Internet Explorer 6.0.2900.5512

2/6/2010 2:37:35 PM
mbam-log-2010-02-06 (14-37-35).txt





-------------------------------------------------------------------------------------




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:28:47 PM, on 2/6/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Garmin\ANT Agent\ANT Agent.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\control.exe
C:\WINDOWS\system32\control.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070412
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070412
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SonicWALLNetExtender] C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe -hideGUI -clearReboot
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ANT Agent] C:\Garmin\ANT Agent\ANT Agent.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_18.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_18.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} (NELaunchCtrl Class) - https://vpn.hargrove-associates.com/NELX.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c9cd0e429dfd3a) (gupdate1c9cd0e429dfd3a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicWALL NetExtender Service (SONICWALL_NetExtender) - SonicWALL Inc. - C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 11658 bytes

Scan type: Quick Scan
Objects scanned: 136894
Time elapsed: 5 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsoft (Trojan.FakeAV) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ohewnkfw (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ohewnkfw (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)





-------------------------------------------------------------------------------------

Thank you very much in advance,
MichaelWelcome to CH.

Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and logs posted for each one)

* Copy the file path in the below Code box:
Code: [Select]C:\WINDOWS\system32\control.exe * At the upload SITE, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will POSSIBLY be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

----------

Create An Uninstall List

* Start HijackThis
* Click on the Open the Misc Tools section
* Click on the Open Uninstall Manager button.
* Click on the Save list button and specify where you would like to save this file and click Save.
* When you press Save button a notepad will open with the contents of that file.
* Copy and paste that list in your reply.please find below, Jotti link and Hijackthis uninstall list as per your request... and again, thank you very much.



http://virusscan.jotti.org/en/scanresult/7ce180637af5ad73b922082feff3d8
dc20542628/328e27ad005e7f7d31fd6161432e018cd2a89627





-------------------------------------------------------------------------------------





32 Bit HP CIO Components Installer
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 9.2
Adobe Stock Photos 1.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
BeatScanner 1.41
Bonjour
Broadcom 440x 10/100 Integrated Controller
Broadcom Management Programs
CCleaner
Conexant HDA D110 MDC V.92 Modem
Critical Update for Windows Media Player 11 (KB959772)
FlashPlayer Plus 2.6(Trial version)
FUJIFILM USB Driver
Garmin Communicator Plugin
Garmin Training Center 3.4.3.0
Garmin USB Drivers
Garmin USB Drivers
Garmin WebUpdater
Garmin WebUpdater
Google Earth
Google Update Helper
Google Updater
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HOTFIX for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Deskjet All-In-One Software 9.0
HP Imaging Device Functions 9.0
HP Photosmart Essential 2.01
HP Smart Web Printing
HP Solution Center 9.0
Intel(R) Graphics Media Accelerator Driver
Intel(R) PROSet/Wireless Software
iTunes
Java(TM) 6 Update 18
LimeWire 5.3.6
LineupDominator Version 5.0b Full
LiveUpdate 3.1 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
mCore
MCU
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PROOF (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
mIWA
mLogView
mMHouse
Modem Helper
Mozilla Firefox (3.5.7)
mPfMgr
mPfWiz
mProSafe
mSCfg
MSN
mSSO
MSXML 6 Service Pack 2 (KB954459)
mWlsSafe
mWMI
mZConfig
Netflix Movie Viewer
NetWaiting
Picasa 3
QuickTime
RealPlayer
Safari
SBEDS v4
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
SlingPlayer
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SonicWALL SSL-VPN NetExtender
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
Synergy
Uninstall 1.0.0.0
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb977839)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
URL Assistant
USB Driver Vers. 3.2
Webshots Desktop
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3

Go to Add or Remove Programs and uninstall:

  • LiveUpdate 3.1 (Symantec Corporation)
  • LiveUpdate Notice (Symantec Corporation)
  • URL Assistant
.
----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixHow do I disable AVG 9.0?See here. http://free.avg.com/ww-en/kb.num-2429ComboFix 10-02-07.08 - Michael Perniciaro 02/08/2010 10:30:22.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1402 [GMT -6:00]
Running from: c:\documents and settings\Michael Perniciaro\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Michael Perniciaro\Local Settings\Application Data\xhnsay
c:\documents and settings\Michael Perniciaro\Local Settings\Application Data\xhnsay\kfehsftav.exe
c:\windows\AegisP.inf
c:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.

2010-02-07 09:05 . 2010-02-07 09:05--------d-----w-C:\d29983a7598216d258f242
2010-02-06 21:08 . 2010-02-06 21:23--------d-----w-c:\documents and settings\Michael Perniciaro\.SunDownloadManager
2010-02-06 20:44 . 2010-02-06 20:44503808----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\msvcp71.dll
2010-02-06 20:44 . 2010-02-06 20:44499712----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\jmc.dll
2010-02-06 20:44 . 2010-02-06 20:44348160----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\msvcr71.dll
2010-02-06 20:44 . 2010-02-06 20:4461440----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ffedcc-n\decora-sse.dll
2010-02-06 20:44 . 2010-02-06 20:4412800----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ffedcc-n\decora-d3d.dll
2010-02-06 15:53 . 2010-02-06 15:53--------d-----w-c:\program files\CCleaner
2010-02-06 05:44 . 2010-02-06 05:44--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\Malwarebytes
2010-02-06 05:43 . 2010-01-07 22:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-06 05:43 . 2010-02-06 05:43--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-06 05:43 . 2010-02-06 05:46--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-02-06 05:43 . 2010-01-07 22:0719160----a-w-c:\windows\system32\drivers\mbam.sys
2010-02-06 02:41 . 2010-02-06 02:4152224----a-w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-06 02:41 . 2010-02-06 02:41117760----a-w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\program files\SUPERAntiSpyware
2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com
2010-02-06 02:32 . 2010-02-06 02:32--------d-----w-c:\program files\Trend Micro
2010-02-06 02:09 . 2010-02-06 02:11--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\QuickScan
2010-02-06 02:09 . 2010-01-11 23:33789320----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-02-06 02:09 . 2010-01-11 23:32698184----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2010-02-05 16:08 . 2010-02-07 09:06--------d-----w-c:\windows\system32\XPSViewer
2010-02-05 16:07 . 2010-02-05 16:07--------d-----w-c:\program files\Reference Assemblies
2010-02-05 16:07 . 2008-07-06 12:0689088----a-w-c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-05 16:07 . 2006-06-29 19:0714048------w-c:\windows\system32\spmsg2.dll
2010-02-05 16:02 . 2010-02-05 16:02--------d-----w-C:\3b84628148cac7604d4a2edb
2010-02-05 16:02 . 2010-02-05 18:27--------d-----w-C:\5838f9b2fb6304ca6b
2010-02-04 15:50 . 2010-02-04 15:50--------d-----w-c:\program files\iPod
2010-02-04 15:50 . 2010-02-04 15:51--------d-----w-c:\program files\iTunes
2010-02-04 15:46 . 2010-02-04 15:47--------d-----w-c:\program files\QuickTime
2010-02-04 15:41 . 2010-02-04 15:4172488----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-31 18:30 . 2010-01-31 20:23--------d-----w-c:\program files\Jumi
2010-01-19 22:03 . 2010-01-19 22:03--------d-----w-c:\program files\Garmin GPS Plugin
2010-01-13 19:24 . 2009-11-21 15:51471552------w-c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 16:32 . 2008-10-25 15:17--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\DNA
2010-02-08 16:12 . 2007-04-12 05:04--------d-----w-c:\program files\Google
2010-02-08 15:52 . 2008-10-25 15:17--------d-----w-c:\program files\DNA
2010-02-08 06:11 . 2009-05-04 23:14--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
2010-02-08 04:33 . 2007-05-01 01:50--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
2010-02-08 04:33 . 2007-05-01 01:48--------d-----w-c:\program files\Common Files\Symantec Shared
2010-02-06 21:23 . 2007-04-12 04:51--------d-----w-c:\program files\Java
2010-02-06 20:53 . 2007-04-12 04:51--------d-----w-c:\program files\Common Files\Java
2010-02-06 14:46 . 2007-05-29 21:10--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2010-02-05 20:43 . 2007-04-12 05:0971616----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 16:08 . 2007-07-11 14:13--------d-----w-c:\program files\MSBuild
2010-02-04 15:50 . 2007-11-22 19:14--------d-----w-c:\program files\Common Files\Apple
2010-01-21 14:25 . 2008-12-23 03:35--------d-----w-c:\program files\Microsoft Silverlight
2010-01-19 16:46 . 2007-04-25 13:49--------d-----w-c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-15 18:23 . 2007-04-25 00:05--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\BitTorrent
2010-01-12 13:43 . 2009-04-18 14:43141136----a-w-c:\windows\hpoins14.dat
2009-12-22 05:21 . 2004-08-11 22:00667136----a-w-c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2004-08-11 22:0081920----a-w-c:\windows\system32\ieencode.dll
2009-12-17 23:14 . 2009-12-12 23:15411368----a-w-c:\windows\system32\deploytk.dll
2009-12-12 23:16 . 2009-12-12 23:13--------d-----w-c:\program files\LimeWire
2009-11-21 15:51 . 2004-08-11 22:00471552----a-w-c:\windows\AppPatch\aclayers.dll
2009-11-15 23:37 . 2009-04-21 16:13360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-11-15 23:37 . 2009-04-21 16:13333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-11-15 23:37 . 2009-04-21 16:1328424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-11-15 23:37 . 2009-04-21 16:1312464----a-w-c:\windows\system32\avgrsstx.dll
2008-07-29 13:58 . 2007-05-28 22:08168--sh--r-c:\windows\system32\00D13C0E55.sys
2008-07-29 13:58 . 2007-05-28 22:085642--sha-w-c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"ANT Agent"="c:\garmin\ANT Agent\ANT Agent.exe" [2008-09-02 8203352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-04 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-30 185896]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"SonicWALLNetExtender"="c:\program files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe" [2009-03-02 710480]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\Michael Perniciaro\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
OneNote Table Of Contents.onetoc2 [2008-5-18 3656]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-15 23:3712464----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/21/2009 10:13 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/21/2009 10:13 AM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/15/2009 5:37 PM 285392]
R3 SSLDrv;SSL-VPN NetExtender Adapter;c:\windows\system32\drivers\SSLDrv.sys [10/23/2007 6:09 PM 20504]
S2 gupdate1c9cd0e429dfd3a;Google Update Service (gupdate1c9cd0e429dfd3a);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2009 5:15 PM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-02-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-22 23:14]

