Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2101.

Solve : download to stop spam?

Answer»

has anyone USED or heard of "AKISMET " spam blocker

if so , is it any good , because my spam blocker is not working , i'm getting over 100 every day , or do you have another i could download

thanks for your HELP , harry

I know I asked before but I forgot.

What sort of email account?If it's free web mail there isn't anything much you can do about it. Go into the options and make sure the spam filter is turned on. Other then that, it's the perils of free email...spam guard is always on , what do you think of the download against itYou can't use third party SOFTWARE with Yahoo mail.sorry to write again

yahoo have disposible e-mail addresses , are they any good , have you used them

harryThey are disposable, not good for much but filling out forms.ok , i'll just give up and keep deletingI have a free Yahoo account. I only use it when I don't fully trust the site/form I am filling in. Yahoo is the worst at spam control. Google, while you might get a lot of spam, is ACTUALLY very efficient at putting it in the spam folder. Maybe one a month will slip through to the actual in box. Yahoo I get about 10 a day that slip through the spam filter..I NEVER GET ANY THAT SLIP TO MY E-MAIL BOX I'M JUST FED UP AT TAKING OUT OVER 100 A DAYIf they are going to the spam box then that is the whole point of the spam box. i understand that , but i'm old and can't be bother with that and get fed up with them , just want rid of them ok thanks for your help , i'll get my hot DRINK and go to bed , harry

2102.

Solve : Help with Virus Removal?

Answer»

Hi - I am learning the hard way why a person should keep their antivirus s/w up to date.

I am having some kind of internet explorer issue where it redirects my browswer each time I try to click a site. SOmetimes I see an ICON on my desktop called CASINO which TAKES me to a pop-up site.

I tried to download the tools to post the 3 logs, but I am unable to get to any site (apparently the virus is keeping me from it). I"m actually really surprised I can visit this site.

I did get the CC Cleaner and I did run it.

Any suggestions on how i can get the tools to run the log/checks? I f I need to I can just bring them in on a thumb drive from another system somwhere.Do you have access to another COMPUTER? You can save the programs to a flash drive, then plug the flash drive into infected computer and run it that way.I'm having the same problem but without the casino icon thing. speckulizer, if you can't get to a site to download something, try looking for it on download.com, that's how I downloaded Spybot Search & Destroy after my virus wouldn't let me get to the official site. Quote from: Cyborger on September 17, 2008, 06:35:55 AM

I'm having the same problem but without the casino icon thing. speckulizer, if you can't get to a site to download something, try looking for it on download.com, that's how I downloaded Spybot Search & Destroy after my virus wouldn't let me get to the official site.
If you have the same problem, PLEASE start a new topic.
2103.

Solve : Invalid registry entry ShellExecuteHook Typ DLL?

Answer»

My Security Task Manager test version is reporting again invalid registry entry 5AE067D3-9AFB-48E0-8532-EBB7F4A000DA.

can i remove it manually too? like using regedit.exe and delet the invalid key?

(i'm thinking to buy security task manager in order to use the full version to remove such entries. i can do so at the end of the month.)What is the exact error message?here is a screen shot http://i10.photobucket.com/albums/a147/besosdefuego/ALBUM/STM.jpgI believe you should post a HijackThis Log.

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthisi have noticed that my bitdefender test version was not working right. there were 2 depending issues to fix. one of them was online security. i don't know what was the other one. i got an error message when fixing it.
right now no issue is open.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:18:11, on 18.09.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
C:\Programme\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe
C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
C:\Programme\BitDefender\BitDefender 2009\bdagent.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
C:\Programme\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe
C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
C:\Programme\Vidalia Bundle\Tor\tor.exe
C:\Programme\BitDefender\BitDefender 2009\seccenter.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Security Task Manager\TaskMan.exe
C:\Programme\PhotoScape\PhotoScape.exe
C:\Programme\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\MICROSOFT\Internet Explorer\Main,Start Page = www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper CLASS - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Programme\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Keyboard Manager Utility] "C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe" /lang DE /H
O4 - HKLM\..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Programme\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Programme\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Programme\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Vidalia] "C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Privoxy.lnk = C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Programme\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE CONTROL) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162468014625
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programme\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: BitDefender Arrakis SERVER (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Programme\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Programme\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 8033 bytes

2104.

Solve : Annoying "Talking" Virus?

Answer»

This thing is really starting to piss me off... It'll start up some .sys file (changes almost every time I see it) and start playing me some COMMERCIALS or some ads or something. This is a shared computer in my office, so I don't know who/what/when/etc. happened. One thing I do know though... this thing has created a user account in windows with administrative access... I've deleted it, changed it's password, changed it's rights... just keeps coming back. User name is IUser_Admin. Someone please help. Thanks!

Oh, here's the hijackthis log...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:39 AM, on 9/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\a-squared free\a2service.exe
C:\WINDOWS\system32\afisicx.exe
C:\Documents and Settings\oper\.cisco_mds9000\bin\Wrapper.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Java\jre1.5.0\bin\javaw.exe
C:\WINDOWS\system32\mabidwe.exe
C:\WINDOWS\system32\macidwe.exe
C:\WINDOWS\system32\noxtcyr.exe
C:\WINDOWS\system32\noytcyr.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PDF Complete\pdfsvc.exe
C:\WINDOWS\system32\roytctm.exe
C:\WINDOWS\system32\soxpeca.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tdxdowkc.exe
C:\WINDOWS\system32\tdydowkc.exe
C:\WINDOWS\system32\wsldoekd.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\TEMP\BO1A3B.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Atomic Clock Sync\Atomic.exe
C:\Novell\Messenger\NMCL32.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\STCHost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\CSISCMGR.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O1 - Hosts: 75.125.165.202 axexe.com
O2 - BHO: ADOBE PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Atomic.exe] C:\Program Files\Atomic Clock Sync\Atomic.exe
O4 - HKCU\..\Run: [ShoreTel Personal Call Manager] C:\Program Files\Shoreline Communications\ShoreWare Client\StartCli.exe
O4 - HKCU\..\Run: [Novell Messenger] "C:\Novell\Messenger\NMCL32.exe"
O4 - HKCU\..\Run: [Fomiu] C:\WINDOWS\system32\??mantec\l?gonui.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: taskmgr.lnk = C:\WINDOWS\system32\taskmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra 'Tools' menuitem: Novell Messenger - {3C3171BC-1025-43d1-8D1D-61CF4B38A28F} - C:\Novell\MESSEN~1\NMCL32.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - https://172.16.10.16:4343/officescan/console/html/ClientInstall/WinNTChk.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - https://172.16.10.16:4343/officescan/console/html/ClientInstall/setup.cab
O16 - DPF: {245338C3-BCA3-4A2C-A7B7-53345999A8E8} (WSpell ActiveX Spelling Checker V5.15) - http://magic8app/magic/wspell.cab
O16 - DPF: {25B82430-A083-4C36-9D72-A4868E744CE2} (MGCSpellCheckAM.MDictionaryAM) - http://magic8app/magic/wspellAM.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - https://172.16.10.16:4343/officescan/console/html/ClientInstall/RemoveCtrl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184157984937
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://magic8app/SCRmagic/Reports/activeXViewer/activexviewer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = clarksdns.com
O17 - HKLM\Software\..\Telephony: DomainName = clarksdns.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = clarksdns.com
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: afisicx Settings storage service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Cisco MDS Fabric Manager (FMServer) - Unknown owner - C:\Documents and Settings\oper\.cisco_mds9000\bin\Wrapper.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe
O23 - Service: macidwe Service (macidwe) - Unknown owner - C:\WINDOWS\system32\macidwe.exe
O23 - Service: noxtcyr Manages messages (noxtcyr) - Unknown owner - C:\WINDOWS\system32\noxtcyr.exe
O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: perfs Service (perfs) - Unknown owner - C:\WINDOWS\system32\perfs.exe (file missing)
O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe
O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe
O23 - Service: tdxdowkc Service (tdxdowkc) - Unknown owner - C:\WINDOWS\system32\tdxdowkc.exe
O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: wsldoekd Portable Media Serial Service (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe

--
End of file - 10189 bytes

One last note... This is an office computer and IE7, Firefox, and XP SP3 have not been 'approved' yet, so that's why they are not installed.We need permission from the IT department before advising any further as this is a work machine...Quote from: patio on September 14, 2008, 08:59:37 AM

We need permission from the IT department before advising any further as this is a work machine...

I spoke with the Desktop Support Manager about trying this and he said he's sick of pulling his hair out, so if I can find other answers I can do it as long as I don't upgrade to SP3 (some of our software hasn't been tested with it yet) or upgrade to IE7 (some of our web based applications don't appear to work with it - yet). Also, I am in the IT department (I work in the NOC), but I mostly deal with the mainframe and Novell and Linux based servers, so Windows and I don't get along...Got it.
In the meantime i'm going to move this to the Virus and Spyware section...
One of our Specialists should be along shortly.
Best of Luck and Welcome Aboard !Thanks... and sorry for posting in the wrong board. I look forward to whatever help y'all can give me... :-)This is a severely infected computer. I see at least 5 rootkits installed. If you know anything about rootkits then you know just how dangerous they can be to a computer, not to mention a shared office computer.

My suggestion is to flatten the drive and reinstall.

Read the below information and let me know what you want to do.

One or more of the identified infections was related to a rootkit componet. Rootkits are very dangerous because they use advanced techniques as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit was identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because a rootkit has been removed the computer is secure. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS. Please read When should I re-format? How should I reinstall? and Reformatting the computer or troubleshooting; which is best?.

Wow... that was not happy news... Thanks for the input. I'll let my Desktop Support guy know what's going on... could you please tell me which ones are "rootkits" so that I can give him a better report?

Great... I have used this computer for banking needs too... *sigh*

Thanks again...These are the ones that are showing. Remember HijackThis only shows some forms of malware and running processes. It doesn't see hidden nasties. I have helped in cleaning this type of infection before but it isn't easy and can easily stretch into a few days or more (depending on your and my schedules).

These are the ones that are easily identified. This particular rootkit will often install 2 or 3 drivers for each rootkit service it installs so there is definitely much more going on then what I can see now.

O23 - Service: perfs Service (perfs) - Unknown owner - C:\WINDOWS\system32\perfs.exe (file missing)
O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe
O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe
O23 - Service: tdxdowkc Service (tdxdowkc) - Unknown owner - C:\WINDOWS\system32\tdxdowkc.exe
O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe

----------

Lets go ahead and maybe see just how bad it is. Sometimes they will go away without a huge fight.

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web BROWSERS. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

Best way out of this is too wipe the hard drive clean, its going to take a lot of time to remove all infected files. Quote from: kizza1645 on September 16, 2008, 03:40:07 AM
Best way out of this is too wipe the hard drive clean, its going to take a lot of time to remove all infected files.

That may be the easiest way for you....

Would you like to learn to fight malware?Quote from: evilfantasy on September 16, 2008, 10:10:12 AM
Quote from: kizza1645 on September 16, 2008, 03:40:07 AM
Best way out of this is too wipe the hard drive clean, its going to take a lot of time to remove all infected files.

That may be the easiest way for you....

Would you like to learn to fight malware?

No, i dont, its just so easy to wipe it. why bother searching for the littbe buggers.Quote from: kizza1645 on September 17, 2008, 12:06:36 AM

No, i dont,

Then leave it for those of us that do....
2105.

Solve : Keylogger ??

Answer»

My cousin downloaded a game (Eudemons, free server)

I heard tonight that it comes with keyloggers. I fear they keyloggers and trojans can get past my firewall (ZoneAlarm).

I made a hijackthis! report.

Can ANYONE scan it and tell me if I am safe ?

---------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:49 PM, on 17/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\AVG8~1\avgwdsvc.exe
c:\program files\dvrms\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\AVG8~1\avgrsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\AVG8~1\avgemc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\DISC\DiscGui.exe
C:\program files\common files\installshield\updateservice\issch.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ZoneAlarm new install\zlclient.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\AVG8~1\avgtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\! WeatherEye\WeatherEye.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\AnalogX MaxMem\maxmem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\FreeMeter_v1.5.2873_with_icons\FreeMeter.exe
C:\DOCUME~1\Alice\LOCALS~1\Temp\irsetup.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Conquer\Conquer.exe
C:\Program Files\Conquer\Conquer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\ClamWin\bin\clamscan.exe
c:\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 124.225.65.173:80
O2 - BHO: Adobe PDF Reader LINK Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG 8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [HPHUPD08] "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
O4 - HKLM\..\Run: [DISCover] "C:\Program Files\DISC\DISCover.exe"
O4 - HKLM\..\Run: [DiscUpdateManager] "C:\Program Files\DISC\DiscUpdateMgr.exe"
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [ISUSPM Startup] C:\Program Files\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ATIPTA] "C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE"
O4 - HKLM\..\Run: [QUICKTIME Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm new install\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\Program Files\AVG8~1\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [GoTrusted] C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel\GoTrusted Secure Tunnel.exe
O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Shortcut to sdefend.lnk = C:\Program Files\!AnalogX Script Defender\sdefend.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Alice\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://z6.invisionfree.com
O15 - Trusted Zone: http://www.programchecker.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187070775843
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E55FD215-A32E-43FE-A777-A7E8F165F551} (Flatcast Viewer 4.15) - http://www.flatcast.com/obj/NpFv415.dll
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (MINESWEEPER Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG 8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG8~1\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG8~1\avgwdsvc.exe
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrms\dvrmsfilewatcherservice.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\Sandra Lite SP1a\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\Sandra Lite SP1a\RpcSandraSrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 11538 bytes
You can't usually tel a Keylogger from HijackThis alone.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 124.225.65.173:80
- O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis and restart the computer to register the changes made by HijackThis.

----------

Download CCleaner Slim and save it to your Desktop.
When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.
Complete the installation then:

  • Double-click the CCleaner shortcut on the desktop to start the program.
  • Click on the Options block on the left, then choose Cookies.
    • Under Cookies to Delete, highlight any cookies you would like to retain permanently
    • Click the right arrow > to move them to the Cookies to Keep window.
  • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
  • Click Cleaner on the left then Run Cleaner on the right to run the program.
  • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
  • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
  • Exit CCleaner after it has completed its process.
.
----------

Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply
2106.

Solve : Cant download files, Lemmy, oduxftw.exe and more?

Answer»

After rebooting there is no more ie running in the background, or any other noticable problems, should I still FINISH these STEPS?Post a NEW HIJACKTHIS log please.

2107.

Solve : Don't know where to start:(?

Answer»

I was on here last week with a virus. I got that removed and everything worked fine for a few days. Now everything is so super slow on my computer. My internet TAKES forever to load a page and my programs won't respond or take forever to respond.

I wasn't sure which step to do first so for now I'll post my HJT Log. I'm running a Compaq 2.8GHz with 760 MB of Ram and Windows XP.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:30:40 PM, on 9/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
BOOT mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax6822.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

--
End of file - 7336 bytes
Does this sound like another virus or something else?

Thanks!Also I can't run my AVG antivirus. It won't open but I can't UNINSTALL or reinstall it b/c I keep getting an error message that says Action failed for registry key HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows

Error 0x80070005This is not a malware problem I am pretty sure.

Go here AVG Free Edition. Start the AVG download and you will be presented with the option to uninstall AVG instead of installing it.

Once you have it installed I would suggest switching to Avira. Some computers just don't get along with AVG and yours seems to be one of them. Avira AntiVir Personal

See if the problems clear up after that.

2108.

Solve : HiJack This log. Possible infection??

Answer»

Hey everyone.

I just wanted to know if there is anything on my HiJack This log , that need to be removed. Thanks for the help in advance. Here it is :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:12 AM, on 9/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla FIREFOX\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 84.232.40.162:11055
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft EXCEL - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/beta/SP.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187902286046
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 5709 bytes

- ZainLooks fine.

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety TESTS of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for TIPS and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

2109.

Solve : HELP!!! windows quick system eraser problem?

Answer»

hi,

i need help since my computer is having problem with some program that activates with any computer start.
it's called windows quick system eraser v.1 and it has following message "please wait till your system is complitely erased". there is an alarm sound activated too.

i got scared each time and i do switch of my notebook immediately. i have done a malwarebyte scan in a safe modus and this is the scan result. unfortunately the problem is still existing. i don't know what to do.
i receive also error messages. one of them is dwwin.exe and the rest i was not able to identify.

this is my first scan in safe modus before i have joined this forum. later i have done all the steps that were sujested and below you will find the attachments as well as the full hijackthis scan. there was only one thing that i was not able to do - to remove ask toolbar. it was probably removed by malwarebyte. i have deleted manually the folder asksbar in program folder.

i have belinea (maxdata) windows xp professional notebook.

Malwarebytes' Anti-Malware 1.28
Datenbank Version: 1134
Windows 5.1.2600 Service Pack 3

15.09.2008 19:49:41
mbam-log-2008-09-15 (19-49-41).txt

Scan-Methode: Vollständiger Scan (C:\|)
Durchsuchte Objekte: 151398
Laufzeit: 31 minute(s), 30 second(s)

Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 11
Infizierte Registrierungswerte: 2
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 6

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{f0d4b230-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23a-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23c-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b15fd82e-85bc-430d-90cb-65db1b030510} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.

Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)

Infizierte Dateien:
C:\Programme\AskSBar\bar\1.bin\A2HIGHIN.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\AskSBar\bar\1.bin\A2PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Programme\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Quarantined and deleted successfully.
C:\Programme\AskSBar\bar\1.bin\NPASKSBR.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\Mozilla Firefox\plugins\NPAskSBr.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Programme\Setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

HIJACKTHIS SCAN REPORT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:43:18, on 16.09.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
C:\Programme\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe
C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
C:\WINDOWS\boot32.exe
C:\Programme\BitDefender\BitDefender 2009\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe
C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
C:\Programme\Vidalia Bundle\Tor\tor.exe
C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\BitDefender\BitDefender 2009\seccenter.exe
C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Programme\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Keyboard Manager Utility] "C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe" /lang DE /H
O4 - HKLM\..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Boot32] C:\WINDOWS\boot32.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Programme\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Programme\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Vidalia] "C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Privoxy.lnk = C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: RESEARCH - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Programme\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162468014625
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Programme\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Programme\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 8121 bytes


[recovering disk space -- attachment deleted by admin]...............Disregard the previous post.
Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
- O4 - HKLM\..\Run: [Boot32] C:\WINDOWS\boot32.exe


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"Alcmtr"=-
"Boot32"=-
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to MERGE with the Registry.