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 23:15]

2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 23:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070412
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} - hxxps://vpn.hargrove-associates.com/NELX.cab
FF - ProfilePath - c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Michael Perniciaro\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe



**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(916)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\netprovcredman.dll
.
Completion time: 2010-02-08 10:34:53
ComboFix-quarantined-files.txt 2010-02-08 16:34

Pre-Run: 11,957,153,792 bytes free
Post-Run: 11,994,955,776 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - E62948865219CF0183A967E1B913F679
Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

Delete the fixme.reg from the Desktop.

----------

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan Log
Did get a success message for the fixme.reg.



ESET found no threats and went straight to a screen with only a "Finish" button and the option to uninstall upon closing. I will continue to keep this box open until I hear from you.


Sounds good.

If there are no more malware issues we can finish up now.

Use the Secunia Software Inspector to check for out of date software.

* Click Start Now
* Check the box next to Enable thorough system inspection.
* Click Start
* Allow the scan to finish and scroll down to see if any updates are needed.
* Update anything listed.

----------

Go to Microsoft Windows Update and get all critical updates.

----------

If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Everything seems to be working fine. Thank you very much. No, really, THANK YOU!Your welcome.

Safe surfing...








1692.

Solve : Need Help Removing Malware?

Answer»

Wife said the computer locked up and when she restarted it we are getting numerous alert windows that we are being attacked and do we want to block the attack. One window says "Application cannot be executed. The file avgui.exe is infected. Do you want to activate your antivirus software now?". Previously this window indicated CSC.exe was infected. Different message at each attempt to launch a program.

Any help is much appreciated as I don't know how to proceed.Hello, cruisin702...your comment has been removed. Please do not post advice to members. ~ DragonMaster JayHello, Jdog66.

Please visit this WEBPAGE for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix when you've accomplished that.Installed and ran Combofix. When it finished computer restarted but the screen is now blank.
Afraid to proceed without advice. Please save the following instructions into Notepad and print it out as this webpage would not be available when you're carrying out the process.

1.Please reboot into Recovery Console.

2.You must enter which Windows installation to log onto. Type 1 and press Enter.

3.At the C:\Windows prompt, type the following bolded command, and press Enter:

set allowallpaths = true

4.At the next prompt type without the quotes "cd erdnt\subs" and hit Enter.

5.At the next prompt, please type in the following without the quotes: "batch erdnt.con" and hit Enter.

The erunt backups should begin copying backup files. At the next prompt after it is complete, Type exit.

kindly reboot your pc and tell me if Windows is loading nowI returned from work to find that it had completed and the log was displayed. I guess I wasn't expecting it to take that long. Here is the Combofix log...


ComboFix 10-02-01.02 - Jen 02/01/2010 22:49:38.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.200 [GMT -6:00]
Running from: c:\documents and settings\Jen\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jen\Application Data\SearchToolbarCorp
c:\documents and settings\Jen\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
c:\documents and settings\Jen\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
c:\documents and settings\Jen\My Documents\My Documents.url
c:\documents and settings\Jen\My Documents\My Music\My Music.url
c:\documents and settings\Jen\My Documents\My Pictures\My Pictures.url
c:\documents and settings\Jen\My Documents\My Videos\My Video.url
c:\documents and settings\Jen\Start Menu\Programs\VirusTrigger 2.1
c:\documents and settings\Jen\Start Menu\Programs\VirusTrigger 2.1\VirusTrigger 2.1.lnk
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\content\options.js
c:\program files\SelectRebates\FFToolbar\chrome\content\options.xul
c:\program files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.xul
c:\program files\SelectRebates\FFToolbar\chrome\locale\en-US\contents.rdf
c:\program files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.dtd
c:\program files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.dtd.skin
c:\program files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.properties
c:\program files\SelectRebates\FFToolbar\chrome\skin\3rdParty.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\add-folderplus.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\add-plussign.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\alert-blue.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\alert-red.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\bluebar.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\dollarsign.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\FindWords.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\gripper.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\icon-magnifying.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\invite.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\invite2.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\my-blue.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\my-gray.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\my-green.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\my-red.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\Options.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\S.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\SAH-LogoHotSpots.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\SAH-logotext.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v1.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v2.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\sahtoolbar.css
c:\program files\SelectRebates\FFToolbar\chrome\skin\Scissors.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\Search.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\shoppingcart.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\singleperson.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\star.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\thumb2.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\Thumbs.db
c:\program files\SelectRebates\FFToolbar\chrome\skin\toolbar-images-ALL.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\Toolbar_HelpAndFeedback.png
c:\program files\SelectRebates\FFToolbar\chrome\skin\Wrench.png
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SahImages\bg-gradient.gif
c:\program files\SelectRebates\SahImages\button-close.gif
c:\program files\SelectRebates\SahImages\sah-logopop.gif
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates.exe
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesApi.exe
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesUninstall.exe
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\Add.bmp
c:\program files\SelectRebates\Toolbar\AdvancedOptions.html
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\basis.xml.temp
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\button-CloseWindow.gif
c:\program files\SelectRebates\Toolbar\i_clipboard.bmp
c:\program files\SelectRebates\Toolbar\i_help.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
c:\program files\SelectRebates\Toolbar\Invite.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\MyNew.bmp
c:\program files\SelectRebates\Toolbar\MyNone.bmp
c:\program files\SelectRebates\Toolbar\MyPage.bmp
c:\program files\SelectRebates\Toolbar\Rate.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\sah_logo_bars.gif
c:\program files\SelectRebates\Toolbar\Scissors.bmp
c:\program files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
c:\program files\SelectRebates\Toolbar\Tools.bmp
c:\program files\SelectRebates\Toolbar\Tools2.bmp
c:\program files\webmediaviewer
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\kb913800.exe
c:\windows\system32\512686
c:\windows\system32\bszip.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\rtutv.bak1
c:\windows\system32\rtutv.bak2
c:\windows\system32\rtutv.ini2
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.

2010-01-28 00:17 . 2010-01-28 00:17--------d--h--w-c:\windows\PIF
2010-01-27 19:16 . 2010-01-27 19:1623----a-w-c:\documents and settings\Jen\Local Settings\Application Data\syssvc.exe
2010-01-27 19:08 . 2010-02-02 04:27--------d-----w-c:\documents and settings\Jen\Local Settings\Application Data\dunrth
2010-01-13 00:59 . 2009-11-21 15:51471552------w-c:\windows\system32\dllcache\aclayers.dll
2010-01-08 15:40 . 2010-01-08 15:44--------d-----w-c:\program files\iTunes
2010-01-08 15:40 . 2010-01-08 15:44--------d-----w-c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-08 15:29 . 2010-01-08 15:31--------d-----w-c:\program files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 18:16 . 2006-02-20 03:38--------d-----w-c:\documents and settings\Jen\Application Data\Apple Computer
2010-01-08 15:41 . 2006-02-20 03:36--------d-----w-c:\program files\iPod
2010-01-08 15:41 . 2009-07-27 00:08--------d-----w-c:\program files\Common Files\Apple
2010-01-05 10:00 . 2005-08-16 10:18832512----a-w-c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 10:1878336----a-w-c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 10:1817408----a-w-c:\windows\system32\corpol.dll
2009-12-19 16:43 . 2008-06-01 21:30--------d-----w-c:\documents and settings\Phil\Application Data\ComcastToolbar
2009-11-25 14:40 . 2007-02-07 21:4869168----a-w-c:\documents and settings\Erika\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:51 . 2005-08-16 10:18471552----a-w-c:\windows\AppPatch\aclayers.dll
2006-01-31 03:47 . 2006-01-31 03:47774144----a-w-c:\program files\RngInterstitial.dll
2006-02-01 05:04 . 2006-01-29 06:4956--sh--r-c:\windows\system32\16C82B422B.sys
2008-11-10 17:30 . 2008-11-05 02:14608--sha-w-c:\windows\system32\winzvprt5.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-01-23 26112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-18 8192]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-18 110592]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-01-23 168448]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"LXSUPMON"="c:\windows\system32\LXSUPMON.EXE" [2002-03-08 900096]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 198184]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2007-10-03 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-11 406016]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2006-1-31 36864]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-3-22 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2006-1-31 36864]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-31 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 14:4611952----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\hp laserjet m1522\\Fax Config utility1.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\HP\\hp laserjet m1522\\hppfaxnc1.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hppscan6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/21/2008 8:53 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/21/2008 8:54 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/6/2009 7:33 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/21/2008 8:53 AM 297752]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-02-02 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]

2010-01-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
.
------- Supplementary Scan -------
.
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
LSP: c:\windows\system32\mclsp.dll
Trusted Zone: myretirementplan.com\www
Trusted Zone: musicmatch.com\online
DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} - hxxp://abtapn480.abbott.com/sametime/stmeetingroomclient/STJNILoader.cab
FF - ProfilePath - c:\documents and settings\Jen\Application Data\Mozilla\Firefox\Profiles\o2kal4qc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Jen\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Jen\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\Jen\Application Data\Mozilla\Firefox\Profiles\o2kal4qc.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}\plugins\NPCpnMgr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\V3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - c:\program files\WebMediaViewer\hpmun.dll
Toolbar-{98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - c:\program files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-jceiduqj - c:\documents and settings\Jen\Local Settings\Application Data\dunrth\vsoesysguard.exe
HKLM-Run-PCLEUSBTip - c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
HKLM-Run-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
HKLM-Run-jceiduqj - c:\documents and settings\Jen\Local Settings\Application Data\dunrth\vsoesysguard.exe
AddRemove-Browser Toolbar - c:\program files\WebMediaViewer\browseu.exe
AddRemove-ComcastHSI - c:\program files\support.com\uninstall\chsi_uninstaller.exe
AddRemove-IExplorer add-on - c:\program files\WebMediaViewer\hpmun.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-02 06:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(768)
c:\windows\system32\mclsp.dll
c:\windows\system32\SPORDER.dll

- - - - - - - > 'explorer.exe'(3432)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\ehome\mcrdsvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-02-02 07:01:55 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-02 13:01

Pre-Run: 90,528,731,136 bytes free
Post-Run: 100,027,961,344 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 6656277F665738B3211F607743238CFA
Hi again. Please do these steps in order.

1. Please download TFC by OldTimer to your desktop

  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
2. Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to EITHER and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer:

http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Post the log from SUPERAntiSpyware when you've accomplished that.

4. Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

5. Post the following in your next reply:
  • MBAM log
  • SAS log
  • ESET log
And, please tell me how your computer is doing.Haven't had any pop-ups since running the Combofix but performance has been sluggish. Here are the logs and THANK YOU FOR ALL YOU HELP!

MBAM Log:

Malwarebytes' Anti-Malware 1.44
Database version: 3691
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

2/4/2010 9:53:41 PM
mbam-log-2010-02-04 (21-53-41).txt

Scan type: Full Scan (C:\|)
Objects scanned: 322964
Time elapsed: 58 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\webmedia.chl (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\All Users\Start Menu\Online Antispyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.


SAS Log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/04/2010 at 11:11 PM

Application Version : 4.33.1000

Core Rules Database Version : 4558
Trace Rules Database Version: 2370

Scan type : Complete Scan
Total Scan Time : 00:39:05

Memory items scanned : 673
Memory threats detected : 0
Registry items scanned : 6721
Registry threats detected : 14
File items scanned : 32144
File threats detected : 133

Adware.ShopAtHomeSelect
HKLM\Software\Classes\CLSID\{E8DAAA30-6CAA-4b58-9603-8E54238219E2}
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32#ThreadingModel
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\ProgID
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\Programmable
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\TypeLib
HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\VersionIndependentProgID
HKCR\ToolBand.ShopAtHomeIEHelper.1
HKCR\ToolBand.ShopAtHomeIEHelper
HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C}
C:\PROGRAM FILES\SELECTREBATES\TOOLBAR\SHOPATHOMETOOLBAR.DLL
HKU\S-1-5-21-2249627288-277516385-4155468564-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}

Adware.Tracking Cookie
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][3].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Cam\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][5].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt
C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt

Rogue.WebMediaViewer
HKU\S-1-5-21-2249627288-277516385-4155468564-1006\Software\WebMediaViewer

Malware.Installer-Pkg/Gen
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE


ESET Log:

[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.16981 (vista_gdr.091215-2244)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=b2ca1fda90706a47bad8743498afb32f
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-05 06:42:24
# local_time=2010-02-05 12:42:24 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1024 16777191 100 0 38039465 38039465 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=148897
# found=6
# cleaned=6
# scan_time=3468
C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebates.exe.virprobably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebatesApi.exe.virprobably a variant of Win32/Adware.SAHAgent application (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebatesUninstall.exe.virprobably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.bak1.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.bak2.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.ini2.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C
Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Here is the log. Things seem pretty good now.