Run CCleaner and restart the computer.

----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.oh thank you so much. i have a question. i have bitdefender antivirus and firewall. how do i disable this one?

and the same question is for malwarebyte and superantispyware.Just right click them in the system tray and choose to exit (or whatever term is used for them)ok here are the scans from comnofix

ComboFix 08-09-15.02 - Elvira 2008-09-16 2:40:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1031.18.1551 [GMT 2:00]
ausgeführt von:: C:\Dokumente und Einstellungen\Elvira\Desktop\ComboFix.exe
* Neuer Wiederherstellungspunkt wurde erstellt

Achtung - Auf diesem PC ist keine Wiederherstellungskonsole installiert !!
.

(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\Programme\autorun.inf
C:\system.exe

.
((((((((((((((((((((((( Dateien erstellt von 2008-08-16 bis 2008-09-16 ))))))))))))))))))))))))))))))
.

2008-09-16 00:36 . 2008-09-16 00:36d--------C:\Programme\Trend Micro
2008-09-16 00:29 . 2008-09-16 00:29d--------C:\Programme\Sun
2008-09-15 22:50 . 2008-09-16 02:35d--------C:\Programme\SUPERAntiSpyware
2008-09-15 22:50 . 2008-09-16 02:35d--------C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\SUPERAntiSpyware.com
2008-09-15 22:50 . 2008-09-15 22:50d--------C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SUPERAntiSpyware.com
2008-09-15 22:26 . 2008-09-15 22:26d--------C:\Programme\CCleaner
2008-09-15 19:14 . 2008-09-16 02:34d--------C:\Programme\Malwarebytes' Anti-Malware
2008-09-15 19:14 . 2008-09-15 19:14d--------C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\Malwarebytes
2008-09-15 19:14 . 2008-09-15 19:14d--------C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes
2008-09-14 13:54 . 2008-09-14 13:54850--a------C:\Windows\system32\ProductTweaks.xml
2008-09-14 13:54 . 2008-09-14 13:54385--a------C:\Windows\system32\user_gensett.xml
2008-09-14 13:21 . 2008-09-14 13:21d--------C:\Programme\MSXML 4.0
2008-09-14 02:54 . 2008-09-14 02:54d--------C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\Uniblue
2008-09-14 00:26 . 2008-09-14 00:26d--------C:\Windows\system32\logs
2008-09-14 00:26 . 2008-09-14 00:26d--------C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\BitDefender
2008-09-14 00:26 . 2008-09-14 00:26d--------C:\Binaries
2008-09-14 00:25 . 2008-09-14 00:26d--------C:\Programme\BitDefender
2008-09-14 00:25 . 2008-09-14 00:27d--------C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BitDefender
2008-09-14 00:24 . 2008-09-14 00:26d--------C:\Programme\Gemeinsame Dateien\BitDefender
2008-09-13 22:00 . 2008-09-13 22:00d--------C:\8bf8871132766c1e6f2dd340
2008-09-13 19:13 . 2008-08-29 10:32646,184--a------C:\autoruns.exe
2008-09-13 19:13 . 2008-08-29 10:32540,712--a------C:\autorunsc.exe
2008-09-13 18:43 . 2008-09-13 18:43d--------C:\Programme\Enigma Software Group
2008-09-12 22:34 . 2008-09-12 22:3416,384--a------C:\Windows\~DFA40B.tmp
2008-09-12 22:23 . 2008-09-12 22:23d--------C:\Programme\Autodesk
2008-09-12 16:41 . 2008-09-07 02:2128,672--a------C:\Windows\boot32.exe
2008-09-12 16:37 . 2008-09-13 19:06d-a------C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP
2008-09-12 16:37 . 2008-09-12 16:370--a------C:\Windows\system32\MSWINSCK.OCX
2008-09-06 21:44 . 2004-03-29 17:2390,112--a------C:\Windows\unvise32.exe
2008-09-05 10:27 . 2008-09-06 11:45d--------C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\FrostWire
2008-09-05 10:26 . 2008-09-05 10:27d--------C:\Programme\FrostWire
2008-09-05 01:07 . 2008-09-06 21:55d--------C:\Programme\Gemeinsame Dateien\DAZ
2008-09-03 17:15 . 2008-09-03 17:27d--------C:\Programme\Photoshop
2008-08-26 12:27 . 2008-05-01 16:34331,776---------C:\Windows\system32\dllcache\msadce.dll
2008-08-26 12:26 . 2008-04-11 21:04691,712---------C:\Windows\system32\dllcache\inetcomm.dll

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 00:23---------d-----wC:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\tor
2008-09-15 22:30---------d-----wC:\Programme\Java
2008-09-15 12:25---------d-----wC:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\Vidalia
2008-09-13 19:57---------d-----wC:\Programme\Panda Security
2008-09-13 19:57---------d-----wC:\Programme\Gemeinsame Dateien\Panda Software
2008-09-12 20:22---------d-----wC:\Programme\Gemeinsame Dateien\InstallShield
2008-09-10 18:01---------d-----wC:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help
2008-09-04 23:36---------d-----wC:\Programme\LimeWire
2008-09-04 09:09---------d-----wC:\Programme\Gemeinsame Dateien\Adobe
2008-09-02 15:14---------d-----wC:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\LimeWire
2008-08-28 22:17---------d-----wC:\Programme\Windows Live Safety Center
2008-08-22 08:18---------d-----wC:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\dvdcss
2008-08-14 16:54102,208----a-wC:\WINDOWS\system32\drivers\bdfndisf.sys
2008-08-12 16:40228,672----a-wC:\WINDOWS\system32\drivers\bdfsfltr.sys
2008-08-12 16:40108,864----a-wC:\WINDOWS\system32\drivers\bdfm.sys
2008-08-08 16:39---------d-----wC:\Programme\Vidalia Bundle
2008-08-08 12:517,333,664----a-wC:\Programme\Firefox Setup 3.0.1.exe
2008-08-01 23:06---------d-----wC:\Programme\PhotoScape
2008-07-31 20:48---------d-----wC:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\MSNInstaller
2008-07-20 16:56---------d-----wC:\Programme\Tor Browser
2008-07-18 20:1094,920----a-wC:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:1094,920----a-wC:\WINDOWS\system32\cdm.dll
2008-07-18 20:1053,448----a-wC:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:1053,448----a-wC:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:1045,768----a-wC:\WINDOWS\system32\wups2.dll
2008-07-18 20:1036,552----a-wC:\WINDOWS\system32\wups.dll
2008-07-18 20:1036,552----a-wC:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09563,912----a-wC:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09563,912----a-wC:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09325,832----a-wC:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09325,832----a-wC:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09205,000----a-wC:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09205,000----a-wC:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:091,811,656----a-wC:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:091,811,656----a-wC:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07270,880----a-wC:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07210,976----a-wC:\WINDOWS\system32\muweb.dll
2008-07-07 20:26253,952----a-wC:\WINDOWS\system32\es.dll
2008-07-07 20:26253,952------wC:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:4274,240----a-wC:\WINDOWS\system32\mscms.dll
2008-06-24 16:4274,240------wC:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 08:143,592,192------wC:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:2070,656------wC:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20625,664------wC:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:2013,824------wC:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23161,792------wC:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46247,296----a-wC:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46247,296------wC:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46147,968------wC:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51361,600------wC:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40138,496------wC:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08225,856------wC:\WINDOWS\system32\dllcache\tcpip6.sys
2003-04-22 09:462,719,744------wC:\Programme\aiodrv.msi
2003-04-22 09:422,588,672------wC:\Programme\aiosw.msi
2003-04-22 09:23267----a-wC:\Programme\readme.html
2003-04-09 17:192,848----a-wC:\Programme\hpound08.inf
2003-04-09 17:1914,157----a-wC:\Programme\hpousc08.inf
2003-04-09 17:004,715----a-wC:\Programme\hpoglu08.inf
2003-04-09 17:002,889----a-wC:\Programme\hpousb08.inf
2003-03-20 15:2024,728----a-wC:\Programme\HPZipr12.cat
2003-03-20 15:2024,285----a-wC:\Programme\hposcu08.cat
2003-03-20 15:2022,523----a-wC:\Programme\HPZius12.cat
2003-03-20 15:2022,082----a-wC:\Programme\hpzist12.cat
2003-03-20 15:2022,082----a-wC:\Programme\HPZid412.cat
2003-03-20 15:2021,641----a-wC:\Programme\HPOunp08.cat
2003-03-20 15:20205,503----a-wC:\Programme\hpoprn08.cat
2003-03-09 20:3063,562----a-wC:\Programme\hposcu08.inf
2003-03-09 20:3051,266----a-wC:\Programme\hpoprn08.inf
2003-03-09 20:3033,952----a-wC:\Programme\hpzid412.inf
2003-03-09 20:303,898----a-wC:\Programme\hpounp08.inf
2003-03-09 20:303,667----a-wC:\Programme\hpzist12.inf
2003-03-09 20:30274,432----a-wC:\Programme\hpzglu07.exe
2003-03-09 20:30237,568----a-wC:\Programme\hpzc3212.dll
2003-03-09 20:3023,186----a-wC:\Programme\hpzcin06.ex_
2003-03-09 20:30184,320----a-wC:\Programme\hpzscr07.dll
2003-03-09 20:3016,352----a-wC:\Programme\HPZUCI12.DLL
2003-03-09 20:3014,285----a-wC:\Programme\hpzius12.inf
2003-03-09 20:3010,325----a-wC:\Programme\hpzipr12.inf
2002-09-09 17:48458,752----a-wC:\Programme\tls704d.dll
2002-09-09 17:4822,608----a-wC:\Programme\usbprint.sys
2002-09-09 17:4812,288----a-wC:\Programme\usbmon.dll
2002-09-09 17:4770,656----a-wC:\Programme\msvcirt.dll
2002-09-09 17:4755,155----a-wC:\Programme\hpzusb00.sy_
2002-09-09 17:475,705----a-wC:\Programme\hpzuci02.dl_
2002-09-09 17:47254,005----a-wC:\Programme\msvcrt.dll
2002-09-09 17:4725,639----a-wC:\Programme\hpzpom04.dl_
2002-09-09 17:47212,992----a-wC:\Programme\hpzpnp07.dll
2002-09-09 17:4652,552----a-wC:\Programme\hpziou01.dl_
2002-09-09 17:4649,212----a-wC:\Programme\hpzjvp01.dll
2002-09-09 17:4646,017----a-wC:\Programme\hpzion00.sy_
2002-09-09 17:46417,849----a-wC:\Programme\hpzjpp01.dll
2002-09-09 17:4628,722----a-wC:\Programme\hpzjlog.dll
2002-09-09 17:46249,913----a-wC:\Programme\hpzjut01.dll
2002-09-06 09:54995,383----a-wC:\Programme\MFC42.DLL
2003-01-13 09:59278,528------wC:\Programme\internet explorer\plugins\PanoViewer.dll
1999-04-30 15:0098,304------wC:\Programme\internet explorer\plugins\UPjpeg.dll
2008-05-09 19:3032,768--sha-wC:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008050920080510\index.dat
.

(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Vidalia"="C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe" [2008-08-03 3945620]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-22 8433664]
"Adobe Reader Speed Launcher"="C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IAAnotif"="C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"SynTPEnh"="C:\Programme\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
"Keyboard Manager Utility"="C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe" [2007-08-02 4128768]
"SMSERIAL"="C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"RemoteControl"="C:\Programme\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Ulead AutoDetector v2"="C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe" [2005-05-23 90112]
"BDAgent"="C:\Programme\BitDefender\BitDefender 2009\bdagent.exe" [2008-09-15 716800]
"BitDefender Antiphishing Helper"="C:\Programme\BitDefender\BitDefender 2009\IEShow.exe" [2008-08-10 69632]
"SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"nwiz"="nwiz.exe" [2007-05-22 C:\Windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 C:\Windows\RTHDCPL.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

C:\Dokumente und Einstellungen\All Users\Startmen�\Programme\Autostart\
hpoddt01.exe.lnk - C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-09 28672]
Privoxy.lnk - C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 250368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"SweetIM"=C:\Programme\Macrogaming\SweetIM\SweetIM.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programme\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programme\\Messenger\\msmsgs.exe"=
"C:\\Programme\\MSN Messenger\\msnmsgr.exe"=
"C:\\Programme\\MSN Messenger\\livecall.exe"=
"C:\\Programme\\LimeWire\\LimeWire.exe"=
"C:\\Programme\\FrostWire\\FrostWire.exe"=

R2 BDVEDISK;BDVEDISK;C:\Programme\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-07-02 82568]
R3 bdfm;BDFM;C:\WINDOWS\system32\drivers\bdfm.sys [2008-08-12 108864]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-08-14 102208]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2006-09-19 36608]
R3 qkbfiltr;Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\qkbfiltr.sys [2007-02-01 33792]
S3 Arrakis3;BitDefender Arrakis Server;C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdxREG_MULTI_SZ scan

*Newly Created Service* - PROCEXP90
.
Inhalt des "geplante Tasks" Ordners
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -

HKLM-RunOnce- - (no file)
Notify-avldr - (no file)


.
------- Zusätzlicher Scan -------
.
FireFox -: Profile - C:\Dokumente und Einstellungen\Elvira\Anwendungsdaten\Mozilla\Firefox\Profiles\8ysqmy3s.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
FF -: plugin - C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-16 02:43:33
Windows 5.1.2600 Service Pack 3 NTFS

Scanne versteckte Prozesse...

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------

Prozess: C:\WINDOWS\SYSTEM32\winlogon.exe
-> C:\Programme\SUPERAntiSpyware\SASWINLO.dll
.
Zeit der Fertigstellung: 2008-09-16 2:44:23
ComboFix-quarantined-files.txt 2008-09-16 00:44:18

Pre-Run: 10 Verzeichnis(se), 127,487,578,112 Bytes frei
Post-Run: 14 Verzeichnis(se), 127,497,596,928 Bytes frei

233--- E O F ---2008-09-14 11:21:58

and hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:47:34, on 16.09.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
C:\Programme\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe
C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
C:\Programme\BitDefender\BitDefender 2009\bdagent.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe
C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
C:\Programme\Vidalia Bundle\Tor\tor.exe
C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\BitDefender\BitDefender 2009\seccenter.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Programme\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Programme\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Keyboard Manager Utility] "C:\Programme\Keyboard Manager\Manager Utility\KeyboardManager.exe" /lang DE /H
O4 - HKLM\..\Run: [SMSERIAL] C:\Programme\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Programme\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Programme\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Vidalia] "C:\Programme\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Privoxy.lnk = C:\Programme\Vidalia Bundle\Privoxy\privoxy.exe
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .UVR: C:\Programme\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162468014625
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Programme\Gemeinsame Dateien\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Programme\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 7346 bytes
Download OTMoveIt2 by OldTimerand save it to your Desktop.

Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

1. Double-click OTMoveIt2.exe to run it.
2. Copy the lines in the codebox below.

Code: [Select][kill explorer]
C:\Windows\~DFA40B.tmp
C:\Windows\boot32.exe
EmptyTemp
[start explorer]
3. Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
4. Click the red Moveit! button.
5. Copy everything in the Results window (under the green bar) and paste it in your next reply.
6. Close OTMoveIt2

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.i was immediatelly asked to reboot my computer and this message was shown after the restart.

Explorer killed successfully
C:\Windows\~DFA40B.tmp moved successfully.
C:\Windows\boot32.exe moved successfully.
< EmptyTemp >
File delete failed. C:\DOKUME~1\Elvira\LOKALE~1\Temp\etilqs_UNTI0OwsDWD7ZCAbNDQm scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\tmp00000f88\tmp00000000 scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09162008_031212

Files moved on Reboot...
File C:\DOKUME~1\Elvira\LOKALE~1\Temp\etilqs_UNTI0OwsDWD7ZCAbNDQm not found!
File C:\WINDOWS\temp\tmp00000f88\tmp00000000 not found!

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.

  • The above PROCEDURE will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • Reset the clock SETTINGS.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

How is everything now?combofix is uninstalled now. let me shut down my computer and start new. i'll reply you soon.i think that the problem with windows quick system eraser is solved now. it doesn't appear when i start the computer. i have checked this two times with shut down and once with restart.

the only problem is that each time i woudl shut down the computer i receive an error message about dwwin.exe.Thats the Dr. Watson for Windows (Drwtsn32.exe) Tool - See here for more information http://support.microsoft.com/kb/308538

You might try seeing if something is needing to be updated.

Use the Secunia Software Inspector

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
i have done the update also with windows update. from the info on the net dwwin.exe isn't a wild problem.

the main problem is fixed. i can't thank you enough, i owe you so much!

big cyber hug!!!!
2110.

Solve : What is the latest link to a Symantec removal tool??

Answer»

Running two antivirus programs is a distinct system problem. Can you give me the best (LATEST) link to access the Symantec Antivrus program removal tool. We will write BACK and confirm a problem has been fixed. One firewall and only one A/V program.

Thanks tom.Here.

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please CLOSE ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will START running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
It didn't work. I followed your INSTRUCTIONS and this is what happened.

It did download to my desktop. I accepted the license. I typed in the ltrs and #'s. This is the response:

SymNRT: Invalid signature - this file is not signed so it won't run.
http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
2111.

Solve : Re: Virus Alert Clock, No C: or D:, selective internet activity, no control panel.?

Answer»

Can you CHECKOUT my LOGS and tell me ANYTHING else i have to do please, Ive REMOVED all the problems but i am still left with the redirecting of LINKS ?
What should i do ?

Thanx for all your help.

[Saving space - attachment deleted by admin]

2112.

Solve : viewpoint media player?

Answer»

jusy saw that my brand new hp laptop has viewpoint media player should i uninstall this?Not NECESSARY, and if the laptop is new, you don't need the extra HDD space.Viewpoint is adware, I would REMOVE it if I were you.Adware?

Sorry, I didn't realise it is. Foistware... http://en.wikipedia.org/wiki/Foistware

Viewpoint Media Player/Manager/Toolbar is considered as foistware INSTEAD of MALWARE since it is installed without users approval but doesn't spy or do anything "bad".

More information:

2113.

Solve : GoogleUpdate.exe?