Malwarebytes' Anti-Malware 1.44
Database version: 3695
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

2/5/2010 6:54:51 PM
mbam-log-2010-02-05 (18-54-51).txt

Scan type: Quick Scan
Objects scanned: 163873
Time elapsed: 8 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done
To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Results of screen317's Security Check version 0.99.1
Windows XP Service Pack 3
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
AVG Free 8.5
ESET Online Scanner v3
Antivirus up to date! (On Access scanning disabled!)
``````````````````````````````
Anti-malware/Other Utilities Check:

Java(TM) 6 Update 13
Java(TM) SE Runtime Environment 6 Update 1
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java 2 Runtime Environment, SE v1.4.2_03
Out of date Java installed!
Adobe FLASH Player 10
Adobe Reader 9
``````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
AVG avgemc.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Firewall
  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.
AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has REALTIME protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
See this page for more info about malware and prevention.Great thanks so much. I really appreciate all your help.

I updated the Java as you instructed and I will review the information and install a firewall and antispyware. I have AVG currently installed but I am now on comcast and was wondering if there was any benefit to switch to McAfee that they provide free to customers?I do not like McAfee, but if you stay with AVG, you will have a more secure computer.
1693.

Solve : A few problems with my computer?

Answer»

Hi! I'm having a few problems with computer (32-bit vista).

- When I USE search engines I get re directed to different sites.
- Norton 360 not working.
- Microsoft Security Essentials is not installing
- Computer crashes randomly (blue screen saying that windows found a problem)
- I scanned with Superantispyware free edition and found lots of tracking cookies and trojans. After a second scan i found that there were some more cookies.

Thank you in advance for your help, as you can see when it comes to computers I have two left hands haha :p

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:12:11 PM, on 02/02/2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\spool\drivers\w32x86\3\printray.exe
C:\Program Files\LexmarkX73\ACMonitor_X73.exe
C:\Program Files\LexmarkX73\AcBtnMgr_X73.exe
C:\ProgramData\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Izn\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Izn\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\conime.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\Izn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Izn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Users\Izn\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=13818&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.5.2.11\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [PrinTray] C:\Windows\system32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TalkAndWrite] C:\ProgramData\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe /run
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [Google Update] "C:\Users\Izn\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'Izn')
O4 - HKUS\S-1-5-21-1269665831-4724830-4121108689-1002\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Izn')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.5.2.11\coIEPlg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\Combo-Fix21057C\PEV.cfxxe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 14136 bytesPlease visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.hey, I installed combo fix a few weeks ago. I tried scanning 4 times today. Twice on normal mode, this lead to my computer crashing before it could finish. Twice on safe mode with networking. In safe mode it found a root kit causing it to reboot my comp.

Heres a combofix log from a few days ago (I was still having the same problems back then, hopefully this is good enough. Thank you in advance for all your help.)

ComboFix 10-01-30.07 - Saqib 31/01/2010 12:01:47.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.3071.1434 [GMT -7:00]
Running from: c:\users\Saqib\Desktop\Combo-Fix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! Antivirus *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1269665831-4724830-4121108689-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2331971223-1396865169-3388170851-500
c:\$recycle.bin\S-1-5-21-953789392-149394006-1689920443-500
c:\program files\Mozilla Firefox\plc4.dll
c:\windows\E88D4.exe
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\drivers\H8SRTtmlegtcaex.sys
c:\windows\system32\H8SRTfvhgedmeuj.dll
c:\windows\system32\H8SRThmujwgcmon.dat
c:\windows\system32\H8SRTrkcmshcocq.dll
c:\windows\system32\H8SRTujybyfcopp.dll
c:\windows\system32\krl32mainweq.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-31 )))))))))))))))))))))))))))))))
.

2100-02-23 21:35 . 2001-02-22 16:54768----a-w-c:\windows\x73_lut.dat
2100-02-23 21:35 . 2001-02-22 16:54768----a-w-c:\program files\x73_lut.dat
2100-02-08 23:03 . 2001-05-11 18:3953248----a-w-c:\program files\ACMonitor_X73.exe
2010-01-31 19:15 . 2010-01-31 19:16--------d-----w-c:\users\Saqib\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:16--------d-----w-c:\users\Izn\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:15--------d-----w-c:\users\Sian\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:15--------d-----w-c:\users\Sami\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:15--------d-----w-c:\users\Izzah\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:15--------d-----w-c:\users\IUSR_NMPR\AppData\Local\temp
2010-01-31 19:15 . 2010-01-31 19:15--------d-----w-c:\users\Default\AppData\Local\temp
2010-01-31 18:39 . 2010-01-31 18:3915880----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-01-31 18:39 . 2010-01-31 18:39163728----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-01-31 18:39 . 2010-01-31 18:39327000----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-01-31 18:39 . 2010-01-31 18:3987496----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-01-31 17:55 . 2010-01-07 09:00177520----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\NAVENG32.DLL
2010-01-31 17:55 . 2010-01-07 09:001647984----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\NAVEX32A.DLL
2010-01-31 17:55 . 2010-01-07 09:001323568----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\NAVEX15.SYS
2010-01-31 17:55 . 2010-01-07 09:0084912----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\NAVENG.SYS
2010-01-31 17:55 . 2010-01-07 09:00371248----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\EECTRL.SYS
2010-01-31 17:55 . 2010-01-07 09:00259440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\ECMSVR32.DLL
2010-01-31 17:55 . 2010-01-07 09:00102448----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\ERASER.SYS
2010-01-31 17:55 . 2010-01-07 09:002747440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100131.003\CCERASER.DLL
2010-01-30 01:15 . 2009-12-31 04:48811896----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\Scxpx86.dll
2010-01-30 01:15 . 2009-12-31 04:48488312----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSxpx86.dll
2010-01-30 01:15 . 2009-12-31 04:48343088----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys
2010-01-30 01:15 . 2009-12-31 04:48329592----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSXpx86.sys
2010-01-30 01:15 . 2009-12-31 04:48466992----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSviA64.sys
2010-01-30 01:04 . 2009-08-22 08:14165240----a-r-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-01-26 22:39 . 2010-01-26 22:39--------d-----w-c:\users\Izn\AppData\Local\Xenocode
2010-01-26 00:46 . 2010-01-26 22:46--------d-----w-c:\program files\Mixed In Key 4
2010-01-22 01:33 . 2010-01-22 01:33--------d-----w-c:\users\Sian\AppData\Roaming\TeamViewer
2010-01-22 01:12 . 2010-01-22 01:12--------d-----w-c:\users\Saqib\AppData\Roaming\TeamViewer
2010-01-22 01:12 . 2010-01-22 01:12--------d-----w-c:\program files\TeamViewer
2010-01-21 23:36 . 2010-01-19 11:4219024----a-w-c:\windows\system32\drivers\aswFsBlk.sys
2010-01-21 23:36 . 2010-01-19 13:13162640----a-w-c:\windows\system32\drivers\aswSP.sys
2010-01-21 23:36 . 2010-01-19 11:4323248----a-w-c:\windows\system32\drivers\aswRdr.sys
2010-01-21 23:36 . 2010-01-19 11:4646544----a-w-c:\windows\system32\drivers\aswTdi.sys
2010-01-21 23:36 . 2010-01-19 11:4351792----a-w-c:\windows\system32\drivers\aswMonFlt.sys
2010-01-21 23:36 . 2010-01-19 11:5738848----a-w-c:\windows\system32\avastSS.scr
2010-01-21 23:36 . 2010-01-19 11:57152672----a-w-c:\windows\system32\aswBoot.exe
2010-01-21 23:35 . 2010-01-21 23:35--------d-----w-c:\programdata\Alwil Software
2010-01-21 23:35 . 2010-01-21 23:35--------d-----w-c:\program files\Alwil Software
2010-01-21 23:20 . 2010-01-21 23:20--------d-----w-c:\programdata\Yahoo! Companion
2010-01-21 23:20 . 2010-01-21 23:21--------d-----w-c:\program files\CCleaner
2010-01-21 22:59 . 2009-12-18 12:52832512----a-w-c:\windows\system32\wininet.dll
2010-01-21 22:55 . 2010-01-07 09:001647984----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\NAVEX32A.DLL
2010-01-21 22:55 . 2010-01-07 09:0084912----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\NAVENG.SYS
2010-01-21 22:55 . 2010-01-07 09:00177520----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\NAVENG32.DLL
2010-01-21 22:55 . 2010-01-07 09:001323568----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\NAVEX15.SYS
2010-01-21 22:55 . 2010-01-07 09:00102448----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\ERASER.SYS
2010-01-21 22:55 . 2010-01-07 09:00371248----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\EECTRL.SYS
2010-01-21 22:55 . 2010-01-07 09:00259440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\ECMSVR32.DLL
2010-01-21 22:55 . 2010-01-07 09:002747440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100121.005\CCERASER.DLL
2010-01-21 22:41 . 2010-01-21 22:41142----a-w-c:\programdata\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\uninst.bat
2010-01-21 01:09 . 2010-01-21 01:09--------d-----w-c:\program files\Common Files\Skype
2010-01-20 19:16 . 2010-01-31 18:393803208----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-01-20 01:41 . 2008-06-16 20:1181920----a-w-c:\windows\system32\emfxp.dll
2010-01-20 01:41 . 2010-01-21 01:49--------d-----w-c:\programdata\TalkAndWrite
2010-01-20 01:41 . 2010-01-20 01:41--------d-----w-c:\program files\TalkAndWrite
2010-01-16 18:26 . 2009-12-31 04:48811896----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-16 18:26 . 2009-12-31 04:48488312----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-16 18:26 . 2009-12-31 04:48343088----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-16 18:26 . 2009-12-31 04:48329592----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-16 18:26 . 2009-12-31 04:48466992----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys
2010-01-15 22:20 . 2010-01-15 22:20764168----a-w-c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-01-13 22:38 . 2010-01-17 22:26--------d-----w-c:\program files\VirtualDJ
2010-01-12 22:23 . 2009-10-19 14:42156672----a-w-c:\windows\system32\t2embed.dll
2010-01-12 22:23 . 2009-10-19 14:3924064----a-w-c:\windows\system32\lpk.dll
2010-01-12 22:23 . 2009-10-19 14:3772704----a-w-c:\windows\system32\fontsub.dll
2010-01-12 22:23 . 2009-10-19 14:3710240----a-w-c:\windows\system32\dciman32.dll
2010-01-12 22:23 . 2009-10-19 14:3634304----a-w-c:\windows\system32\atmlib.dll
2010-01-12 22:23 . 2009-10-19 11:45289792----a-w-c:\windows\system32\atmfd.dll
2010-01-08 22:36 . 2010-01-07 09:0084912----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\NAVENG.SYS
2010-01-08 22:36 . 2010-01-07 09:00177520----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\NAVENG32.DLL
2010-01-08 22:36 . 2010-01-07 09:001647984----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\NAVEX32A.DLL
2010-01-08 22:36 . 2010-01-07 09:001323568----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\NAVEX15.SYS
2010-01-08 22:36 . 2010-01-07 09:00102448----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\ERASER.SYS
2010-01-08 22:36 . 2010-01-07 09:00371248----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\EECTRL.SYS
2010-01-08 22:36 . 2010-01-07 09:002747440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\CCERASER.DLL
2010-01-08 22:36 . 2010-01-07 09:00259440----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100108.002\ECMSVR32.DLL
2010-01-08 01:25 . 2009-12-31 04:48811896----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2010-01-08 01:25 . 2009-12-31 04:48488312----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2010-01-08 01:25 . 2009-12-31 04:48343088----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2010-01-08 01:25 . 2009-12-31 04:48329592----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2010-01-08 01:25 . 2009-12-31 04:48466992----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2010-01-07 22:59 . 2010-01-11 23:03554352----a-r-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2010-01-07 22:29 . 2010-01-07 22:57--------d-----w-C:\Combo-Fix26869C