Answer»

Evilfantasy, Unfortunately I cannot get rid of GoogleUpdate.exe.

Even if I remove it from my startup items, it still comes up.

Here is the LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:49:20 PM, on 20-Sep-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\PROGRA~1\Lenovo\LENOVO~1\LPMGR.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Mousotron\Mousotron.exe
C:\Program Files\NetMeter\NetMeter.exe
C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\trayit_4_6_5_5\TrayIt!.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\user\My Documents\Applications\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll
O4 - HKLM\..\RUN: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~1\LPMGR.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
O4 - HKCU\..\Run: [Mousotron] C:\Program Files\Mousotron\Mousotron.exe
O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: TrayIt!.lnk = C:\Program Files\trayit_4_6_5_5\TrayIt!.exe
O8 - Extra context menu ITEM: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: SUN Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 5036 bytes
Download OTMoveIt2 by OldTimerand save it to your Desktop.

Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

1. Double-click OTMoveIt2.exe to run it.
2. Copy the lines in the quotebox below.

Quote

[kill explorer]
C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[start explorer]

3. Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
4. Click the red Moveit! button.
5. Copy everything in the Results window (under the green bar) and paste it in your next reply.
6. Close OTMoveIt2

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

----------

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"Google Update"=-
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.


Interesting experience, I have to say.


Explorer killed successfully
C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe moved successfully.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09212008_004132OTMoveIt2 is a powerful little tool. It will move registry keys and even entire folders. Nice tool but to be USED with caution.

If you want to get rid of it and it's backups just open it and click CleanUp. It is self destructing...Haha, a self destruct? Nice. So is the GoogleUpdate.exe gone?Yep!

Thanks.w00t

2114.

Solve : Please help, I use my comp at work and hit by Antivirus 2008, all logs included?

Answer»

I have it too. I have already run through the entire "start here" post. I have attached the logs below.
I do use my computer for work, but i own it. There are some programs I need for work, specifically the VNC server, and Trend Micro Security Agent. I am very familiar with COMPUTERS and the Windows platform, though "Expert" may be a little over rated, I definitely fall closer to Expert than Familiar on your scale.
Here are the issues, as noted per item, some were resolved by the "start here" procedures which I have already run ALL of.
1. Started with a popup screen that said I needed to install "Antivirus 2008" etc. (remedied by the "start here" steps)
2. Desktop was changed to a blue boundary, with a centered image stating that I needed to install an antivirus software, and that two viruses or spy ware items were found. ALSO, upon attempting to change my desktop back, the tab in the properties for the desktop was not there. (remedied by the "start here" steps)
3. On opening: IE the home page was set to blank, and upon typing in a URL would report either no connection or website is busy. (has improved after running through "start here" steps, see next item)
4. Within Firefox: any anti virus website (any other websites connect just fine) that I tried to connect to (via typing in the URL or via links on a search engine) will redirect to any number of other pages, INCLUDING search engines or ads. The same links or URLs do not connect to the same redirected site each time they are clicked or typed in. After running all of the "start here" steps IE is now doing the same thing as Firefox.
I did have to run the SAS 2x's as my comp kept crashing in the middle, so there are two logs.
Here are the logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/21/2008 at 10:55 AM

Application Version : 4.21.1004

Core Rules Database Version : 3575
Trace Rules Database Version: 1563

Scan type : Complete Scan
Total Scan Time : 00:30:50

Memory items scanned : 435
Memory threats detected : 1
Registry items scanned : 7581
Registry threats detected : 1
File items scanned : 29997
File threats detected : 39

Trojan.Dropper/SVCHost-Fake
C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE
[SVCHOST.EXE] C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE

Adware.Tracking Cookie
C:\Documents and Settings\Julie\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Julie\Cookies\[emailprotected][1].txt
.overture.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
cache.trafficmp.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
.dynamic.media.adrevolver.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\cookies.txt ]

Rogue.AntiVirus 2008
C:\WINDOWS\SYSTEM32\PHCVHSJ0ERTQ.BMP
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/21/2008 at 12:31 PM

Application Version : 4.21.1004

Core Rules Database Version : 3575
Trace Rules Database Version: 1563

Scan type : Complete Scan
Total Scan Time : 01:08:47

Memory items scanned : 428
Memory threats detected : 0
Registry items scanned : 7557
Registry threats detected : 0
File items scanned : 124622
File threats detected : 1

NotHarmful.Sysinternals Bluescreen Screen Saver
C:\WINDOWS\SYSTEM32\BLPHCVHSJ0ERTQ.SCR
Malwarebytes' Anti-Malware 1.28
Database version: 1188
Windows 5.1.2600 Service Pack 3

9/21/2008 1:04:30 PM
mbam-log-2008-09-21 (13-04-30).txt

Scan type: Quick Scan
Objects scanned: 51133
Time elapsed: 2 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\inrhcrhsj0ertq (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcvhsj0ertq (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssl.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent) -> Delete on reboot.

Remaining log in following post, due to space constraints.Here is the remaining log file, thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:30:22 PM, on 9/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\TEMP\VVEDB5.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=presario&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=presario&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=presario&pf=laptop
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/WinNTChk.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/setup.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/RemoveCtrl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://download.playfirst.com/play/game/petshophop/petshophopweb.1.0.0.15.cab
O16 - DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} (CPlayFirstDreamChronControl Object) - http://download.playfirst.com/play/game/dreamchronicles2/dream2web.1.0.0.13.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 10949 bytes

I would appreciate any help you can offer,
Thanks,
JulieHello Julienoel.

If you are still needing help please run a new HijackThis scan and post the log.

Thanks.Here is today's log file, yes i still need some assistance. I still cannot access any antivirus related web sites. the other issues have been resolved with the 5 steps, but this redirection thing is still hanging on.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:04 PM, on 9/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\TEMP\DX3B36.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=presario&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=presario&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=presario&pf=laptop
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/WinNTChk.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/setupini.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/setup.cab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) - https://triad.local.triadfs.org:4343/officescan/console/ClientInstall/RemoveCtrl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {C0C0CB9B-BFEB-47C2-90FA-BE9692875ADB} (CPlayFirstPetShopHopControl Object) - http://download.playfirst.com/play/game/petshophop/petshophopweb.1.0.0.15.cab
O16 - DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} (CPlayFirstDreamChronControl Object) - http://download.playfirst.com/play/game/dreamchronicles2/dream2web.1.0.0.13.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 10804 bytes
Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. http://rapidshare.com/files/147594550/ComboFix.exe.html

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.OK, here is the combo fix log, thanks for you response. I can open mcafee now! ANYTHING else i should do?

ComboFix 08-09-20.05 - Julie 2008-09-22 20:22:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.603 [GMT -7:00]
Running from: C:\Documents and Settings\Julie\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Julie\Application Data\inst.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\windows_update.exe
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-08-23 to 2008-09-23 )))))))))))))))))))))))))))))))
.

2008-09-21 20:45 . 2006-01-23 16:29106,496--a------C:\WINDOWS\system32\ssPlantasia.scr
2008-09-21 13:05 . 2008-09-21 13:0561,440--a------C:\WINDOWS\system32\drivers\islsep.sys
2008-09-21 12:49 . 2008-09-21 12:49d--------C:\Documents and Settings\Julie\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-21 12:50d--------C:\Program Files\Malwarebytes' Anti-Malware
2008-09-21 12:48 . 2008-09-21 12:48d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-10 00:0438,528--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-21 12:48 . 2008-09-10 00:0317,200--a------C:\WINDOWS\system32\drivers\mbam.sys
2008-09-20 23:30 . 2005-11-03 00:29163,840--a------C:\tmdbg20.dll
2008-09-20 23:30 . 2005-11-03 00:30127,049--a------C:\LogServer.exe
2008-09-20 22:52 . 2008-09-20 22:52d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\SUPERAntiSpyware
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\Common Files\Wise Installation Wizard
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Documents and Settings\Julie\Application Data\SUPERAntiSpyware.com
2008-09-20 22:50 . 2008-09-20 22:5049--a------C:\OfcDebug.ini
2008-09-20 21:41 . 2008-09-20 23:29d--------C:\WINDOWS\SxsCaPendDel
2008-09-20 21:08 . 2008-09-21 11:21d--------C:\Program Files\Enigma Software Group
2008-09-20 19:50 . 2008-09-20 19:50d--------C:\Program Files\CCleaner
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\scripting
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\en
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\bits
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\l2schemas
2008-09-03 08:58 . 2008-09-03 08:58d--------C:\WINDOWS\ServicePackFiles
2008-09-02 09:18 . 2008-09-02 09:18d--------C:\WINDOWS\Twain32
2008-09-01 19:33 . 2008-09-17 22:32d--------C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
2008-09-01 13:55 . 2008-09-01 17:22d--------C:\Program Files\Plantasia_at
2008-09-01 00:23 . 2008-09-01 00:23d--------C:\Program Files\ReflexiveArcade
2008-08-31 23:17 . 2008-09-19 21:46d-a------C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-26 12:30 . 2008-08-26 14:54d--------C:\Program Files\MSECache
2008-08-25 00:40 . 2008-08-25 00:40268--ah-----C:\sqmdata13.sqm
2008-08-25 00:40 . 2008-08-25 00:40244--ah-----C:\sqmnoopt13.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 20:27---------d-----wC:\Program Files\Trend Micro
2008-09-21 20:23---------d-----wC:\Program Files\Java
2008-09-21 04:42---------d-----wC:\Program Files\WildTangent
2008-09-20 15:21---------d--h--wC:\Program Files\InstallShield Installation Information
2008-09-20 15:21---------d-----wC:\Program Files\NetWaiting
2008-09-20 07:37---------d-----wC:\Program Files\Yahoo! Games
2008-09-20 07:37---------d-----wC:\Program Files\Buildcity
2008-09-19 05:27---------d-----wC:\Documents and Settings\All Users\Application Data\HipSoft
2008-09-13 03:12---------d--h--wC:\Documents and Settings\Julie\Application Data\Move Networks
2008-09-12 04:01---------d-----wC:\Documents and Settings\Julie\Application Data\PlayFirst
2008-09-11 06:11---------d-----wC:\Program Files\PlayFirst
2008-09-05 04:21---------d-----wC:\Documents and Settings\Julie\Application Data\Mind Control Software
2008-09-03 18:15---------d-----wC:\Program Files\MSN Messenger
2008-09-02 00:230----a-wC:\Program Files\temp01
2008-07-19 05:1094,920----a-wC:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 05:1094,920----a-wC:\WINDOWS\system32\cdm.dll
2008-07-19 05:1053,448----a-wC:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:1053,448----a-wC:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 05:1045,768----a-wC:\WINDOWS\system32\wups2.dll
2008-07-19 05:1036,552----a-wC:\WINDOWS\system32\wups.dll
2008-07-19 05:1036,552----a-wC:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 05:09563,912----a-wC:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09563,912----a-wC:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 05:09325,832----a-wC:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09325,832----a-wC:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 05:09205,000----a-wC:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09205,000----a-wC:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 05:091,811,656----a-wC:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:091,811,656----a-wC:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:26253,952----a-wC:\WINDOWS\system32\es.dll
2008-07-07 20:26253,952------wC:\WINDOWS\system32\dllcache\es.dll
2008-06-25 01:12295,936------wC:\WINDOWS\system32\wmpeffects.dll
2008-06-24 17:573,592,192----a-wC:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-24 16:4374,240----a-wC:\WINDOWS\system32\mscms.dll
2008-06-24 16:4374,240------wC:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 09:2070,656------wC:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20625,664------wC:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:2013,824------wC:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-18 17:19774,144----a-wC:\Program Files\RngInterstitial.dll
2007-07-21 05:5547,360----a-wC:\Documents and Settings\Julie\Application Data\pcouffin.sys
2007-03-06 23:240----a-wC:\Documents and Settings\Julie\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2008-04-13 143360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" [2005-11-03 372813]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 77824]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 149024]
"MsmqIntCert"="mqrt.dll" [2008-04-13 C:\WINDOWS\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP40"= SP40_32.DLL
"VIDC.SP41"= SP4X_32.DLL
"VIDC.SP42"= SP4X_32.DLL
"VIDC.SP43"= SP4X_32.DLL
"VIDC.SP44"= SP4X_32.DLL
"VIDC.SP45"= SP4X_32.DLL
"VIDC.SP46"= SP4X_32.DLL
"VIDC.SP47"= SP4X_32.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

S3 ACRUSBTM;ACRUSBTM;C:\WINDOWS\system32\drivers\ACRUSBTM.SYS [2007-08-02 28672]
S3 AVC1100;Adaptec AVC-1100 Video Capture;C:\WINDOWS\system32\DRIVERS\CA506AV.SYS [2002-07-21 175042]
S3 ca506aaf;Adaptec USB Audio Filter Driver (WDM);C:\WINDOWS\system32\drivers\ca506aaf.sys [2002-07-21 14273]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Julie\Application Data\Mozilla\Firefox\Profiles\lcymk3vp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://my.yahoo.com/
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-22 20:26:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe?[emailprotected]? ?^???`[emailprotected]?[emailprotected]

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]
"imagepath"="\systemroot\system32\drivers\TDSSserv.sys"
.
Completion time: 2008-09-22 20:28:14
ComboFix-quarantined-files.txt 2008-09-23 03:28:10

Pre-Run: 13,698,949,120 bytes free
Post-Run: 13,755,367,424 bytes free

205--- E O F ---2008-09-11 06:49:48
Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
C:\WINDOWS\system32\drivers\islsep.sys
C:\sqmdata13.sqm
C:\sqmnoopt13.sqm

Registry::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]
"imagepath"=-
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeok, here is the latest log file from combofix. Anything else?

ComboFix 08-09-20.05 - Julie 2008-09-22 20:45:35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.630 [GMT -7:00]
Running from: C:\Documents and Settings\Julie\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Julie\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\sqmdata13.sqm
C:\sqmnoopt13.sqm
C:\WINDOWS\system32\drivers\islsep.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\sqmdata13.sqm
C:\sqmnoopt13.sqm
C:\WINDOWS\system32\drivers\islsep.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2008-08-23 to 2008-09-23 )))))))))))))))))))))))))))))))
.

2008-09-21 20:45 . 2006-01-23 16:29106,496--a------C:\WINDOWS\system32\ssPlantasia.scr
2008-09-21 12:49 . 2008-09-21 12:49d--------C:\Documents and Settings\Julie\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-21 12:50d--------C:\Program Files\Malwarebytes' Anti-Malware
2008-09-21 12:48 . 2008-09-21 12:48d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-10 00:0438,528--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-21 12:48 . 2008-09-10 00:0317,200--a------C:\WINDOWS\system32\drivers\mbam.sys
2008-09-20 23:30 . 2005-11-03 00:29163,840--a------C:\tmdbg20.dll
2008-09-20 23:30 . 2005-11-03 00:30127,049--a------C:\LogServer.exe
2008-09-20 22:52 . 2008-09-20 22:52d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\SUPERAntiSpyware
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\Common Files\Wise Installation Wizard
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Documents and Settings\Julie\Application Data\SUPERAntiSpyware.com
2008-09-20 22:50 . 2008-09-20 22:5049--a------C:\OfcDebug.ini
2008-09-20 21:41 . 2008-09-20 23:29d--------C:\WINDOWS\SxsCaPendDel
2008-09-20 21:08 . 2008-09-21 11:21d--------C:\Program Files\Enigma Software Group
2008-09-20 19:50 . 2008-09-20 19:50d--------C:\Program Files\CCleaner
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\scripting
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\en
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\bits
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\l2schemas
2008-09-03 08:58 . 2008-09-03 08:58d--------C:\WINDOWS\ServicePackFiles
2008-09-02 09:18 . 2008-09-02 09:18d--------C:\WINDOWS\Twain32
2008-09-01 19:33 . 2008-09-17 22:32d--------C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
2008-09-01 13:55 . 2008-09-01 17:22d--------C:\Program Files\Plantasia_at
2008-09-01 00:23 . 2008-09-01 00:23d--------C:\Program Files\ReflexiveArcade
2008-08-31 23:17 . 2008-09-19 21:46d-a------C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-26 12:30 . 2008-08-26 14:54d--------C:\Program Files\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 20:27---------d-----wC:\Program Files\Trend Micro
2008-09-21 20:23---------d-----wC:\Program Files\Java
2008-09-21 04:42---------d-----wC:\Program Files\WildTangent
2008-09-20 15:21---------d--h--wC:\Program Files\InstallShield Installation Information
2008-09-20 15:21---------d-----wC:\Program Files\NetWaiting
2008-09-20 07:37---------d-----wC:\Program Files\Yahoo! Games
2008-09-20 07:37---------d-----wC:\Program Files\Buildcity
2008-09-19 05:27---------d-----wC:\Documents and Settings\All Users\Application Data\HipSoft
2008-09-13 03:12---------d--h--wC:\Documents and Settings\Julie\Application Data\Move Networks
2008-09-12 04:01---------d-----wC:\Documents and Settings\Julie\Application Data\PlayFirst
2008-09-11 06:11---------d-----wC:\Program Files\PlayFirst
2008-09-05 04:21---------d-----wC:\Documents and Settings\Julie\Application Data\Mind Control Software
2008-09-03 18:15---------d-----wC:\Program Files\MSN Messenger
2008-09-02 00:230----a-wC:\Program Files\temp01
2007-10-18 17:19774,144----a-wC:\Program Files\RngInterstitial.dll
2007-07-21 05:5547,360----a-wC:\Documents and Settings\Julie\Application Data\pcouffin.sys
2007-03-06 23:240----a-wC:\Documents and Settings\Julie\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( [emailprotected]_20.27.46.91 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 03:02:28163,328----a-wC:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-11-03 07:30:32172,099----a-wC:\WINDOWS\temp\RV2FF6.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2008-04-13 143360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" [2005-11-03 372813]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 77824]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 149024]
"MsmqIntCert"="mqrt.dll" [2008-04-13 C:\WINDOWS\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP40"= SP40_32.DLL
"VIDC.SP41"= SP4X_32.DLL
"VIDC.SP42"= SP4X_32.DLL
"VIDC.SP43"= SP4X_32.DLL
"VIDC.SP44"= SP4X_32.DLL
"VIDC.SP45"= SP4X_32.DLL
"VIDC.SP46"= SP4X_32.DLL
"VIDC.SP47"= SP4X_32.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

S3 ACRUSBTM;ACRUSBTM;C:\WINDOWS\system32\drivers\ACRUSBTM.SYS [2007-08-02 28672]
S3 AVC1100;Adaptec AVC-1100 Video Capture;C:\WINDOWS\system32\DRIVERS\CA506AV.SYS [2002-07-21 175042]
S3 ca506aaf;Adaptec USB Audio Filter Driver (WDM);C:\WINDOWS\system32\drivers\ca506aaf.sys [2002-07-21 14273]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-22 20:49:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe?[emailprotected]? ?^???`[emailprotected]?[emailprotected]

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\NTRtScan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\Client Server Security Agent\TmListen.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\temp\RV2FF6.EXE
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-22 20:55:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-23 03:55:19
ComboFix2.txt 2008-09-23 03:28:15

Pre-Run: 13,733,888,000 bytes free
Post-Run: 13,638,041,600 bytes free

203--- E O F ---2008-09-11 06:49:48
Chipping away.....

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
TDSSserv
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
  • Delete Nortonremoval tool from your Desktop.
Here's the latest. this sure beats editing registries by hand, thats how i got rid of the last one, or tried to.

ComboFix 08-09-20.05 - Julie 2008-09-22 21:09:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.636 [GMT -7:00]
Running from: C:\Documents and Settings\Julie\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Julie\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-08-23 to 2008-09-23 )))))))))))))))))))))))))))))))
.

2008-09-21 20:45 . 2006-01-23 16:29106,496--a------C:\WINDOWS\system32\ssPlantasia.scr
2008-09-21 12:49 . 2008-09-21 12:49d--------C:\Documents and Settings\Julie\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-21 12:50d--------C:\Program Files\Malwarebytes' Anti-Malware
2008-09-21 12:48 . 2008-09-21 12:48d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-21 12:48 . 2008-09-10 00:0438,528--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-21 12:48 . 2008-09-10 00:0317,200--a------C:\WINDOWS\system32\drivers\mbam.sys
2008-09-20 23:30 . 2005-11-03 00:29163,840--a------C:\tmdbg20.dll
2008-09-20 23:30 . 2005-11-03 00:30127,049--a------C:\LogServer.exe
2008-09-20 22:52 . 2008-09-20 22:52d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\SUPERAntiSpyware
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Program Files\Common Files\Wise Installation Wizard
2008-09-20 22:51 . 2008-09-20 22:51d--------C:\Documents and Settings\Julie\Application Data\SUPERAntiSpyware.com
2008-09-20 22:50 . 2008-09-20 22:5049--a------C:\OfcDebug.ini
2008-09-20 21:41 . 2008-09-20 23:29d--------C:\WINDOWS\SxsCaPendDel
2008-09-20 21:08 . 2008-09-21 11:21d--------C:\Program Files\Enigma Software Group
2008-09-20 19:50 . 2008-09-20 19:50d--------C:\Program Files\CCleaner
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\scripting
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\en
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\system32\bits
2008-09-03 09:02 . 2008-09-03 09:02d--------C:\WINDOWS\l2schemas
2008-09-03 08:58 . 2008-09-03 08:58d--------C:\WINDOWS\ServicePackFiles
2008-09-02 09:18 . 2008-09-02 09:18d--------C:\WINDOWS\Twain32
2008-09-01 19:33 . 2008-09-17 22:32d--------C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
2008-09-01 13:55 . 2008-09-01 17:22d--------C:\Program Files\Plantasia_at
2008-09-01 00:23 . 2008-09-01 00:23d--------C:\Program Files\ReflexiveArcade
2008-08-31 23:17 . 2008-09-19 21:46d-a------C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-26 12:30 . 2008-08-26 14:54d--------C:\Program Files\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 20:27---------d-----wC:\Program Files\Trend Micro
2008-09-21 20:23---------d-----wC:\Program Files\Java
2008-09-21 04:42---------d-----wC:\Program Files\WildTangent
2008-09-20 15:21---------d--h--wC:\Program Files\InstallShield Installation Information
2008-09-20 15:21---------d-----wC:\Program Files\NetWaiting
2008-09-20 07:37---------d-----wC:\Program Files\Yahoo! Games
2008-09-20 07:37---------d-----wC:\Program Files\Buildcity
2008-09-19 05:27---------d-----wC:\Documents and Settings\All Users\Application Data\HipSoft
2008-09-13 03:12---------d--h--wC:\Documents and Settings\Julie\Application Data\Move Networks
2008-09-12 04:01---------d-----wC:\Documents and Settings\Julie\Application Data\PlayFirst
2008-09-11 06:11---------d-----wC:\Program Files\PlayFirst
2008-09-05 04:21---------d-----wC:\Documents and Settings\Julie\Application Data\Mind Control Software
2008-09-03 18:15---------d-----wC:\Program Files\MSN Messenger
2008-09-02 00:230----a-wC:\Program Files\temp01
2007-10-18 17:19774,144----a-wC:\Program Files\RngInterstitial.dll
2007-07-21 05:5547,360----a-wC:\Documents and Settings\Julie\Application Data\pcouffin.sys
2007-03-06 23:240----a-wC:\Documents and Settings\Julie\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((( [emailprotected]_20.27.46.91 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 03:02:28163,328----a-wC:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-11-03 07:30:32172,099----a-wC:\WINDOWS\temp\HF359B.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-16 794713]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2008-04-13 143360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" [2005-11-03 372813]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 77824]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 149024]
"MsmqIntCert"="mqrt.dll" [2008-04-13 C:\WINDOWS\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP40"= SP40_32.DLL
"VIDC.SP41"= SP4X_32.DLL
"VIDC.SP42"= SP4X_32.DLL
"VIDC.SP43"= SP4X_32.DLL
"VIDC.SP44"= SP4X_32.DLL
"VIDC.SP45"= SP4X_32.DLL
"VIDC.SP46"= SP4X_32.DLL
"VIDC.SP47"= SP4X_32.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

S3 ACRUSBTM;ACRUSBTM;C:\WINDOWS\system32\drivers\ACRUSBTM.SYS [2007-08-02 28672]
S3 AVC1100;Adaptec AVC-1100 Video Capture;C:\WINDOWS\system32\DRIVERS\CA506AV.SYS [2002-07-21 175042]
S3 ca506aaf;Adaptec USB Audio Filter Driver (WDM);C:\WINDOWS\system32\drivers\ca506aaf.sys [2002-07-21 14273]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-22 21:14:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

C:\WINDOWS\explorer.exe [3148] 0x86086BC0

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe?[emailprotected]? ?^???`[emailprotected]?[emailprotected]

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\NTRtScan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\Client Server Security Agent\TmListen.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\temp\HF359B.EXE
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-22 21:20:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-23 04:20:10
ComboFix2.txt 2008-09-23 03:55:25
ComboFix3.txt 2008-09-23 03:28:15

Pre-Run: 13,617,418,240 bytes free
Post-Run: 13,606,670,336 bytes free

191--- E O F ---2008-09-11 06:49:48
    Looks good.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.

  • The above procedure will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Delete temporary files

Go to:
  • Start
  • Run
  • type: CLEANMGR.EXE
  • Press Enter.
.
When prompted select the C: drive and click OK.
Check the boxes for:
  • Temporary Internet Files
  • Downloaded Program Files
  • Recycle Bin
  • Temporary Files
.
Click OK or Enter

----------

Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

----------

Run a new HijackThis scan and post the log.

Let me know how everything is now.ok, my eyes have gone blurry, will follow up in the morning, thanks for all your help tonight. will let you know.No problem, I'm about done for tonight as well.

2115.

Solve : Java acting up again?

Answer»

Hey ya'll, back with the same issue as before with my Java not working although I've reinstalled it, run Mozilla in safe mode, and everything else suggested. Here are my logs. Thanks for all the help.

[Saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O20 - AppInit_DLLs:

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next REPLY.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Here are the logs man.

[Saving space - attachment deleted by admin]Hey man, just checked and my java is working just fine now. What exactly was wrong in there that you seen? Thanks for all the help man. Is everything else lookin straight in those logs?Something had corrupted the Java applet I think. Don't know what.

There is also a rootkit we will remove now with CF.



Disable Ad-Aware as it may interfere with repairs

  • Click the Settings button, Auto Scans tab, and under Scan on Ad-Aware startup
  • Be sure both selections for No automated scan are checked (green).
  • Then click Save and close Ad-Aware.
----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code BOX by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
TDSSSERV
TDSSserv
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

Here it is man. You're the bomb as always! Hope it looks good now.

[Saving space - attachment deleted by admin]
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .

  • The above procedure will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • RESET the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Download ATF Cleaner by Atribune to your Desktop.

Alternate download link

Note: Vista users must use Run As Administrator
  • Under Main: Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would LIKE to keep your saved passwords click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note that your system will run slower for a reboot or two after having used this tool so don't panic.

Delete ATF Cleaner.

Important: Restart the computer before continuing.

----------

Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the TERMS of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply

Here it is man

[Saving space - attachment deleted by admin] Looks great.

Next: Set a New Restore Point to prevent possible reinfection from an old one.

Please go to: Start -> All Programs -> Accessories -> System Tools -> System Restore -> System Restore Settings
Click to add a check mark beside Turn off System Restore and click Apply
When you are warned that all existing Restore Points will be deleted, click Yes to continue and wait a few moments to let System Restore clear.
Uncheck "Turn off System Restore"
Click "Apply," and then click "OK".

----------

Use the Secunia Software Inspector to check for out of date software.
Click Start Now
Check the box next to Enable thorough system inspection.
Click Start
Allow the scan to finish and scroll down to see if any updates are needed.
Update anything listed.

-----

Learn more about how to protect yourself while on the Internet from the following link. So how did I get infected in the first place? by Tony Klien.
Thanks for everything bro. You're the *censored* and anytime someone has trouble with their computer I always tell them about this site cause of all your hard work and the others. Appreciate it bro Thanks!!

Glad it worked.

2116.

Solve : Is reading email on the web site a way to avoid viruses??

Answer»

We have been warned to delete email unopened, for which the source is unknown and which has an attachment so as to avoid a virus.
Is it OK to access this mail on the website (IP server) and open it there or does the WARNING still apply? Will doing this increase the risk of infecting the website server? Thanks for your advice.If you open the unread email, it should be no PROBLEM. Downloading or opening pictures or clicking on links is the dangerous part.

What are you using to VIEW your EMAILS?

(program or web-based?)

2117.

Solve : Google and other sites behaving oddly - Help??

Answer»

I've gotten rid of a majority of the ill effects of a virus I recently made the mistake of getting (a few years of being clean doesn't mean you should start foregoing scanning things before installing them). Programs menu disappearing from my start menu as well as all of the other things on it, Task Manager Disabled, registry editing disabled, etc. Most of it was really no problem. But I'm STUCK on this one group of effects left.

The most immediately noticable problem I'm having is that google links are instead LINKING me to other search sites like "monstermarketplace".

Aside from that, a majority of the helpful-against-viruses sites, especially ones from that terribly helpful sticky in this forum, end up handing me this:

Failed to Connect
Firefox can't establish a connection to the server at www.besttechie.net.
Though the SITE seems valid, the browser was unable to establish a connection.

Finally, though Internet Explorer and FireFox work (mostly, see above) fine, my precious Google Chrome browser won't load *any* site.

Because my computer's pretty old and kept freezing in the middle of scans, I have two logs for MBAM and SAS (both of them have the logs copied together), because they didn't once finish a whole scan until I stopped them mid-scan at least once. That may be coincidence, though.

If you guys can help me resolve this I'll sing your names at the top of my lungs until I get bored of doing so. =p

Oh and if it's numbingly easy like proxy settings (the mechanics of which evade me on this confoundingly dumbed down system) let me know, so I can have a good laugh over not being able to fix it.

~Boa

[Saving space - attachment deleted by admin]Altough you need a firewall (we can help you with this in a bit) and some better protection (I suggest AVG), I don't actually see anything wrong. SAS and MBAM certain picked up a lot of junk, but HijackThis isn't showing anything aside from WildTangent. You don't have to remove it, but I would if I were you...
http://www.pchell.com/support/wildtangent.shtml

Just to be on the safe side, download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.Well would ya look at that... That resolved my issue! I think I'm in love.

Log attached- Can you CLUE me in on what was going on?

[Saving space - attachment deleted by admin]You had a couple of trojans left on your computer, one of which was hijacking your browser, causing you to get redirected to the wrong sites. As far as I can tell, it looks like your infections should be gone. Now, we should focus on getting you a firewall. You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.

And like I mentioned earlier, you need sufficient anti-virus protection. You can choose between several useful (and free) programs such as AVG, Avast!, Antivir, or several others. You should only use ONE anti-virus!Thanks loads. Looks like I CAME to the right place.

2118.

Solve : Black screen after system restore, other problems before system restore?

Answer»

This is my brother in laws Dell notebook running Vista. He was having problems with desktop icons not opening the program they shortcut to.
And this morning I tried to logon to this site but when I tried to logon, each time I pressed a key to enter my username and password it would execute another function rather than type the letter / number I was trying to enter.
The last thing I did was try system restore but now , after restoring, it has a black screen after start-up.
I already took the steps LISTED in evilfantasy's sticky thread and have SWB, MBAM, and HJT logfiles to post but I can't do anything now with the black screen.
I'm not REAL familiar with Vista so I don't even know how to start in safe mode ect.
Thanks for any HELP with this!!!Was there anything found by SAS and MBAM?

Yes.
SAS found over 20 which I quarantined and DELETED and MBAM found several including 1 infection (shown in red}.Sounds LIKE you might need the install CD.

2119.

Solve : Help, Trojan.....?

Answer» This scanner works with INTERNET Explorer only

Scan with the BitDefender Online Scanner
Click I Agree to the license and then install the ActiveX control.
Please DO NOT change the Scanning Options.
That will make your logs huge and we don't need to see clean files.

Select START Scan to begin.
This scan can take a while so please be patient and let it complete.

Once Bitdefender completes the scan:
Click-on the Detected Problems tab.
Then select Click here to export the scan report



This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

You will have to upload the file online. The forums will not accept HTML.

Upload the file to Savefile.com
There is no need to Register
Select Browse and locate the file.
Fill in the Title, Description and security code then click Upload
Copy the link next to Your link to the file: and post the link back here.http://www.savefile.com/files/1810253Keep screwing around with keygens and you will eventually have to REINSTALL or buy a new Hard Drive...

How is EVERYTHING now?Everything seems fine, but I STOPPED installing keygens a while ago and I thought I deleted all of them too.....Well you already have all of the security you need so you might just want to clear your restore points, it will free up some space but shouldn't be done too often.

Run CCleaner again.


Also...

I would also recommend that you Defrag the computer. There may be a lot of fragmented sections on the drive after cleaning the malware.

You can use the built in Windows Defrag or a faster FREE program. Defraggler is very effective and easy to use. Be sure to clean out temp files and restart the computer just before using this.
2120.

Solve : Unable to install Superantivirus during "read this before..."?

Answer»

1. Click Start, click Run, type msconfig, and then click OK.

The System Configuration Utility dialog box appears.

2. Click the General tab, click Normal Startup - load all device drivers and services, and then click OK.

3. When you are prompted, click Restart to restart the computer.

Any changes?There is no malware showing. You are going to have to find an XP CD to try a Repair Install. Do you have one or someone you can borrow it from?

Go to add/remove programs and uninstall:

ErrorSmart
MarketResearch
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar


----------

Delete the following from your Desktop (If they exist)
ISeeYouXP.exe
ISeeYouXP.txt
ISeeYouXP.lnk
(Shortcut for ISeeYouXP.bat)

----------

Download OTCleanIt.exe and save it to your Desktop.

  • DOUBLE-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
I have to go to WORK now. I think I can get a windows cd from my husbands friend. BUT I have tried to remove programs while in safe mode before (during this process) and I get an error message: ** correction the following error message only occurs with ErrorSmart. I was able to remove all viewpoints but I dont see MarketResearch

"The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not currently installed. Contact your support personnel for assistance"

(I just tried again to be sure)

Installing new Windows is the only option now right?No a Repair install can be tried first.I have a desktop with icons!

Welcome to avast! screen is present. Press OK?And how did this come about?I followed the most recent directions:
I removed all viewpoints from add/remove programs
ErrorSmart gave me the error I mentioned
I deleted all ISeeYouXPs you told me to from the desktop
I downloaded and ran OTCleanIt following all the directions
I rebooted when prompted then came to the desktop screen with the avast! window.

I clicked OK. The avast! screen disappeared but nothing else happened.

Currently, I am able to maneuver the cursor but am not able to click anything. Nor does CTRL ALT DEL work.
So you are back to the Repair install method. If that won't work then a reinstall is all thats left.What about the original win32: patched-cr[trj] I spoke about in the following files:

c:\windows\system32\explorer.exe
c:\windows\system32\lsass.exe
c:\windows\system32\services.exe
c:\windows\system32\svchost.exe
c:\windows\system32\winlogon.exe.

Those files have been fixed by Dr Web.

I'm back

I had some difficulty with the repair install. I borrowed a Windows XP CD from work but could not figure out how to get to the proper boot screen. I modified the Bios to select the cd-rom drive first, but it proceeded to go to the desktop/no icon/cursor screen. In my attempt to proceed I discovered a "Last Known Good Configuration" process--which I performed.

I (slowly) GOT the desktop icons back and was able to access programs and CTRL/ALT/DEL etc. I was able to get online as well. I ran SpyBot - no threats were detected. I ran CCleaner. I also started to add/remove programs that I couldn't while in safe mode. In order to completely remove some of the programs I removed I needed to restart. When I restarted I couldn't get online.

Then I decided to start the "read this before..." process in order over again. I shut down SpyBot and TeaTimer. I downloaded ResetTeaTimer.zip and ran that. I ran avast and it found the same win32: patched-cr[trj] in the same files I mentioned before. It asked me to stop and run a boot TIME scan--I chose no and quit. (If you remember that's what happened to cause me to lose the desktop icons before)

Then I ran Superantispyware. It found a few threats. When the machine restarted I got an error message: Windows - No Disk Exception Processing Message c0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c. Then it asks Cancel/Try Again/Continue. Not sure how to proceed. Is this because of the Bios I tried to change?