2010-01-07 22:28 . 2010-01-07 22:28--------d-----w-C:\Combo-Fix
2010-01-07 02:50 . 2009-01-15 19:1923848----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-07 02:50 . 2008-04-17 19:12107368----a-w-c:\windows\system32\GEARAspi.dll
2010-01-07 02:49 . 2009-08-22 08:1325648----a-r-c:\windows\system32\drivers\SymIMV.sys
2010-01-07 02:49 . 2010-01-11 23:04--------d-----w-c:\program files\Symantec
2010-01-07 02:49 . 2010-01-11 23:04124976----a-w-c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-07 02:49 . 2010-01-07 02:491290592----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2010-01-07 02:49 . 2010-01-07 02:49136840----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2010-01-07 02:49 . 2010-01-07 02:49796016----a-w-c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2010-01-07 02:49 . 2010-01-07 02:49--------d-----w-c:\program files\Norton 360
2010-01-07 02:40 . 2010-01-07 02:40--------d-----w-c:\program files\NortonInstaller
2010-01-06 22:54 . 2010-01-06 22:54--------d-----w-c:\users\Saqib\AppData\Local\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-31 18:40 . 2009-12-20 19:18862040----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-31 18:39 . 2009-12-20 19:18206944----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-31 18:39 . 2009-12-20 19:18390288----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-31 18:39 . 2009-12-20 19:18537576----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-31 18:39 . 2009-12-20 19:18389272----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-01-31 18:39 . 2009-12-20 19:188----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-31 18:39 . 2009-12-20 19:166296864----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-31 18:39 . 2009-12-20 19:16933120----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-31 18:39 . 2009-12-20 19:16816784----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-31 18:39 . 2009-12-20 19:16823928----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-01-31 18:39 . 2009-12-20 19:151643272----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-31 18:39 . 2009-12-20 19:15788880----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-31 18:38 . 2009-12-20 19:151181328----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-30 05:06 . 2009-02-28 03:14--------d-----w-c:\users\Sian\AppData\Roaming\Skype
2010-01-30 01:07 . 2009-01-31 23:53--------d-----w-c:\users\Sian\AppData\Roaming\skypePM
2010-01-29 02:10 . 2009-09-27 17:4512----a-w-c:\windows\bthservsdp.dat
2010-01-26 22:51 . 2009-05-31 22:03--------d-----w-c:\users\Izn\AppData\Roaming\uTorrent
2010-01-24 06:02 . 2008-06-30 05:22--------d-----w-c:\users\Izn\AppData\Roaming\Roxio
2010-01-23 17:50 . 2008-04-16 00:088268----a-w-c:\users\Izn\AppData\Local\d3d9caps.dat
2010-01-22 22:57 . 2009-09-12 19:1869----a-w-c:\users\Izn\jagex_runescape_preferences2.dat
2010-01-22 22:57 . 2008-07-01 18:3739----a-w-c:\users\Izn\jagex_runescape_preferences.dat
2010-01-21 23:21 . 2008-01-24 23:53--------d-----w-c:\program files\Yahoo!
2010-01-21 01:10 . 2009-02-28 01:42--------d-----r-c:\program files\Skype
2010-01-21 01:09 . 2009-01-31 23:49--------d-----w-c:\programdata\Skype
2010-01-20 18:58 . 2009-05-03 17:31--------d-----w-c:\program files\Microsoft Silverlight
2010-01-13 04:03 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
2010-01-12 23:04 . 2008-01-24 23:53--------d--h--w-c:\programdata\yahoo!
2010-01-12 23:00 . 2009-03-03 04:25--------d-----w-c:\program files\AskBarDis
2010-01-11 23:04 . 2009-10-04 01:48--------d-----w-c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2010-01-11 23:04 . 2010-01-07 02:49806----a-w-c:\windows\system32\drivers\SYMEVENT.INF
2010-01-11 23:04 . 2010-01-07 02:497456----a-w-c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-07 23:38 . 2009-04-28 01:54--------d-----w-c:\users\Saqib\AppData\Roaming\LimeWire
2010-01-07 03:40 . 2008-01-24 23:54--------d-----w-c:\program files\Common Files\Symantec Shared
2010-01-07 03:36 . 2008-04-15 03:431356----a-w-c:\users\Saqib\AppData\Local\d3d9caps.dat
2010-01-07 02:50 . 2009-10-04 01:32--------d-----w-c:\programdata\NortonInstaller
2010-01-07 02:49 . 2008-01-24 23:54--------d-----w-c:\programdata\Symantec
2010-01-04 19:05 . 2009-12-06 00:37--------d-----w-c:\program files\M-Audio
2010-01-03 07:12 . 2008-05-11 22:34--------d-----w-c:\users\Izn\AppData\Roaming\LimeWire
2009-12-30 19:16 . 2009-12-30 19:1673728----a-w-c:\users\Saqib\AppData\Roaming\LimeWire\browser\xulrunner\xulrunner-stub.exe
2009-12-30 19:15 . 2009-12-30 19:15--------d-----w-c:\program files\LimeWire
2009-12-24 18:16 . 2009-05-31 22:04--------d-----w-c:\program files\uTorrent
2009-12-24 03:18 . 2009-12-24 01:37--------d-----w-c:\users\Izn\AppData\Roaming\GetRightToGo
2009-12-24 03:16 . 2009-12-24 03:48258352----a-w-c:\windows\system32\unicows.dll
2009-12-23 23:48 . 2009-05-31 22:04--------d-----w-c:\users\Saqib\AppData\Roaming\uTorrent
2009-12-21 23:42 . 2009-12-21 23:42367686----a-r-c:\users\Izn\AppData\Roaming\Microsoft\Installer\{E2BF2060-D1DB-441A-8739-30E7BAA534BA}\_C22EE15BDC4445E6B3F0CD.exe
2009-12-21 23:42 . 2009-12-20 00:37--------d-----w-c:\program files\DENON_DJ
2009-12-21 22:47 . 2008-01-24 23:29--------d--h--w-c:\program files\InstallShield Installation Information
2009-12-20 04:55 . 2009-12-20 04:55--------d-----w-c:\program files\PCDJ Reflex LE
2009-12-20 00:47 . 2009-12-20 00:47--------d-----w-c:\programdata\DDJ_ASIO_Driver
2009-12-18 12:48 . 2010-01-21 22:5856320----a-w-c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-21 22:5878336----a-w-c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-21 22:5852736----a-w-c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-21 22:5872704----a-w-c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-21 22:5826624----a-w-c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-21 22:5848128----a-w-c:\windows\system32\mshtmler.dll
2009-12-18 02:35 . 2009-12-18 02:35--------d-----w-c:\program files\Lame for Audacity
2009-12-16 02:52 . 2008-07-31 05:39--------d-----w-c:\users\Sian\AppData\Roaming\Apple Computer
2009-12-16 02:34 . 2008-07-19 01:17--------d-----w-c:\users\Saqib\AppData\Roaming\Apple Computer
2009-12-13 19:15 . 2009-12-13 19:13--------d-----w-c:\programdata\Lavasoft
2009-12-13 19:14 . 2009-12-13 19:14--------dc-h--w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-13 19:13 . 2009-12-13 19:13--------d-----w-c:\program files\Lavasoft
2009-12-13 07:21 . 2009-12-13 07:21--------d-----r-c:\program files\Norton Support
2009-12-13 02:04 . 2009-12-13 02:04--------d-----w-c:\program files\Audacity
2009-12-09 00:36 . 2009-12-09 00:36--------d-----w-c:\users\Izn\AppData\Roaming\M-Audio
2009-12-08 01:01 . 2009-12-08 01:01484976----a-w-c:\programdata\Google\Google Toolbar\Update\gtbC534.tmp.exe
2009-12-07 14:10 . 2009-12-13 19:142953352-c--a-w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-12-03 04:59 . 2008-04-15 02:17127624----a-w-c:\users\Saqib\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-02 13:19 . 2009-12-13 19:1564288----a-w-c:\windows\system32\drivers\Lbd.sys
2009-12-02 13:19 . 2009-12-13 22:1315880----a-w-c:\windows\system32\lsdelete.exe
2009-11-09 13:34 . 2009-12-09 04:0524064----a-w-c:\windows\system32\nshhttp.dll
2009-11-09 13:30 . 2009-12-09 04:0531232----a-w-c:\windows\system32\httpapi.dll
2009-11-09 11:17 . 2009-12-09 04:05396800----a-w-c:\windows\system32\drivers\http.sys
2009-11-06 03:28 . 2009-11-06 03:2879144----a-w-c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2001-07-26 23:58 . 2000-01-11 19:5047----a-w-c:\program files\ACMonitor_X73.ini
2001-07-05 19:46 . 2001-07-20 17:488116----a-w-c:\program files\OSLO3071b2.USB
2001-05-08 23:36 . 2000-12-05 22:56114688----a-w-c:\program files\lxarscan.dll
2001-04-23 21:22 . 2100-02-08 22:531437----a-w-c:\program files\gtx73.ini
2009-04-01 04:47 . 2009-08-24 23:37324976----a-w-c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-01-24 22:59 . 2008-01-24 22:548192--sha-w-c:\windows\Users\Default\NTUSER.DAT
.