Look here for the error http://www.consumingexperience.com/2007/11/windows-no-disk-exception-processing.html
Thanks. Renaming the drives worked.

Attached are the logs to check my system. I'm still not able to get online with that machine. I'm on my laptop.

**Update I realized that my router has a timer setting to it and this computer was blocked after a certain time. I removed the block and IE is so far working fine now

[Saving space - attachment deleted by admin]Everything lokks OK now.

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.
  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ENSURE everything has been removed.
  • Delete Nortonremoval tool from your Desktop.
OK I ran that twice like you said. Seemed fine.

OK Some loose ends to tie up:

I was concerned that avast kept finding this win32:patched-ck [trj] trojan even after all we've gone through, so I uninstalled the whole program. Restarted and reinstalled again. When I restarted again, it asked to run a boot time scan--I chose no for now. Then a flash screen came up asking for registration, click OK. When I clicked ok the pc froze. I restarted. It froze again after clicking ok. I restarted in Safe mode and removed avast all together. I re-ran Dr. Web (which is what you said already removed the trojan) and it came up clear!

So, I would like to know what antivirus scanner is recommended- one that is going to update itself so she isn't left unprotected again. I use avast on my own computers but I don't like how it just reacted with mom's.

This next thing is a VERY MINOR problem, but I'd like to get rid of it so my mom doesn't get herself into trouble entering something she shouldn't When I load windows now, after the black "setup" screen another screen comes on asking me to select Windows XP Professional or Window XP Home edition. Pro is highlighted and there is a countdown timer that says something like "the highlighted item will be selected in XX seconds or press enter". How can I bypass that?

How can I re-enable SpyBot Tea timer?

What programs should we run routinely to keep the computer safe. I personally run SpyBot, Ad-Aware, Advanced WindowsCare and avast! Are they sufficient?

Thanks again for your help.

2121.

Solve : new hp protection??

Answer»

just bought an hp laptop a week AGO,its got symantec 60 day protection came with it,any other downloads i should add to my system for protection?I would suggest getting rid of Symantec once the trial runs out. There are better free solutions to use.

Once Symantec/Norton is uninstalled run this tool to get rid of what it always leaves behind.

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
  • Delete Nortonremoval tool from your Desktop.
----------

Remember to only install one antivirus!

1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Comodo Antivirus
5) PC Tools AntiVirus Free Edition

Remember to only install one FIREWALL!

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

----------

Go to Microsoft WINDOWS Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX PROGRAMS to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thanks
2122.

Solve : Start up fix please??

Answer»

All right, that would be OK.
Ok once I have added slave drive, ran virus check, ?
Yep. Can't be too careful.I have to go find another ribbon cord, can't attach slave on ribbon cord, so COULD yo let me know next steps please, in case i cant get hold of you when i start this procedure?

Quote from: Carbon Dudeoxide on September 23, 2008, 07:38:45 AM

Yep. Can't be too careful.
What virus SOFTWARE do you guy's use?Quote from: thebroons on September 23, 2008, 07:42:34 AM
I have to go find another ribbon cord, can't attach slave on ribbon cord, so could yo let me know next steps please, in case i cant get hold of you when i start this procedure?
Heh, talk about not getting hold of me. Sorry about that.

What exactly are you asking? Have you started by the way?Question 1 was which Av do you pro's use?

Q.2 can I use a machine that has 98 on it instead of my other machine that has xp?

still trying to locate another ribbon cable with piggy backI use Kaspersky Antivirus. It's not FREE, but its one of the tops.
Good free antiviruses include Avira and Avast.

As for you next question, I'm not sure, but I would go for the XP Machine.Thanks for the heads up..............

anything that is half good yo have to pay for

I am still looking for this piggy cable, can you advise the next step once i have completed virus check on dodgy hard drive please?
We will have to go from there first, I'm afraid.Ok, I'll give u a shout when i have the cable.

cheers
All right. Good Luck!
2123.

Solve : serious error recovery?

Answer»

I apologize if this is posted in the wrong section.

Heres what happened: I left the ROOM and when I CAME back in I noticed my computer was restarting. When it was finished a window poped and said the computer just recovered from a serious error.
here is the error reprt it generated:


C:\DOCUME~1\Erick\LOCALS~1Temp\WERf79c.dir00\Mini092608-01.dmp
C:\DOCUME~1\Erick\LOCALS~1Temp\WERf79c.dir00\sysdata.xml

what does this mean?

I have an HP Pavilion dv8000 laptop. Windows XP. Service pack 2 1.73 GHz Intel T2250.
Let me know if theres anything else you need to know!
thank you.This could be caused by any number of things. If you WANT, you could locate those files (if they still exist), compress them into a zip file (with WinZip or any similar program), and then attach them to your next post. But to be honest, unless it starts giving you trouble, it probably isn't anything to worry about. Of course, we'd still be happy to take a look if you wish.Thanks you. If it keeps doing it Ill let you know!
You're welcome. It was most likely a fluke from some CONFLICTING software. That's typically what I see in cases like this. However, if it happens again, then be sure to let us know so we can look into it further.

2124.

Solve : Oh shoot, help again please??

Answer»

Well I dont know how I did it but someone helped me here a few weeks ago and everything has been great til last night. I am posting my logs and hoping someone can help me.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:37 AM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre1.5.0_16\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Speeditup Free\SpeedItUp.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Analog Devices\SOUNDMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\PhoTags Express\Photags AutoDetect.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre1.5.0_16\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = HTTP://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: SPYBOT-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_16\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_16\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Rebecca\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - Global STARTUP: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Photags AutoDetect.lnk = C:\Program Files\PhoTags Express\Photags AutoDetect.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_16\bin\npjpi150_16.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_16\bin\npjpi150_16.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/html/activexplayer/SMALStreaming.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.photoworks.com/pixami/BPImageEditor.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows LIVE Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F80B9305-A013-11D2-BD23-00A024978908} (Accurad Image Control) - file://E:\viewer\accuradimage.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: GEARSecurity_BackUp - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 11673 bytes
Malwarebytes' Anti-Malware 1.27
Database version: 1127
Windows 5.1.2600 Service Pack 2

9/24/2008 11:59:01 AM
mbam-log-2008-09-24 (11-59-01).txt

Scan type: Quick Scan
Objects scanned: 56816
Time elapsed: 6 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
One of the main problems I am having is getting online.. I know its not my internet provider because I can get online on my sons computer no problem. Alot of problems getting into yahoo mail too. I hope someone can help me out.. thanks so much ! Here is the last log.. sorry for the delay, was having problems restarting my computer to get it.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/24/2008 at 12:51 PM

Application Version : 4.21.1004

Core Rules Database Version : 3578
Trace Rules Database Version: 1566

Scan type : Quick Scan
Total Scan Time : 00:32:18

Memory items scanned : 434
Memory threats detected : 0
Registry items scanned : 467
Registry threats detected : 0
File items scanned : 16139
File threats detected : 102

Adware.Tracking Cookie
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.richmedia.yahoo.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
ads.revsci.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.specificmedia.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.*adult URL* [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.*adult URL* [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.*adult URL* [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.*adult URL* [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.*adult URL* [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.e-2dj6wjk4gidpedo.stats.esomniture.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.tradedoubler.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.tradedoubler.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.tradedoubler.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.paypal.112.2o7.net [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
cache.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
cache.trafficmp.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
.interclick.com [ C:\Documents and Settings\Rebecca\Application Data\Mozilla\Firefox\Profiles\kk6obwxu.default\cookies.txt ]
No malware but you can try a few things.


Delete temporary files

Go to:

  • Start
  • Run
  • type: CLEANMGR.EXE
  • Press Enter.
.
When prompted select the C: drive and click OK.
Check the boxes for:
  • Temporary Internet Files
  • Downloaded Program Files
  • Recycle Bin
  • Temporary Files
..
Click OK or Enter

----------

  • Open Internet Explorer, click the Tools button, and then click Internet Options.
  • Click the Connections tab.
  • Click the first entry in the Dialup and Virtual Private Networks list, and then click Settings.
  • Select the Automatically detect settings check box, and then click OK.
  • Repeat the previous two steps for each entry in the Dialup and Virtual Private Networks list.
  • Click the Lan Settings button in the Connections tab, and repeat steps 4-6. Click OK on the Connections tab.
  • Close Internet Explorer, and then restart it.
Thank you so much!! It seems to be running better now, I am relieved to hear I didnt get another virus .. You guys are great here and thanks again!!
Becca
2125.

Solve : Best way and best software to protect my system from malware and Internet??

Answer»

> I am using sify ISP with limited data tarnsfer package.
>My ISP is showing that i have downloaded 1200 MB which is not true.
>I did'nt turned on the PC on the date prescribed by ISP but it showing i have downloaded 1200 MB and has cut down 20 VALID days
>I think some one has hacked my system.

So i am requesting you to tell the BEST way to protect my system from malware and internet

Thanks in advace.Before anyone tells you that, it may be that someone connected to your internet connection, via wireless?
How are you connected to the internet?

Because if your computer was off on those dates, even if a hacker got into the system the computer needs a PHYSICAL connection to the internet, while the computer is off, there is no way of obtaining an internet connection.
Quote from: kizza1645 on September 26, 2008, 05:07:30 AM

Before anyone tells you that, it may be that someone connected to your internet connection, via wireless?

This is certainly a likely explanation. Do you have a router set up, bspkumar? Someone could simply be hijacking your bandwidth.I agree that someone could be using your internet connection I just wanted to add that if you don't have anything protecting your computer for viruses check out AVAST I have been using it for a long while and it has done a really great job and is free to DOWNLOAD... www.avast.com
2126.

Solve : Windows is telling me i dont have any antivirus??

Answer»

I have avast anti virus and its working fine and has been for the past 8months. But just now windows is telling me i dont have any anti virus or spyware protection, which is weird because i have avast working just fine. Plus i have got spybotSD for spyware.Where is it saying this?

What is the EXACT message?'Windows did not find any anti-virus software on this computer'
says the same for spyware protection

its coming from the windows security center thingCan you CONFIRM that your antivirus is running and that there are no problems with it and is it updated?

When did this start? What did you do before it? (downloads, installs, ect...)Yes, Avast is running and there is a TRAY icon on the desktop. It started HAPPENING just then after i rebooted my computer for having my daily internet problems.I would TRY a System Restore to before the PROBLEM.I lready did that, and another problem is arising. Just then, while i was playing gmod, my internet just stoped.

Now this has been happening ever since i bought the computer, i personally think its vista.

It justs cuts off, and then after about 3 reboots it works fine?

I just then had to open the computer up and take the wireless reviever off the motherboard and plug it back in again.

But that caused even more problems,
static electricity parsed through to the motherboard and the computer started fuc*** up.
But after a faith reboot the problem was solved, and my internet problem.
Just an update, my internet cut off again, but this time it said there was an IP address clash on the network or something

2127.

Solve : runtime error 21?

Answer»

I'm not sure where i got this from, but last website i visited before i got this runtime error 21 pop up was when i logged on to facebook. It keep popping up runtime error 21 two times in a roll. I used spysweeper, and found this troj/agent-HIP. I deleted it from spysweeper but keeps coming back. Now it seems this virus is preventing me from downloading other spy virus removal program. Is blocking my access to download them and also having trouble accessing some of the help sites. I did a hijackthis scan and the log came up like this below. Hope someone here can help me, thanks. By the way, I did system restore and didnt work.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:39 AM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Winamp\winamp.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\nScan\ecls.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
c:\PROGRA~1\iesnap\navplay.exe
C:\WINDOWS\system32\rundll32.exe
C:\firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my123.com/
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\system32\host.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WinSearch - {27E96DE0-8211-42CF-9A1E-FA6246A95B77} - C:\WINDOWS\system32\winsearch.dll
O2 - BHO: Info cache - {385AB8C6-FB22-4D17-8834-064E2BA0A6F0} - C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54EBD53A-9BC1-480B-966A-843A333CA162} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C5E87A05-F463-4841-B19E-DD3EC3862368} - (no file)
O2 - BHO: (no name) - {E157D62A-D8A4-45DF-8E9B-C33D93821BDF} - (no file)
O2 - BHO: (no name) - {EE12D60D-AD9A-4095-B839-3BE6862679FD} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] "C:\Program Files\Realtek\InstallShield\AzMixerSel.exe"
O4 - HKLM\..\Run: [VAIO Recovery] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] "C:\Program Files\Norton Internet Security\UrlLstCk.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1138585964\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PartSeal] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe"
O4 - HKLM\..\Run: [vkevce52] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\vkevce52.dll,DllCanUnloadNow
O4 - HKLM\..\Run: [WJLKFRUN] "C:\WINDOWS\system32\Regsvr32.exe" -s "C:\Program Files\Common Files\WJLKFRUN\WJLKFRUN.dll"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [*Intelli Mouse Pro Version 2.0B*] C:\WINDOWS\system32\splm\ncsjapi32.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_3
O4 - HKCU\..\Run: [Intelli Mouse Pro Version 2.0B] C:\WINDOWS\system32\splm\ncsjapi32.exe
O4 - HKCU\..\RunOnce: [*Intelli Mouse Pro Version 2.0B*] C:\WINDOWS\system32\splm\ncsjapi32.exe
O4 - HKCU\..\Policies\Explorer\Run: [mscheck] rundll32.exe C:\WINDOWS\system32\wincheck080218.dll mymain
O4 - HKUS\S-1-5-18\..\Run: [Intelli Mouse Pro Version 2.0B] C:\WINDOWS\system32\splm\ncsjapi32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [*Intelli Mouse Pro Version 2.0B*] C:\WINDOWS\system32\splm\ncsjapi32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Intelli Mouse Pro Version 2.0B] C:\WINDOWS\system32\splm\ncsjapi32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [*Intelli Mouse Pro Version 2.0B*] C:\WINDOWS\system32\splm\ncsjapi32.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: msnbot.exe.lnk = C:\Documents and Settings\All Users\Application Data\IE7\msnbot.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Windows Update SP11.lnk = C:\Program Files\Common Files\xp11update.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: VeryCD³¬¼¶ËÑË÷ - C:\PROGRA~1\yok\yoksch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: lahd - {54DDB8A3-377A-4686-8FC7-6AED2FE70E17} - (no file)
O21 - SSODL: - {12311512-2C1D-44b2-A044-872AD2AD5A61} - (no file)
O21 - SSODL: (no name) - {12311512-2C1D-44b2-A044-872AD2AD5A61} - (no file)
O21 - SSODL: wbwk - {12311512-2C1D-44b2-A044-872AD2AD5A61} - (no file)
O21 - SSODL: eslo - {12311512-2C1D-44b2-A044-872AD2AD5A61} - (no file)
O23 - Service: 9477A - Unknown owner - C:\WINDOWS\system32\9477A.exe (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: B23989EF - Unknown owner - C:\WINDOWS\system32\6E36333D.EXE (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Drivers Desktop Management (Drivers Desktop) - Unknown owner - C:\WINDOWS\system32\explore.exe (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\DRIVER\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: ·þÎñÃû (svcname) - Unknown owner - C:\WINDOWS\system32\ebx1e4.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Windows XP SP2 Center - Unknown owner - C:\WINDOWS\system32\server.exe (file missing)
O23 - Service: Windows Accounts Driver (WindowsRemote) - Unknown owner - C:\WINDOWS\system32\servciesb.exe (file missing)
O23 - Service: Portable Media Serial Number Services (WmdmPmSNs) - Unknown owner - C:\WINDOWS\system32\tcpip.exe (file missing)

--
End of file - 17159 bytesWelcome to CH.

Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/147901966/SDFix.exe.html

When using this tool, you must use the Administrator's account or an account with Administrative rights

  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with SEVERAL options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.
Hi EF. Thanks for helping. I try to go into safe mode and my lap top won't let me. The screen will load up in the background with letters and will flash into blue ground saiding can't access and something about files being corrupted or i have virus preventing me to open this up. The blue iflash s really quick so I can't really pick up info in details. Also it seems I only can access everything thru task manager now. When my lap top reload, non of the icon s and tool bars shows up. I have no start button either. This thing is really killing my lap top.You will need to save this somewhere you can get to it to open it and try to have it run.

Download Malwarebytes' Anti-Malware (MBAM) http://rapidshare.com/files/148053910/mbam-setup.exe.html

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra NOTE)
    • The log is automatically saved by MBAM and can be viewed by clicking the LOGS tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Thanks alot EF. U been really HELPFUL and really quick with replies. The software u gave me fixed it. Once again, thanks alot.You should run a new HijackThis scan now and post the log.

    There is usually more hiding when it comes to this malware and it is better to get it all now so it doesn't come back later and cause more problems.
    2128.

    Solve : Not sure what it means...?

    Answer»

    8)Well, it isn't quite a year YET, but as I came here on another matter I thought I'd leave an update.

    No PROBLEMS here. I am, however, running Windows Defender once a week. The computer (still the same one) seems to be clean as a whistle. I think I had one bit of annoyance malware in the last 10 months.

    Windows Defender has me puzzled however. I ran it out of schedule because of the annoyance malware MENTIONED above and the malware disappeared. Now if you use WD you know that it GETS definition updates about twice a week - i.e., someone appears to be staying on top of things. What puzzles me however, is that WD ALWAYS says it found nothing. It has NEVER reported find something and deleting or quarantining it. Yet the machine is squeaky clean??? Maybe someone can SHED some light on that.

    Still living in a fools paradise here...

    2129.

    Solve : log files?

    Answer»

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 09/24/2008 at 09:15 AM

    Application Version : 4.1.1046

    Core Rules Database Version : 3578
    Trace Rules Database Version: 1566

    Scan type : Complete Scan
    Total Scan Time : 01:42:12

    Memory items scanned : 568
    Memory threats detected : 0
    Registry items scanned : 6849
    Registry threats detected : 2
    File items scanned : 129730
    File threats detected : 1

    Adware.Tracking Cookie
    C:\Documents and Settings\Erick\Cookies\[emailprotected][1].txt

    Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\FCOVM
    HKLM\SOFTWARE\Microsoft\RemoveRP
    Malwarebytes' Anti-Malware 1.24
    Database version: 1012
    Windows 5.1.2600 Service Pack 2

    11:48:58 AM 9/24/2008
    mbam-log-9-24-2008 (11-48-58).txt

    Scan type: Quick Scan
    Objects scanned: 44125
    Time elapsed: 8 minute(s), 52 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:52:21 AM, on 9/24/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Common Files\SYMANTEC Shared\ccSetMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Bret Taylor\Stickies\Stickies.exe
    C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
    R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: (no name) - {2FD955F0-970C-468A-A985-9CC8D3524542} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKCU\..\Run: [Stickies] C:\Program Files\Bret Taylor\Stickies\Stickies.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210812860062
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network DRIVERS Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Vongo Service - Unknown owner - C:\Program Files\Vongo\VongoService.exe (file missing)

    --
    End of file - 11989 bytes
    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - O2 - BHO: (no name) - {2FD955F0-970C-468A-A985-9CC8D3524542} - (no file)

    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis and restart the computer to register the changes made by HijackThis.

    ----------

    Create An Uninstall List

    • Start HijackThis
    • Click on the Open the Misc Tools section
    • Click on the Open Uninstall Manager button.
    • Click on the Save list button and specify where you would like to save this file and click Save.
      • When you press Save button a notepad will open with the contents of that file.
    • Copy and paste that list in your reply.
    32 Bit HP CIO Components Installer
    3Planesoft Screensaver Manager 1.1
    Ad-Aware SE Plus
    Adobe Creative Suite
    Adobe Flash Player ActiveX
    Adobe Premiere Pro
    Adobe Reader 6.0.1
    Adobe SVG Viewer 3.0
    AMP Font Viewer
    AOL Instant Messenger
    Apple Mobile Device Support
    Apple Software Update
    Canon EOS 5D WIA Driver
    Canon EOS-1Ds Mark II WIA Driver
    Canon RAW Image Task for ZoomBrowser EX
    Canon RemoteCapture Task for ZoomBrowser EX
    Canon Utilities Digital Photo Professional 3.0
    Canon Utilities EOS Utility
    Canon Utilities Original Data Security Tools
    Canon Utilities PhotoStitch
    Canon Utilities WFT-E1/E2 Utility
    Canon Utilities ZoomBrowser EX
    CC_ccProxyExt
    ccCommon
    CCleaner (remove only)
    ccPxyCore
    Conexant HD Audio
    Customer Experience Enhancement
    DGOControls
    DivX Content Uploader
    DivX Web Player
    Easy Internet Sign-up
    Eye Candy 4000
    GemMaster Mystic
    Google Earth
    HDAUDIO Soft Data Fax Modem with SmartCP
    HijackThis 2.0.2
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB896256)
    Hotfix for Windows XP (KB909095)
    Hotfix for Windows XP (KB912436)
    Hotfix for Windows XP (KB915326)
    Hotfix for Windows XP (KB926239)
    HP Customer Participation Program 10.0
    HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3
    HP Game Console and games
    HP Help and Support
    HP Imaging Device Functions 10.0
    HP Photosmart Essential 3.5
    HP Photosmart Premier Software 6.0
    HP Photosmart, Officejet and Deskjet 7.0.A
    HP PSC & OfficeJet 5.3.B
    HP Quick Launch Buttons 6.00 E2
    HP QuickPlay 2.1
    HP Smart Web Printing
    HP Solution Center 10.0
    HP Update
    HP User Guides 0011
    HP User Guides--System Recovery
    HP Wireless Assistant 2.00 E1
    Intel(R) PRO Network Connections Drivers
    iTunes
    Java(TM) 6 Update 7
    Koi Pond 3D Screensaver (CD Version) 1.0
    KPT(R) effects(TM)
    LimeWire 4.18.3
    LiveReg (Symantec Corporation)
    LiveUpdate 3.0 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)
    Logitech Gaming Software
    Macromedia Dreamweaver 8
    Macromedia Extension Manager
    Macromedia Flash 8
    Macromedia Flash 8 Video Encoder
    Macromedia Flash Player 8
    Macromedia Flash Player 8
    Macromedia Flash Player 8 Plugin
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft .NET Framework 3.0 Service Pack 1
    Microsoft .NET Framework 3.5
    Microsoft .NET Framework 3.5
    Microsoft Combat Flight Simulator
    Microsoft Money 2006
    Microsoft Office 2000 Premium
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Mozilla Firefox (2.0.0.16)
    MSRedist
    MSXML 6.0 Parser (KB933579)
    Musicmatch® Jukebox
    muvee autoProducer 4.5
    NetWaiting
    Norton AntiSpam
    Norton AntiVirus 2006
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security
    Norton Internet Security 2006 (Symantec Corporation)
    Norton Protection Center
    Norton SystemWorks 2003
    Norton WMI Update
    Norton WMI Update
    NVIDIA Drivers
    Office 2003 Trial Assistant
    OpenOffice.org Installer 1.0
    Quicken 2006
    QuickTime
    Rhapsody Player Engine
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows XP (KB893066)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB901190)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB903235)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Shop for HP Supplies
    SmartAudio
    Sonic Audio Module
    Sonic Copy Module
    Sonic Data Module
    Sonic Express Labeler
    Sonic MyDVD Plus
    Sonic Update Manager
    SonicAC3Encoder
    SonicMPEGEncoder
    SPBBC
    SPORE™ Creature Creator
    Stickies
    Super DVD Ripper v1.90
    SUPERAntiSpyware Free Edition
    Synaptics Pointing Device Driver
    Texas Instruments PCIxx21/x515/xx12 drivers.
    TourSetup
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Viewpoint Media Player
    Vongo
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB884575
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885464
    Windows XP Hotfix - KB885855
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888239
    Windows XP Hotfix - KB888402
    Windows XP Hotfix - KB889673
    Windows XP Hotfix - KB890546
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB892559
    WinRAR archiver
    Wireless Home Network Setup

    Update Firefox to the new version. Mozilla Firefox 2.0.0.17

    Go to Add or Remove Programs and uninstall Viewpoint Media Player

    Run CCleaner.

    How is everything now?Everything is good now! THANK YOU once again!!! You ROCK!!!Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.
    2130.

    Solve : how to get rid antivirus 2009?

    Answer»

    When you put the CD in if it does not start automatically you need to go into Computer or My Computer from the Desktop and start the CD that way.pulled it the disc up on my computer but dont know where to go from here I found another repair option to look at.
    http://www.bleepingcomputer.com/tutorials/tutorial148.htmlwent to this link but my disc does not have repair option showing should i click install now ?or how do i boot from disc ?I am really not sure... Not a Vista user thanks for all the help computer seems to be booting on normal mode but stiill says safe boot on hjt LOG but when i do boot manually in safe mode has a whole different look than now?Post a fresh HJT log please.Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:36:44 PM, on 9/21/2008
    Platform: WINDOWS Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16711)
    Boot mode: Safe mode with network support

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
    O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
    O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
    O4 - HKLM\..\Run: [QuickTime TASK] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
    O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
    O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
    O4 - HKLM\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
    O4 - HKLM\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
    O4 - HKLM\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
    O4 - HKLM\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [64813512409585575315790004508932] C:\Program Files\Antivirus 2009\av2009.exe
    O4 - HKCU\..\Run: [\SUE73BA.exe] C:\Windows\SUE73BA.exe
    O4 - HKCU\..\Run: [\SUE7CBF.exe] C:\Windows\SUE7CBF.exe
    O4 - HKCU\..\Run: [\SUE81DD.exe] C:\Windows\SUE81DD.exe
    O4 - HKCU\..\Run: [\SUE85D3.exe] C:\Windows\SUE85D3.exe
    O4 - HKCU\..\Run: [\SUE978F.exe] C:\Windows\SUE978F.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKman000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\logan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
    O13 - Gopher Prefix:
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: eNetHook.dll,avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Fix-It Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9815 bytes
    performance has gotten alot better,but STILL some issuesRun this online scan. Requires Internet Explorer

    Use the ESET Nod32 Online Scanner

    1. Check the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the activex control to install
    4. Click Start
    5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
    6. Click Scan
    7. Wait for the scan to finish
    8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.just cant get nod 32 to download,i'll keep trying

    2131.

    Solve : Re: Read this before requesting malware removal help?

    Answer»

    I was directed to your POST by another user and read all the details, I started with the C CCleanup and realized I have no idea if there are any cookies that I would need to keep or why. In following the rest of the steps I realized that the remedy is way too beyond my computer capabilities. I'm hoping, if I can describe for you what I am encountering, you may recognize it and what possible malware may have infected me.

    I have a pretty large music library, just under 3000 songs. Many were downloaded from CD's, some from friends libraries. some downloaded --- primarily from LimeWire (the user that directed me to your post said he BELIEVES LimeWire may be where he got his unwelcome friend). I compiled a very large and extremely time-consuming playlist in MS Media Player yesterday. I subsequently loaded and listened to the list for a few hours afterwards. As I was closing down MS Media for the evening, I looked at the list (still in the 'Play' box) and noticed that every song I had listened to had a duplicate entry on the playlist. I opened the list to edit and the duplicates were all there so I spent about 40 minutes manually deleting them. This just atarted yesterday

    I have no idea why this is happening and needless to say I'm reluctant to play that list or even to use the media player for fear that everything I access will be duplicated. I have a fairly NEW machine loaded with the most up-to-date version of TREND Micro Internet Security. I ran a full scan on the entire machine and then again on the music library and the MS Media Player program files and all came back clean (in each instance the final reports said they had detected and resolved on issue).

    Does this sound at all familiar to you? If so, or even if not, can you suggest any potential remedy that would not require me to be an MIT graduate? The machine is very new and full warrantied. I can take it back to Best Buy and they will probably run a diagnostic free of CHARGE, I'm just not sure if this is something they's be able to detect and eliminate.

    Any suggestions or direction would be most appreciated.

    Celtic 1Without the logs there isn't much we can do.

    2132.

    Solve : I am having problems with IE7 and java?

    Answer»

    I am having problems with IE7 and java. Anything with a javascript will not open on the websites. I am at a loss for what to do next. I have tried to install and uninstall java several times and still no luck. I am running win XP media center with IE7 and firefox. Please help. thank you in advance.

    Here is my hijackthis log file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:35:12 AM, on 9/25/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
    C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
    C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
    C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Common Files\NEW Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Digital Media Reader\shwiconem.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer DOWNLOAD and RECORD Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
    O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
    O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
    O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
    O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - GLOBAL Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra CONTEXT menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222248593562
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222248650671
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
    O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
    O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
    O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
    O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
    O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

    --
    End of file - 12410 bytes

    Download JavaRa

    • Unzip the file and open the JavaRa.exe
    • Click Remove Older Versions
    • JavaRa will search for and remove any outdated version of Java and remove any that are found.
    • Click Additional Tasks
    • Place a check next to Remove Useless JRE Files and click Go
    • Exit JavaRa
    • Delete the JavaRa files from the Desktop
    .
    ----------

    How is it now?Still nothing works with java related material.Open a web page, click tools, internet options, click delete browsing history, delete all, tick the box for add ons.

    Click advanced, click reset

    Close then open IE
    2133.

    Solve : Computer not working - Help with virus please!?

    Answer»

    Hi, I'm new to the boards and didn't want to sift through all the past threads since I need my computer fixed quickly and I don't understand any of this stuff.


    My issue is that my computer was freezing and crashing to the blue screen saying there was a "PHYSICAL MEMORY dump" or something like that. I went on and my wallpaper had gone to the default and my computer become laggy and firefox crashed frequently.

    Now when I log in all there is is the wallpaper and nothing else. There is no start task bar or icons. I don't know where to click...

    I'm very LOST and I just want to fix my computer so I can finish my work.

    Btw, I do have ad aware and avg they found things (that I removed) but they kept coming up with more later.


    Any help would be appreciated.Can you download and run anything?

    Press ctrl + alt + delete to bring up Task Manager. The go to File > New Task and type explorer.exe and press enter.

    Download TrendMicro HijackThis.exe (HJT) to the Desktop.

    • Double-click on HJTInstall.
    • Click on the Install button.
    • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
    • Upon install, HijackThis should open for you.
    • Click on the Do a SYSTEM scan and save a log file button
    • HijackThis will scan and then a log will open in notepad.
    • Copy and then paste the entire contents of the log in your post.
    • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or EVEN required.
    2134.

    Solve : Google link virus?

    Answer»

    I have been infected by a virus which affected Firefox and Internet explorer. I am not able to do a proper search using google or msn as it will re-direct me to some random sites. I am also not able to access anti-virus sites and all the links posted in this forum.

    Please help.

    Thank you so much for the assistance.Hi,

    Welcome , please read This

    Thanks!Hi Ivy,

    Thanks for your assistance.

    I am able to PROCEED till Step 3. The link for the anti-virus is not accessible for me.


    If you cannot download SuperAntiSpyware, can you continue to Step 4 and 6?I cant do that either. The links are not accessible. Can't download HijackThis or MalwareBytes?

    I guess I can put Ivy's knowledge to good use:


    Try this.

    Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

    * Double click on RSIT.exe to run.
    * Click Continue at the DISCLAIMER screen.
    * Once it has finished, two logs will open.
    * log.txt * Please post the contents of both logs in your next replygish.... I cant access that link either. Any alternative links?Can you try getting into Safe Mode With Networking?

    When you press the power button to turn on the computer, keep PRESSING F8.I cant boot up in the Safe mode. The blue screen appears after loading a couple of drivers. Are there any other ways?I was able to download CCleaner in normal mode but not the rest of the programPlease print these instructions as they will be needed later when Internet access is not available.

    Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/149732586/SDFix.exe.html

    When using this tool, you must use the Administrator's account or an account with Administrative rights


    • Double click SDFix.exe and it will extract the files to %systemdrive%
    • (this is the drive that contains the Windows Directory, typically C:\SDFix).
    • DO NOT use it just yet.
    Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Open the SDFix folder and double click RunThis.bat to start the script.

    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Copy and paste the contents of the results file Report.txt in your next reply.
    Thanks to all. I managed to solve the problem. Attached are the logs from the scans/clean.

    Cheers!

    [Saving space - attachment deleted by admin]Did you see the part about using two ANTIVIRUS? The logs look OK except for that.
    2135.

    Solve : Suspected Virtumundo?

    Answer»

    It all began when I ran an executable called keygen.exe... Yes, I know, stupid. If any of you are familiar with it, it's the sort that comes with crack.exe in the same archive as a text file. If it's pertinent, I'll post the link where I got it. I've done a lot of crap on my system, trying to fix it myself, so I haven't done anything else on the "Before you post" thread in case it'll make my system worse. I'll describe what's wrong with my system, then I'll give a list of the things I did, in the order I did them.

    Symptoms:
    -Certain sites won't load. Specifically, when I try to search google, or make any other search. Other various forums, including this one, won't load, and I'm actually using my laptop to make this post right now, which is why it's hard to get logs from my PC to here. I tried with the Firefox and Internet Explorer browsers, but the end result is the same - it just hangs while going "Waiting for www.google.com...." or whatever site I'm trying.
    -In the beginning, it kept saying my automatic updates were disabled, even though it said it wasn't on the control panel. Despite turning it off and on, every time I started up my comp, it would say that my automatic updates were disabled (in the Security Center).
    -The start bar lags on startup as well, you can't see anything but a long blue strip until it finally loads up correctly.

    What I did:
    -First, I ran a scan with Symantec, and it didn't find any errors.
    -Then, I installed Kaspersky (I had to uninstall Symantec to do so) and ran a full system scan, which found a few trojans and other malware, and deleted them, but my symptoms remained the same.
    -Next, I installed Spyware Doctor and ran a full scan, which also found some spyware and deleted them, but my computer was still just as bad.
    -I then followed these instructions:
    Quote

    ***********
    Download [but do *NOT* yet run] FixVundo from
    http://securityresponse.symantec.com/avcenter/FixVundo.exe

    [we'll have you run it later]
    Note: If you have previously download this file on another occasion, please download it again, to be absolutely sure you have the most current version.
    ********************
    Next, download VirtumundoBeGone from:
    http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

    * SAVE it to your Desktop
    * Close all running programs (including your Internet Browser)
    * Double-click VirtumundoBeGone.exe on the desktop
    * Follow the directions as indicated
    please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.
    just reboot if your system "jams"
    *********************
    After rebooting, it's now time to run FixVundo (which you had downloaded earlier).
    Make sure all other programs, including your Internet Browser, are closed.
    Double-click the FixVundo.exe file to start the removal tool.
    Click Start to begin the process, and then allow this tool to run.

    Important: Do not launch any new applications while the tool is running!

    Reboot your computer.
    Run the FixVundo removal tool again to ensure that the system is clean.

    I ran VirtumundoBeGone.exe but the log said:
    Quote
    [09/28/2008, 12:16:54] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\leon\Desktop\VirtumundoBeGone.exe" )
    [09/28/2008, 12:16:55] - Detected System Information:
    [09/28/2008, 12:16:55] - Windows Version: 5.1.2600, Service Pack 3
    [09/28/2008, 12:16:55] - Current Username: leon (Admin)
    [09/28/2008, 12:16:55] - Windows is in NORMAL mode.
    [09/28/2008, 12:16:55] - SEARCHING for Browser Helper Objects:
    [09/28/2008, 12:16:55] - BHO 1: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} (IEVkbdBHO Class)
    [09/28/2008, 12:16:55] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    [09/28/2008, 12:16:55] - Finished Searching Browser Helper Objects
    [09/28/2008, 12:16:55] - Finishing up...
    [09/28/2008, 12:16:55] - Nothing found! Exiting...

    Next I ran FixVundo.exe which ran a lengthy full scan of my computer. After a while, the window SIMPLY went gray and froze, and I had to forcibly end it. I rebooted my system and tried VirtumundoBegone again but nothing appeared still.

    -Then, I ran f-vmonde.exe from another source and it simply said no traces were detected either.

    As of now, the "Automatic Updates" notification no longer appears, but the same webpage problem persists.read this

    once you've followed those steps- you can post the logs here.Quote from: BC_Programmer on September 28, 2008, 06:54:58 PM
    read this

    once you've followed those steps- you can post the logs here.

    Alright, after doing all that, I ran into a few hitches, but otherwise my system appears TOTALLY normal now (Except one time my firefox crashed, which was a bit worrying, but that was before I finished everything else). When I was running Super Antispyware, it froze the first time as it was completing, so I ran it three more times, the third time completing the entire full scan. Here are all the logs.