------- Sigcheck -------

[-] 2008-04-16 00:23 . BA0787C5520D54733BA409B62BBA9A53 . 21560 . . [------] . . c:\windows\System32\drivers\atapi.sys
[7] 2008-04-16 . B35CFCEF838382AB6490B321C87EDF17 . 21560 . . [6.0.6000.16632] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[7] 2008-01-19 . 2D9C903DC76A66813D350A562DE40ED9 . 21560 . . [6.0.6001.18000] . . c:\windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[7] 2006-11-02 . 4F4FCB8B6EA06784FB6D475B7EC7300F . 19048 . . [6.0.6000.16386] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-04-16 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-06-01 1783400]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"="FactoryMode" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-24 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-11 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-11 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-11 88608]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"PrinTray"="c:\windows\system32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-12 36864]
"Lexmark X73 Button Monitor"="c:\progra~1\LEXMAR~1\ACMonitor_X73.exe" [2001-10-08 53248]
"Lexmark X73 Button Manager"="c:\progra~1\LEXMAR~1\AcBtnMgr_X73.exe" [2001-07-11 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"TalkAndWrite"="c:\programdata\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe" [2009-02-28 3062784]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-12-11 722256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-01-19 2743104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

c:\users\Saqib\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Snapfish Media Detector.lnk - c:\program files\Snapfish Picture Mover\SnapfishMediaDetector.exe [2007-5-7 1273856]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [13/12/2009 12:15 PM 64288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\N360\0305020.00B\SymEFA.sys [11/01/2010 4:03 PM 310320]
R1 aswSP;aswSP;c:\windows\System32\drivers\aswSP.sys [21/01/2010 4:36 PM 162640]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\N360\0305020.00B\BHDrvx86.sys [11/01/2010 4:03 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\N360\0305020.00B\cchpx86.sys [11/01/2010 4:03 PM 482432]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100128.002\IDSvix86.sys [29/01/2010 6:15 PM 343088]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [21/01/2010 4:36 PM 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [21/01/2010 4:36 PM 51792]
R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [24/01/2008 4:46 PM 198240]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [11/01/2010 4:03 PM 117640]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [12/01/2010 7:57 AM 185640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [29/06/2008 12:43 PM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [07/01/2010 6:26 PM 102448]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [26/02/2008 8:17 AM 493568]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\N360\0305020.00B\symndisv.sys [11/01/2010 4:03 PM 48688]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\System32\drivers\WSDPrint.sys [02/11/2006 3:25 AM 16896]
R3 xcbdaNtsc;ViXS Tuner Card (NTSC);c:\windows\System32\drivers\xcbda.sys [07/09/2007 5:36 AM 156928]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [03/09/2006 11:32 AM 208896]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [10/05/2006 10:13 AM 29696]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/12/2009 6:19 AM 1181328]
S3 MADFU;MADFU;c:\windows\System32\drivers\MADFU.sys [05/12/2009 1:45 AM 16512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcsREG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1002Core.job
- c:\users\Izn\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-07 01:04]

2010-01-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1269665831-4724830-4121108689-1002UA.job
- c:\users\Izn\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-07 01:04]

2010-01-31 c:\windows\Tasks\User_Feed_Synchronization-{0DF703CF-8A20-4FC2-AB2D-3B7F609F968B}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

2010-01-31 c:\windows\Tasks\User_Feed_Synchronization-{9D23CA72-CD71-44E2-BFDA-BE3B3D39E8DE}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

2010-01-31 c:\windows\Tasks\User_Feed_Synchronization-{A28E1254-1A9E-448F-9BBB-C22291493DAC}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/?o=13818&l=dis
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Saqib\AppData\Roaming\Mozilla\Firefox\Profiles\nqfgqqgp.default\
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-31 12:16
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x87885E07]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x82c56d1f
\Driver\ACPI -> acpi.sys @ 0x804699d6
\Driver\atapi -> ataport.SYS @ 0x8078d9c6
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x8259727f
SecurityProcedure -> ntkrnlpa.exe @ 0x825964a3
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x8259727f
SecurityProcedure -> ntkrnlpa.exe @ 0x825964a3
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-31 12:19:46
ComboFix-quarantined-files.txt 2010-01-31 19:19

Pre-Run: 203,572,072,448 bytes free
Post-Run: 203,772,313,600 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 722FC9ADAD8A10CD68683CF98D202423Hi again. Please do these steps in order.

1. Please download TFC by OldTimer to your desktop

  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
2. Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer:

http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Post the log from SUPERAntiSpyware when you've accomplished that.

4. Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

5. Post the following in your next reply:
  • MBAM log
  • SAS log
  • ESET log
And, please tell me how your computer is doing.Thank you for all your help so far. Search engines are still rerouting to different sites, however norton is working again, my computer is noticeably faster, and my computer has not crashed once since mbs scan. Anyways here are my logs:

Malwarebytes' Anti-Malware 1.44
Database version: 3691
Windows 6.0.6000 (Safe Mode)
Internet Explorer 7.0.6000.16982

04/02/2010 5:59:25 PM
mbam-log-2010-02-04 (17-59-05).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 393684
Time elapsed: 1 hour(s), 4 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No MALICIOUS items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\ProgramData\sysReserve.ini (Malware.Trace) -> No action taken.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/04/2010 at 09:45 PM

Application Version : 4.33.1000

Core Rules Database Version : 4548
Trace Rules Database Version: 2360

Scan type : Complete Scan
Total Scan Time : 02:27:50

Memory items scanned : 756
Memory threats detected : 0
Registry items scanned : 8898
Registry threats detected : 0
File items scanned : 56352
File threats detected : 10

Adware.Tracking Cookie
C:\Users\Izn\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Izn\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Users\Sian\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt


[emailprotected] as CAB hook log:
OnlineScanner.ocx - registred OK


(not sure why the last log is like that, is that normal?)
If ESET online scanner produce no results, then yes - that is ok.

Let's get a final malware check here:

Please download Cheetah-Anti-Rogue, and save to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.cmd to start.
  • It will finish quickly and launch a log.
  • Post the contents of it in your next reply.
KK done. Again thank you for all your help I know your all volunteers here and are spending your own free time on this so I really appreciate it.

Heres the log:

Cheetah-Anti-Rogue v1.2.17
by DragonMaster Jay

Microsoft Windows [Version 6.0.6000]
Date: 06/02/2010 - Time: 11:23:38 - Arch.: x86


-- Malware tools check --
CCleaner
Trend Micro HijackThis 2.0.2
Malwarebytes' Anti-Malware
SUPERAntiSpyware


-- Known infection --



Extra message: Detection only.


EOF
To manually create a new Restore Point
  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive i.e. C
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
You are now done

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Here it is mate.