    [Saving space - attachment deleted by admin]Here is the final SUPERAntiSpyware log that I couldn't get in (it only lets me do 4)

    [Saving space - attachment deleted by admin]Download the Norton Removal Tool (SymNRT) to your Desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.
    • Go to your desktop and double click on the removal tool and then click Setup.
    • Once open Click Next
    • Accept the license agreement and click Next
    • Type in the letters/numbers that you see into the text box then click Next.
    • Then click Next and the tool will start running.
    • Once finished restart the PC and run the tool again to ensure everything has been removed.
    • Delete Nortonremoval tool from your Desktop.
    .
    ----------

    Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the Desktop.

    ----------

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    O20 - Winlogon Notify: mlJApNDw - mlJApNDw.dll (file missing)

    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis and run CCleaner.

    How is everything now?Everything works perfectly (to my knowledge). Thank you very much Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start &GT; Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    2136.

    Solve : How to create?

    Answer»

    How do i create my own VIRUS to see how it works.
    I will like to HACK to a remote computer with this virus to see whether virus or TROJANS can do that and some PEOPLE say.The ability to understand a computer would help.If you LIVE in the U.S. follow the below link and I am sure you will get some assistance.

    http://www.fbi.gov/

    2137.

    Solve : new infection?

    Answer»

    downloaded something i thought was an e-card from a realative, turns out otherwise. slow performance and "Task Manager" button unavailable upon CTRL+ALT=DEL. i've run AVG, NAV, and AdAware several times each with no hits. everything's updated accordingly. oddly enough, NAV DETECTED TROJAN activity twice but found nothing in the scans.

    HiJackThis log below. thanks in advance for help.

    Logfile of Trend MICRO HijackThis v2.0.2
    Scan saved at 2:59:10 PM, on 9/27/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\Explorer.EXE
    C:\Documents and Settings\All Users\Application Data\yjmtydez\gvmjinyj.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\CTHELPER.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
    C:\Program Files\2Wire Wireless Manager\2Wire.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: (no name) - {a33fa729-d155-4b23-842b-2c665ecabdb6} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [2Wire Wireless Manager] "C:\Program Files\2Wire Wireless Manager\2Wire.exe" -a
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AABRQNRI] %systemroot%\AABRQNRI.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [glzH3A8zpZ] C:\Documents and Settings\All Users\Application Data\yjmtydez\gvmjinyj.exe
    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
    O4 - S-1-5-18 Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe (User 'Default user')
    O4 - Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/LightSurfUploadControl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193266776421
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193273452609
    O21 - SSODL: uicfgmnt - {4349E812-0311-51BF-A08A-091922CF8CD5} - C:\Program Files\wmgtzqf\uicfgmnt.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 9751 bytes
    Download Malwarebytes' Anti-Malware (MBAM)

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and Paste the entire report in your next reply.
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

      ----------

      Now run a new HijackThis scan and post the log.thanks. the "Application Data\yjmtydez\gvmjinyj.exe" line that seemed to be the issue looks like it was removed. if you see anything else that needs attention, please let me know.

      MBAM REPORT:

      Malwarebytes' Anti-Malware 1.28
      Database version: 1217
      Windows 5.1.2600 Service Pack 3

      9/28/2008 2:13:14 AM
      mbam-log-2008-09-28 (02-13-14).txt

      Scan type: Quick Scan
      Objects scanned: 49353
      Time elapsed: 6 minute(s), 9 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 22
      Registry Values Infected: 3
      Registry Data Items Infected: 1
      Folders Infected: 5
      Files Infected: 69

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\CLSID\{4349E812-0311-51BF-A08A-091922CF8CD5} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\glzh3a8zpz (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\uicfgmnt (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Folders Infected:
      C:\Program Files\Inet Delivery (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\349168 (Trojan.BHO) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

      Files Infected:
      C:\Documents and Settings\All Users\Application Data\yjmtydez\gvmjinyj.exe (Trojan.FakeAlert.H) -> Delete on reboot.
      C:\Program Files\Inet Delivery\inetdl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\Inet Delivery\intdel.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\akl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\uninstall.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\unsetup.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\wmgtzqf\uicfgmnt.dll (Trojan.FakeAlert.H) -> Delete on reboot.
      C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\Drivers\RSVTRRNO.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\[emailprotected]k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\medup020.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.


      HiJackThis 2nd log on next reply...HIJACKTHIS 2nd REPORT:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 2:22:30 AM, on 9/28/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\VTTimer.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\CTHELPER.EXE
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\2Wire Wireless Manager\2Wire.exe
      C:\Program Files\PowerISO\PWRISOVM.EXE
      C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
      C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Sprint Instinct Applications\MEMonitor.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\system32\SearchProtocolHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: (no name) - {a33fa729-d155-4b23-842b-2c665ecabdb6} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
      O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKLM\..\Run: [2Wire Wireless Manager] "C:\Program Files\2Wire Wireless Manager\2Wire.exe" -a
      O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
      O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [AABRQNRI] %systemroot%\AABRQNRI.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
      O4 - S-1-5-18 Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe (User 'SYSTEM')
      O4 - .DEFAULT Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe (User 'Default user')
      O4 - Startup: Sprint media monitor.lnk = C:\WINDOWS\RM.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
      O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
      O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/LightSurfUploadControl.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193266776421
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193273452609
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

      --
      End of file - 9547 bytes
      Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      O4 - HKLM\..\Run: [AABRQNRI] %systemroot%\AABRQNRI.exe

      Important: Close all windows except for HijackThis and then click Fix checked.

      Exit HijackThis.

      ----------

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Go to Start > Run and type notepad.exe then click OK

      Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

      Code: [Select]REGEDIT4

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
      "AABRQNRI"=-
      Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

      Make sure that you tell me if you receive a success message about adding the above
      to the registry. If you do not get a success message, it did not work.


      Delete the fixme.reg from the Desktop.

      ----------

      Run this online scan. Requires Internet Explorer

      Use the ESET Nod32 Online Scanner

      1. Check the box next to YES, I accept the Terms of Use.
      2. Click Start
      3. When asked, allow the activex control to install
      4. Click Start
      5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
      6. Click Scan
      7. Wait for the scan to finish
      8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

      Also let me know how everything is now.reg addition was successful. connection still seems slow but that's likely the network. everything else seems fine.

      ESET Log:

      # version=4
      # OnlineScanner.ocx=1.0.0.635
      # OnlineScannerDLLA.dll=1, 0, 0, 79
      # OnlineScannerDLLW.dll=1, 0, 0, 78
      # OnlineScannerUninstaller.exe=1, 0, 0, 49
      # vers_standard_module=3481 (20080929)
      # vers_arch_module=1.064 (20080214)
      # vers_adv_heur_module=1.066 (20070917)
      # EOSSerial=048ed1922d508249a7da7870d4fe045d
      # end=finished
      # remove_checked=true
      # unwanted_checked=true
      # utc_time=2008-09-30 08:28:18
      # local_time=2008-09-30 01:28:18 (-0800, Pacific Daylight Time)
      # country="United States"
      # osver=5.1.2600 NT Service Pack 3
      # scanned=712317
      # found=2
      # scan_time=10424
      C:\Documents and Settings\Johnny H. Christ\Local Settings\Temp\inst2_297.exeWin32/Srizbi.NBR trojan (unable to clean - deleted)00000000000000000000000000000000
      C:\Documents and Settings\Johnny H. Christ\Local Settings\Temp\mmm(2).exeWin32/Spy.Goldun.NDM trojan (unable to clean - deleted)00000000000000000000000000000000


      thank you.Download CCleaner Slim and save it to your Desktop.
      When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
      Follow the prompts to install the program.
      Complete the installation then:

      • Double-click the CCleaner shortcut on the desktop to start the program.
      • Click on the Options block on the left, then choose Cookies.
        • Under Cookies to Delete, highlight any cookies you would like to retain permanently
        • Click the right arrow > to move them to the Cookies to Keep window.
      • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
      • Click Cleaner on the left then Run Cleaner on the right to run the program.
      • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
      • Caution: It is not recommended that you use the 'Registry' FEATURE unless you are very familiar with the registry.
      • Exit CCleaner after it has completed its process.
      .
      ----------

      Your Java is out of date.

      Older versions have vulnerabilities that malicious sites can use to infect your system.

      First install the new Sun Java Runtime Environment

      Be sure to close all browser windows before beginning the install.

      Remove the old version(s)

      • Download JavaRa and unzip the file to your Desktop.
      • Open JavaRA.exe and choose Remove Older Versions
      • Once complete exit JavaRA and delete the program.
      • Run CCleaner.
      ----------

      How is everything now?everything seems to be okay. re0installed java, though it said the latest version was already installed.

      but for the most part everything is back to normal. thanks!Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide or Windows Vista System Restore Guide
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from GETTING infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
      2138.

      Solve : Hey, my computer has slowed down tremendously.?

      Answer»

      Hey CH, sorry that I'm back again to bother you guys. I've been experiencing very slow internet connections, my laptop can only get 36 mbps from my own router. Also firefox has been freezing on me a lot lately. I did a complete scan with SuperAntiSpyware and it hasn't found any problems. I then tried scanning with Malwarebytes which did me no good either.

      Here is my Hijackthis Log, Thank you.


      Logfile of TREND Micro HijackThis v2.0.2
      Scan saved at 2:21:51 PM, on 9/30/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\System32\hkcmd.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\AIM6\aim6.exe
      C:\Program Files\AIM6\aolsoftware.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
      O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
      O8 - Extra context menu item: APPEND Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1218790466575
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O20 - AppInit_DLLs: acaptuser32.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: McAfee Application Installer Cleanup (0099891222740077) (0099891222740077mcinstcleanup) - Unknown owner - C:\Windows\TEMP\009989~1.EXE (file missing)
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
      O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
      O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
      O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
      O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
      O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
      O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
      O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
      O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
      O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
      O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
      O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

      --
      End of file - 11140 bytes
      I don't think it is malware. Try POSTING in the Windows forum.

      Have HijackThis fix this entry.

      O23 - Service: McAfee Application Installer Cleanup (0099891222740077) (0099891222740077mcinstcleanup) - Unknown owner - C:\Windows\TEMP\009989~1.EXE (file missing)

      2139.

      Solve : Problem with winlogin.exe?

      Answer»