Results of screen317's Security Check version 0.99.1
Windows Vista (UAC is enabled)
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Disabled!
ESET Online Scanner v3
Norton 360
WMIC entry does not exist for antivirus; attempting automatic update.
``````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
SUPERAntiSpyware Free Edition
HijackThis 2.0.2
CCleaner
Java(TM) 6 Update 18
Java(TM) SE Runtime Environment 6 Update 1
Java Auto Updater
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 8.1.3
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe is disabled!
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

=====

Please consider updating to Windows Vista Service Packs 1 & 2.
Windows Vista Service Packs 1 & 2 contain all the updates released since the first release plus support for new types of hardware and emerging hardware standards.
It is now available via Windows Update or as a standalone installation here.

=====

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

AntiSpyware
  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and BECOME less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a LOT of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:
1694.

Solve : Atapi.sys Google Redirect Problem?

Answer»

You're WELCOME.

1695.

Solve : System infected.?

Answer»

I have a message on my desktop that my system is infected and spyware activity has been detected. I am also UNABLE to open any pdf FILES. I tried system restore but get a message" Application cannot be executed. the file is infected . please activate antivirus software.Also the computer is running very slow. How can I get rid of the spyware / malware?Quote from: tpayne on February 08, 2010, 10:40:27 AM

I have a message on my desktop that my system is infected and spyware activity has been detected. I am also unable to open any pdf files. I tried system restore but get a message" Application cannot be executed. the file is infected . please activate antivirus software.Also the computer is running very slow. How can I get rid of the spyware / malware?
system is windows XPPlease download Cheetah-Anti-Rogue, and save to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.cmd to start.
  • It will finish quickly and launch a log.
  • Post the contents of it in your next reply.
Thanks Jay,

Here is the log

Cheetah-Anti-Rogue v1.2.17
by DragonMaster Jay

Microsoft Windows XP [Version 5.1.2600]
Date: 02/08/2010 - Time: 17:35:22 - Arch.: x86


-- Malware tools check --
SUPERAntiSpyware


-- Known infection --

C:\Program Files\Internet Explorer\msimg32.dll (Adw.MyWebSearch)
C:\Documents and Settings\Terry\Application Data\Microsoft\Internet Explorer\Desktop.htt (Trj.FakeAlert)


Extra message: Detection only.


EOF
Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just FOLLOW the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then SHOW Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (SEE Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
1696.

Solve : Struggling with slow m/c, LONG re-boot and lost HDD space?

Answer»

Hi, hope you can help me.

The machine is a small but crucial laptop - Dell Inpiron 2600 - long in tooth but still vital to me. Runs XP with SP2, Celeron 1066Mhz, 382 Mb RAM, 830M graphics controller, 20G HDD (with 5G free space but more about this later).

Have struggled for a long time (years?) with slow processing and a 30+ minute re-boot time. Get lots of HDD chattering until eventually I get to do some work.

What prompts this cry for help is that in last few days I created 5Gb free space by deleting stuff, removing stuff and compressing the drive during Disk Cleanup and then within a few days the 5Gb disappeared and shows me having just 156Mb free space!

This afternoon, have CAREFULLY followed the clearing up stages shown on thread 46313 and now have the 5Gb back - but the processing is still really slow.

Please can someone have a look at the attached logs and see if there is a visible cause for the slow processing and any possible ACTION I could take?

I would really APPRECIATE any help you can give as I have a large job to do on here and I dread the slow processor.

Thanks in anticipation
Grody



[SAVING space, attachment deleted by admin]Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.

1697.

Solve : Google Redirection and Others?

Answer»

Hi, and sorry if I previously posted to another thread. I didn't realize that I wasn't supposed to do that.

I started out with Antivirus Live problems. Using research on the web, I seemed at first successful at getting rid of it by going into the registry, removing all references to what it seemed to call itself (becusysguard.exe), and then deleting the folder it put in my c:\documents and settings\myname\local settings\application data\random dir\becusysguard.exe. Also, I took out the proxy settings from IE that it put in on its behalf.

This worked for about two weeks, but I keep getting hit with similar "You have a virus blah blah blah" infection - similar to Antivirus Live, but a different infection. In these later cases, the infection locks me out of just about everything, and the only way I can resolve is to boot the Windows XP CD into repair mode and then copy a bare bones registry from c:\windows\repair, and then boot into safe mode and then PICK a RESTORE point before infection. These are temporary fixes. Within a few days, I get hit with something else.

At one point, I downloaded and installed McAfee, and since then I haven't gotten the "Antivirus Live" type of issues, but now I have what seems to be the Google Redirection issue. The computer also seems to be doing funky things - screen vibrates, scroll bars advance on their own - almost as if someone is remoted in.

So, I went through all the Read Me First posts and did all the scans. I will attach the logs here. In Add / Remove Programs, the only thing I don't recognize is WindowsLive OneCare Safety Scanner. I didn't see this on any list of viruses or malware, and I don't suspect it's a problem, but I mention it here.

So thank you for all of your kind help, and I hope that we can get rid of this thing. Is it possible that my IP Address is open to someone, so that even though I clean my machine, they can continue to re-enter and infect? Would they be getting through my firewall if that were the case?

[Saving space, attachment deleted by admin]Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and logs posted for each one)

* Copy the file path in the below Code box:
Code: [Select]C:\Documents and Settings\Stu\Start Menu\Programs\Startup\SUN.EXE* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is finished, Copy and then Paste the link in the address BAR into your next reply.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixCombofix froze while running unattended. I let it be for a few hours. I went into task manager to do an orderly shutdown, and that froze too. After a hard power reset, the machine just rebooted itself during startup even when attempting safe mode. Going into the recovery console and copying a bare bones registry from c:\windows\repair into c:\windows\system32\config did not resolve this. Neither did fixboot, chkdsk, or any other utility I could find. I did a repair install of Windows XP which got me running again, but at this point, I'll say that the machine is unstable enough to validate a clean install from scratch. So, I'll get started on that, and after many hours of updates, plus driver installs, etc... I'll come back in and say hello. Oh, and that Sun.EXE is a legit program that sits in the systray. It just tells you sunrise and sunset times and is more than ten years old. You can check this out at www.sunrisesunset.com The Jotti's malware scan didn't pick up anything for this...

http://virusscan.jotti.org/en/scanresult/8962ed2bc3277daa3b0ef278cb96291145f51ac9

All OK as per above, but I'm having trouble reinstalling McAfee Security. After downloading and installing, it says I have remnants of Enterprise. I don't see how this is possible with a newly formatted HD, but nonetheless, I can't find the McAfee Enterprise Removal Tool to try and get rid of it. Anyone know where I may get this?Sorry I somehow missed your prior reply...


Try this for the McAfee errors.

Download the McAfee Consumer Product Removal Tool to your Desktop.

Using McAfee Consumer Product Removal tool:

* Double click the MCPR.exe
* A Command Line window will be displayed, and then close automatically.
* Wait for a second Command Line window to be displayed.

Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.

* After the second window appears, the program will BEGIN the cleanup.
* Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
* Press Y on the keyboard.
* Wait for the computer to restart.
* All McAfee products are now removed from your computer.

1698.

Solve : NvCplDaemon?

Answer»

I am running MSI/SpywareBlaster and web of TRUST and I have Comodo registry cleaner after running registry cleaner I clicked on the startup tab and noticed this NvCplDaemon what is it ?
Do I need to get rid of it?
How?Please ignore this post I overreacted done some checking and found out I my computer runs this at start up has SOMETHING to do about setting clock speed.Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.

There are a number of them available and some are more safe than others. Keep in MIND that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. WITHOUT research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated METHOD to cause problems with the registry.

For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

Further reading: XP Fixes Myth #1: Registry Cleaners

1699.

Solve : HP Pavillion ZD7000 has a virus, trojan?! Help!?

Answer»

I was useing my Hp laptop last week and i download a torrent it was windows Chicago which was made in 1993 (so they say) and i used Bit Torrent to fully download it. the next DAY i boot it up and the welcome screen loads longer and the following ERROR shows up:
"Security Warning!
Worm. Win32. Netsky detected on your machine.
This virus is distributed via the internet though e-mail and active-x objects.
The worm has it's own SMTP engine which means it gathers e-mails from your local computer and re-distributes itself.
viruses can damage your confidential data and work on your computer.
Continue working in unprotected mode is very dangerous.

Type: virus
system affected: windows 2000, Nt, Me, Xp, vista, 7
security risk(0-5): 5
Recomendations: It is necessary to perform a full sytem scan.

then when i click ok the computer finishes loading and instead of my desktop it shows a green screen with the words Your system is infected and some more............
then it does a scan through antivirus plus and finds:

SecurePCCCleaner
Dialer.trafficjam
trojan.poision.j
win32.delbot

and it goes on and on
My system has:

3 GHz processor
512 mg RAM
80 Gb hdd
Dvd burner

any HELP PLEASE!? Is there anything i can do WITHOUT wiping out the Hdd?Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.

1700.

Solve : computer slow & hanging up in internet...had a trojan (see below)?

Answer»

Hi, not long ago I had a trojan, which supposedly i got rid of...when I start my computer it says that C:\progra1/my WEB not found..My computer has gotten horribly slow within the last 3 wks and when I click on something to look at on the internet it will hang up but after a few minutes it will unhang. I'm a medical transcriptionist and can't be down...Quote

I'm a medical transcriptionist and can't be down...


Then you have a company computer right? What about tech support?

no..I'm self employed.Download TrendMicro HijackThis.exe (HJT) to the desktop.

* Double-click on HJTInstall.
* Click on the Install button.
* It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
* Upon install, HijackThis should open for you.
* Important! If using WINDOWS Vista or Windows 7, close HijackThis. Now right-click HijackThis and Run As Administrator
* Click on the Do a system scan and save a log file button
* HijackThis will scan and then a log will open in notepad.
* Copy and then paste the entire contents of the log in your post.
* Do not have HijackThis fix ANYTHING yet. Most of what it finds will be harmless or even required.