      + 2008-04-14 00:12:2413,312------WC:\WINDOWS\ServicePackFiles\i386\lsass.exe
      + 2004-08-04 03:41:36606,684------wC:\WINDOWS\ServicePackFiles\i386\ltmdmnt.sys
      + 2004-08-04 03:41:38420,992------wC:\WINDOWS\ServicePackFiles\i386\ltmdmntt.sys
      + 2008-04-13 18:40:527,040------wC:\WINDOWS\ServicePackFiles\i386\ltotape.sys
      + 2004-08-04 03:39:3220,864------wC:\WINDOWS\ServicePackFiles\i386\lwadihid.sys
      + 2008-04-14 00:12:2472,704------wC:\WINDOWS\ServicePackFiles\i386\magnify.exe
      + 2008-04-14 00:12:2557,344------wC:\WINDOWS\ServicePackFiles\i386\makecab.exe
      + 2008-04-14 00:11:5614,336------wC:\WINDOWS\ServicePackFiles\i386\mcastmib.dll
      + 2008-04-14 00:11:5684,480------wC:\WINDOWS\ServicePackFiles\i386\mciavi32.dll
      + 2008-04-14 00:11:5635,328------wC:\WINDOWS\ServicePackFiles\i386\mciqtz32.dll
      + 2008-04-14 00:11:5623,040------wC:\WINDOWS\ServicePackFiles\i386\mciseq.dll
      + 2008-04-14 00:11:5623,552------wC:\WINDOWS\ServicePackFiles\i386\mciwave.dll
      + 2008-04-14 00:11:56118,272------wC:\WINDOWS\ServicePackFiles\i386\mdminst.dll
      + 2008-04-14 00:11:5686,016------wC:\WINDOWS\ServicePackFiles\i386\mdmxsdk.dll
      + 2004-08-04 03:41:5611,868------wC:\WINDOWS\ServicePackFiles\i386\mdmxsdk.sys
      + 2008-04-13 18:41:2126,112------wC:\WINDOWS\ServicePackFiles\i386\memstpci.sys
      + 2008-04-13 18:36:4163,744------wC:\WINDOWS\ServicePackFiles\i386\mf.sys
      + 2008-04-14 00:11:5640,960------wC:\WINDOWS\ServicePackFiles\i386\mf3216.dll
      + 2008-04-14 00:11:56927,504------wC:\WINDOWS\ServicePackFiles\i386\mfc40u.dll
      + 2008-04-14 00:11:561,028,096------wC:\WINDOWS\ServicePackFiles\i386\mfc42.dll
      + 2006-10-14 08:13:25981,760------wC:\WINDOWS\ServicePackFiles\i386\mfc42u.dll
      + 2008-04-14 00:11:5622,528------wC:\WINDOWS\ServicePackFiles\i386\mfcsubs.dll
      + 2008-04-14 00:11:5614,848------wC:\WINDOWS\ServicePackFiles\i386\mgmtapi.dll
      + 2008-04-14 00:11:5718,944------wC:\WINDOWS\ServicePackFiles\i386\midimap.dll
      + 2008-04-14 00:11:57274,432------wC:\WINDOWS\ServicePackFiles\i386\migism.dll
      + 2008-04-14 00:11:57261,120------wC:\WINDOWS\ServicePackFiles\i386\migisma.dll
      + 2008-04-14 00:11:5760,928------wC:\WINDOWS\ServicePackFiles\i386\miglibnt.dll
      + 2008-04-14 00:12:25103,936------wC:\WINDOWS\ServicePackFiles\i386\migload.exe
      + 2008-04-14 00:12:257,680------wC:\WINDOWS\ServicePackFiles\i386\migregdb.exe
      + 2008-04-14 00:12:25245,248------wC:\WINDOWS\ServicePackFiles\i386\migwiz.exe
      + 2008-04-14 00:12:25241,152------wC:\WINDOWS\ServicePackFiles\i386\migwiza.exe
      + 2008-04-14 00:11:5729,696------wC:\WINDOWS\ServicePackFiles\i386\mimefilt.dll
      + 2008-04-14 00:11:57586,240------wC:\WINDOWS\ServicePackFiles\i386\mlang.dll
      + 2008-04-14 00:12:251,414,656------wC:\WINDOWS\ServicePackFiles\i386\mmc.exe
      + 2008-04-14 00:11:57184,320------wC:\WINDOWS\ServicePackFiles\i386\mmc30.dll
      + 2008-04-14 00:11:5728,672------wC:\WINDOWS\ServicePackFiles\i386\mmc30r.dll
      + 2008-04-14 00:11:57163,328------wC:\WINDOWS\ServicePackFiles\i386\mmcbase.dll
      + 2008-04-14 00:11:57397,312------wC:\WINDOWS\ServicePackFiles\i386\mmcex.dll
      + 2008-04-14 00:11:5740,960------wC:\WINDOWS\ServicePackFiles\i386\mmcexr.dll
      + 2008-04-14 00:11:57106,496------wC:\WINDOWS\ServicePackFiles\i386\mmcfxc.dll
      + 2008-04-14 00:11:576,656------wC:\WINDOWS\ServicePackFiles\i386\mmcfxcr.dll
      + 2008-04-14 00:11:571,872,896------wC:\WINDOWS\ServicePackFiles\i386\mmcndmgr.dll
      + 2008-04-14 00:12:2533,792------wC:\WINDOWS\ServicePackFiles\i386\mmcperf.exe
      + 2008-04-14 00:11:5761,440------wC:\WINDOWS\ServicePackFiles\i386\mmcshext.dll
      + 2008-04-14 00:11:5717,408------wC:\WINDOWS\ServicePackFiles\i386\mmfutil.dll
      + 2004-08-04 12:00:0068,768------wC:\WINDOWS\ServicePackFiles\i386\mmsystem.dll
      + 2008-04-14 00:11:5734,560------wC:\WINDOWS\ServicePackFiles\i386\mnmdd.dll
      + 2008-04-14 00:12:2532,768------wC:\WINDOWS\ServicePackFiles\i386\mnmsrvc.exe
      + 2008-04-14 00:11:57207,360------wC:\WINDOWS\ServicePackFiles\i386\mobsync.dll
      + 2008-04-14 00:12:26143,360------wC:\WINDOWS\ServicePackFiles\i386\mobsync.exe
      + 2008-04-13 19:00:1930,080------wC:\WINDOWS\ServicePackFiles\i386\modem.sys
      + 2008-04-14 00:11:57153,600------wC:\WINDOWS\ServicePackFiles\i386\modemui.dll
      + 2008-04-14 00:12:2616,384------wC:\WINDOWS\ServicePackFiles\i386\mofcomp.exe
      + 2008-04-14 00:11:57123,904------wC:\WINDOWS\ServicePackFiles\i386\mofd.dll
      + 2008-04-14 00:12:4216,896------wC:\WINDOWS\ServicePackFiles\i386\more.com
      + 2008-04-13 16:45:30216,064------wC:\WINDOWS\ServicePackFiles\i386\moricons.dll
      + 2008-04-13 18:39:4723,040------wC:\WINDOWS\ServicePackFiles\i386\mouclass.sys
      + 2008-04-13 18:39:4642,368------wC:\WINDOWS\ServicePackFiles\i386\mountmgr.sys
      + 2008-04-14 00:12:273,558,912------wC:\WINDOWS\ServicePackFiles\i386\moviemk.exe
      + 2008-04-13 18:46:2215,232------wC:\WINDOWS\ServicePackFiles\i386\mpe.sys
      + 2008-04-14 00:12:27123,392------wC:\WINDOWS\ServicePackFiles\i386\mplay32.exe
      + 2008-04-14 00:11:5759,904------wC:\WINDOWS\ServicePackFiles\i386\mpr.dll
      + 2008-04-14 00:11:5787,040------wC:\WINDOWS\ServicePackFiles\i386\mprapi.dll
      + 2008-04-14 00:11:5753,248------wC:\WINDOWS\ServicePackFiles\i386\mprdim.dll
      + 2008-04-13 18:32:44180,608------wC:\WINDOWS\ServicePackFiles\i386\mrxdav.sys
      + 2008-04-13 19:17:01456,576------wC:\WINDOWS\ServicePackFiles\i386\mrxsmb.sys
      + 2008-04-14 00:11:5871,680------wC:\WINDOWS\ServicePackFiles\i386\msacm32.dll
      + 2008-04-14 00:11:58331,776------wC:\WINDOWS\ServicePackFiles\i386\msadce.dll
      + 2008-04-13 17:25:5720,480------wC:\WINDOWS\ServicePackFiles\i386\msadcer.dll
      + 2008-04-14 00:11:5861,440------wC:\WINDOWS\ServicePackFiles\i386\msadcf.dll
      + 2008-04-13 17:25:5716,384------wC:\WINDOWS\ServicePackFiles\i386\msadcfr.dll
      + 2008-04-14 00:11:58143,360------wC:\WINDOWS\ServicePackFiles\i386\msadco.dll
      + 2008-04-13 17:25:5716,384------wC:\WINDOWS\ServicePackFiles\i386\msadcor.dll
      + 2008-04-14 00:11:5853,248------wC:\WINDOWS\ServicePackFiles\i386\msadcs.dll
      + 2008-04-14 00:11:58155,648------wC:\WINDOWS\ServicePackFiles\i386\msadds.dll
      + 2008-04-13 17:25:5824,576------wC:\WINDOWS\ServicePackFiles\i386\msaddsr.dll
      + 2008-04-13 17:26:1724,576------wC:\WINDOWS\ServicePackFiles\i386\msader15.dll
      + 2008-04-14 00:11:58536,576------wC:\WINDOWS\ServicePackFiles\i386\msado15.dll
      + 2008-04-14 00:11:58180,224------wC:\WINDOWS\ServicePackFiles\i386\msadomd.dll
      + 2008-04-14 00:11:5857,344------wC:\WINDOWS\ServicePackFiles\i386\msador15.dll
      + 2008-04-14 00:11:58200,704------wC:\WINDOWS\ServicePackFiles\i386\msadox.dll
      + 2008-04-14 00:11:5857,344------wC:\WINDOWS\ServicePackFiles\i386\msadrh15.dll
      + 2008-04-14 00:10:063,584------wC:\WINDOWS\ServicePackFiles\i386\msafd.dll
      + 2008-04-14 00:11:5886,016------wC:\WINDOWS\ServicePackFiles\i386\msapsspc.dll
      + 2008-04-14 00:11:5857,344------wC:\WINDOWS\ServicePackFiles\i386\msasn1.dll
      + 2008-04-14 00:11:58220,160------wC:\WINDOWS\ServicePackFiles\i386\mscandui.dll
      + 2008-04-14 00:11:5873,728------wC:\WINDOWS\ServicePackFiles\i386\mscms.dll
      + 2008-04-14 00:11:5869,632------wC:\WINDOWS\ServicePackFiles\i386\msconf.dll
      + 2008-04-14 00:12:27169,984------wC:\WINDOWS\ServicePackFiles\i386\msconfig.exe
      + 2004-07-17 16:42:20116,288------wC:\WINDOWS\ServicePackFiles\i386\msconv97.dll
      + 2008-04-13 17:26:0712,288------wC:\WINDOWS\ServicePackFiles\i386\mscpx32r.dll
      + 2008-04-14 00:11:5836,864------wC:\WINDOWS\ServicePackFiles\i386\mscpxl32.dll
      + 2008-04-14 00:11:58297,984------wC:\WINDOWS\ServicePackFiles\i386\msctf.dll
      + 2008-04-14 00:11:5868,608------wC:\WINDOWS\ServicePackFiles\i386\msctfp.dll
      + 2008-04-14 00:11:584,096------wC:\WINDOWS\ServicePackFiles\i386\msdadc.dll
      + 2008-04-14 00:11:58118,784------wC:\WINDOWS\ServicePackFiles\i386\msdadiag.dll
      + 2008-04-14 00:11:584,096------wC:\WINDOWS\ServicePackFiles\i386\msdaenum.dll
      + 2008-04-14 00:11:584,096------wC:\WINDOWS\ServicePackFiles\i386\msdaer.dll
      + 2008-04-14 00:11:58532,480------wC:\WINDOWS\ServicePackFiles\i386\msdaipp.dll
      + 2008-04-14 00:11:58233,472------wC:\WINDOWS\ServicePackFiles\i386\msdaora.dll
      + 2008-04-13 17:24:1416,384------wC:\WINDOWS\ServicePackFiles\i386\msdaorar.dll
      + 2008-04-14 00:11:5877,824------wC:\WINDOWS\ServicePackFiles\i386\msdaosp.dll
      + 2008-04-13 17:25:5816,384------wC:\WINDOWS\ServicePackFiles\i386\msdaprsr.dll
      + 2008-04-14 00:11:58200,704------wC:\WINDOWS\ServicePackFiles\i386\msdaprst.dll
      + 2008-04-14 00:11:59204,800------wC:\WINDOWS\ServicePackFiles\i386\msdaps.dll
      + 2008-04-14 00:11:59118,784------wC:\WINDOWS\ServicePackFiles\i386\msdarem.dll
      + 2008-04-13 17:25:5816,384------wC:\WINDOWS\ServicePackFiles\i386\msdaremr.dll
      + 2008-04-14 00:11:59151,552------wC:\WINDOWS\ServicePackFiles\i386\msdart.dll
      + 2008-04-14 00:11:594,096------wC:\WINDOWS\ServicePackFiles\i386\msdasc.dll
      + 2008-04-14 00:11:59315,392------wC:\WINDOWS\ServicePackFiles\i386\msdasql.dll
      + 2008-04-13 17:26:0716,384------wC:\WINDOWS\ServicePackFiles\i386\msdasqlr.dll
      + 2008-04-14 00:11:5994,208------wC:\WINDOWS\ServicePackFiles\i386\msdatl3.dll
      + 2008-04-14 00:11:5920,480------wC:\WINDOWS\ServicePackFiles\i386\msdatt.dll
      + 2008-04-14 00:11:594,096------wC:\WINDOWS\ServicePackFiles\i386\msdaurl.dll
      + 2008-04-14 00:11:5936,864------wC:\WINDOWS\ServicePackFiles\i386\msdfmap.dll
      + 2008-04-14 00:11:5914,336------wC:\WINDOWS\ServicePackFiles\i386\msdmo.dll
      + 2008-04-14 00:12:276,144------wC:\WINDOWS\ServicePackFiles\i386\msdtc.exe
      + 2008-04-14 00:11:5958,880------wC:\WINDOWS\ServicePackFiles\i386\msdtclog.dll
      + 2008-04-14 00:11:59427,008------wC:\WINDOWS\ServicePackFiles\i386\msdtcprx.dll
      + 2008-04-14 00:11:5990,112------wC:\WINDOWS\ServicePackFiles\i386\msdtcstp.dll
      + 2008-04-14 00:11:59956,928------wC:\WINDOWS\ServicePackFiles\i386\msdtctm.dll
      + 2008-04-14 00:11:59161,792------wC:\WINDOWS\ServicePackFiles\i386\msdtcuiu.dll
      + 2008-04-13 18:46:0951,200------wC:\WINDOWS\ServicePackFiles\i386\msdv.sys
      + 2008-03-25 04:50:28518,944------wC:\WINDOWS\ServicePackFiles\i386\msexch40.dll
      + 2008-03-25 04:50:30326,432------wC:\WINDOWS\ServicePackFiles\i386\msexcl40.dll
      + 2008-04-13 18:32:3919,072------wC:\WINDOWS\ServicePackFiles\i386\msfs.sys
      + 2008-04-14 00:11:59539,136------wC:\WINDOWS\ServicePackFiles\i386\msftedit.dll
      + 2008-04-14 00:11:59997,376------wC:\WINDOWS\ServicePackFiles\i386\msgina.dll
      + 2008-04-13 18:56:3235,072------wC:\WINDOWS\ServicePackFiles\i386\msgpc.sys
      + 2008-04-14 00:11:593,166,208------wC:\WINDOWS\ServicePackFiles\i386\msgr3en.dll
      + 2008-04-14 00:11:5915,360------wC:\WINDOWS\ServicePackFiles\i386\msgrocm.dll
      + 2008-04-14 00:11:5982,944------wC:\WINDOWS\ServicePackFiles\i386\msgsc.dll
      + 2008-04-13 17:30:28180,224------wC:\WINDOWS\ServicePackFiles\i386\msgslang.dll
      + 2008-04-14 00:11:5933,792------wC:\WINDOWS\ServicePackFiles\i386\msgsvc.dll
      + 2008-04-14 00:12:45188,416------wC:\WINDOWS\ServicePackFiles\i386\msh261.drv
      + 2008-04-14 00:12:45294,912------wC:\WINDOWS\ServicePackFiles\i386\msh263.drv
      + 2008-04-14 00:12:2729,184------wC:\WINDOWS\ServicePackFiles\i386\mshta.exe
      + 2008-04-14 00:11:593,066,880------wC:\WINDOWS\ServicePackFiles\i386\mshtml.dll
      + 2008-04-14 00:11:59449,024------wC:\WINDOWS\ServicePackFiles\i386\mshtmled.dll
      + 2008-04-13 16:26:2656,832------wC:\WINDOWS\ServicePackFiles\i386\mshtmler.dll
      + 2008-04-14 00:11:592,843,136------wC:\WINDOWS\ServicePackFiles\i386\msi.dll
      + 2008-04-14 00:11:5951,712------wC:\WINDOWS\ServicePackFiles\i386\msident.dll
      + 2008-04-14 00:11:596,656------wC:\WINDOWS\ServicePackFiles\i386\msidle.dll
      + 2008-04-14 00:11:59248,832------wC:\WINDOWS\ServicePackFiles\i386\msieftp.dll
      + 2008-04-14 00:12:2878,848------wC:\WINDOWS\ServicePackFiles\i386\msiexec.exe
      + 2008-04-14 00:11:59271,360------wC:\WINDOWS\ServicePackFiles\i386\msihnd.dll
      + 2008-04-14 00:11:594,608------wC:\WINDOWS\ServicePackFiles\i386\msimg32.dll
      + 2008-04-14 00:12:2860,416------wC:\WINDOWS\ServicePackFiles\i386\msimn.exe
      + 2008-04-13 15:39:43884,736------wC:\WINDOWS\ServicePackFiles\i386\msimsg.dll
      + 2008-04-14 00:11:59159,232------wC:\WINDOWS\ServicePackFiles\i386\msimtf.dll
      + 2008-04-14 00:11:59376,832------wC:\WINDOWS\ServicePackFiles\i386\msinfo.dll
      + 2008-04-13 18:54:2822,016------wC:\WINDOWS\ServicePackFiles\i386\msircomm.sys
      + 2008-04-14 00:12:2840,960------wC:\WINDOWS\ServicePackFiles\i386\msiregmv.exe
      + 2008-04-14 00:11:5915,360------wC:\WINDOWS\ServicePackFiles\i386\msisip.dll
      + 2008-03-25 04:50:341,516,568------wC:\WINDOWS\ServicePackFiles\i386\msjet40.dll
      + 2008-03-25 04:50:40355,112------wC:\WINDOWS\ServicePackFiles\i386\msjetol1.dll
      + 2008-04-14 00:12:00151,583------wC:\WINDOWS\ServicePackFiles\i386\msjint40.dll
      + 2008-04-14 00:12:00102,400------wC:\WINDOWS\ServicePackFiles\i386\msjro.dll
      + 2008-03-25 04:50:4260,192------wC:\WINDOWS\ServicePackFiles\i386\msjter40.dll
      + 2008-03-25 04:50:42248,608------wC:\WINDOWS\ServicePackFiles\i386\msjtes40.dll
      + 2008-04-13 18:39:527,552------wC:\WINDOWS\ServicePackFiles\i386\mskssrv.sys
      + 2008-04-14 00:12:0025,088------wC:\WINDOWS\ServicePackFiles\i386\mslbui.dll
      + 2008-03-25 04:50:44219,936------wC:\WINDOWS\ServicePackFiles\i386\msltus40.dll
      + 2008-04-14 00:12:0039,936------wC:\WINDOWS\ServicePackFiles\i386\mslwvtts.dll
      + 2008-04-14 00:12:281,695,232------wC:\WINDOWS\ServicePackFiles\i386\msmsgs.exe
      + 2004-08-04 12:00:0011,053,008------wC:\WINDOWS\ServicePackFiles\i386\msncli.exe
      + 2008-04-14 00:12:00290,816------wC:\WINDOWS\ServicePackFiles\i386\msnsspc.dll
      + 2004-08-04 12:00:001,327,320------wC:\WINDOWS\ServicePackFiles\i386\msnsusii.exe
      + 2008-04-14 00:12:00122,368------wC:\WINDOWS\ServicePackFiles\i386\msobcomm.dll
      + 2008-04-14 00:12:0016,384------wC:\WINDOWS\ServicePackFiles\i386\msobdl.dll
      + 2008-04-14 00:12:00565,248------wC:\WINDOWS\ServicePackFiles\i386\msobmain.dll
      + 2008-04-14 00:12:0030,720------wC:\WINDOWS\ServicePackFiles\i386\msobshel.dll
      + 2008-04-14 00:12:0019,456------wC:\WINDOWS\ServicePackFiles\i386\msobweb.dll
      + 2008-04-14 00:12:001,314,816------wC:\WINDOWS\ServicePackFiles\i386\msoe.dll
      + 2008-04-14 00:12:00252,928------wC:\WINDOWS\ServicePackFiles\i386\msoeacct.dll+ 2008-04-13 16:23:542,479,616------wC:\WINDOWS\ServicePackFiles\i386\msoeres.dll
      + 2008-04-14 00:12:00105,984------wC:\WINDOWS\ServicePackFiles\i386\msoert2.dll
      + 2008-04-14 00:12:2829,184------wC:\WINDOWS\ServicePackFiles\i386\msoobe.exe
      + 2008-04-13 17:24:1420,480------wC:\WINDOWS\ServicePackFiles\i386\msorc32r.dll
      + 2008-04-14 00:12:00143,360------wC:\WINDOWS\ServicePackFiles\i386\msorcl32.dll
      + 2008-04-14 00:12:28343,040------wC:\WINDOWS\ServicePackFiles\i386\mspaint.exe
      + 2008-04-14 00:12:0029,696------wC:\WINDOWS\ServicePackFiles\i386\mspatcha.dll
      + 2008-03-25 04:50:45355,104------wC:\WINDOWS\ServicePackFiles\i386\mspbde40.dll
      + 2008-04-13 18:39:505,376------wC:\WINDOWS\ServicePackFiles\i386\mspclock.sys
      + 2008-04-13 18:39:514,992------wC:\WINDOWS\ServicePackFiles\i386\mspqm.sys
      + 2008-04-13 16:23:3148,128------wC:\WINDOWS\ServicePackFiles\i386\msprivs.dll
      + 2008-04-14 00:12:00146,432------wC:\WINDOWS\ServicePackFiles\i386\msrating.dll
      + 2008-03-25 04:50:47432,928------wC:\WINDOWS\ServicePackFiles\i386\msrd2x40.dll
      + 2008-03-25 04:50:49322,336------wC:\WINDOWS\ServicePackFiles\i386\msrd3x40.dll
      + 2008-03-25 04:50:52559,904------wC:\WINDOWS\ServicePackFiles\i386\msrepl40.dll
      + 2008-04-14 00:12:0011,264------wC:\WINDOWS\ServicePackFiles\i386\msrle32.dll
      + 2008-04-14 00:12:00134,656------wC:\WINDOWS\ServicePackFiles\i386\mssap.dll
      + 2008-04-14 00:12:00155,136------wC:\WINDOWS\ServicePackFiles\i386\mssha.dll
      + 2008-04-13 18:14:5876,800------wC:\WINDOWS\ServicePackFiles\i386\msshamsg.dll
      + 2008-04-13 18:36:4615,488------wC:\WINDOWS\ServicePackFiles\i386\mssmbios.sys
      + 2008-04-14 00:12:00274,432------wC:\WINDOWS\ServicePackFiles\i386\mst120.dll
      + 2008-04-14 00:12:0057,344------wC:\WINDOWS\ServicePackFiles\i386\mst123.dll
      + 2008-04-13 18:46:0849,024------wC:\WINDOWS\ServicePackFiles\i386\mstape.sys
      + 2008-04-14 00:12:00274,944------wC:\WINDOWS\ServicePackFiles\i386\mstask.dll
      + 2008-04-13 18:39:505,504------wC:\WINDOWS\ServicePackFiles\i386\mstee.sys
      + 2008-03-25 04:50:55264,992------wC:\WINDOWS\ServicePackFiles\i386\mstext40.dll
      + 2008-04-14 00:12:00532,480------wC:\WINDOWS\ServicePackFiles\i386\mstime.dll
      + 2008-04-14 00:12:2912,288------wC:\WINDOWS\ServicePackFiles\i386\mstinit.exe
      + 2008-04-14 00:12:00116,224------wC:\WINDOWS\ServicePackFiles\i386\mstlsapi.dll
      + 2008-04-14 00:12:00195,072------wC:\WINDOWS\ServicePackFiles\i386\msutb.dll
      + 2008-04-14 00:12:00132,608------wC:\WINDOWS\ServicePackFiles\i386\msv1_0.dll
      + 2008-04-14 00:12:001,384,479------wC:\WINDOWS\ServicePackFiles\i386\msvbvm60.dll
      + 2008-04-14 00:12:0157,344------wC:\WINDOWS\ServicePackFiles\i386\msvcirt.dll
      + 2008-04-14 00:12:01413,696------wC:\WINDOWS\ServicePackFiles\i386\msvcp60.dll
      + 2008-04-14 00:12:01343,040------wC:\WINDOWS\ServicePackFiles\i386\msvcrt.dll
      + 2008-04-13 18:30:4661,440------wC:\WINDOWS\ServicePackFiles\i386\msvcrt40.dll
      + 2008-04-14 00:12:01121,344------wC:\WINDOWS\ServicePackFiles\i386\msvfw32.dll
      + 2008-04-14 00:12:011,428,992------wC:\WINDOWS\ServicePackFiles\i386\msvidctl.dll
      + 2008-04-14 00:12:0172,704------wC:\WINDOWS\ServicePackFiles\i386\msw3prt.dll
      + 2008-03-25 04:50:57838,432------wC:\WINDOWS\ServicePackFiles\i386\mswdat10.dll
      + 2008-04-14 00:12:01203,776------wC:\WINDOWS\ServicePackFiles\i386\mswebdvd.dll
      + 2008-04-14 00:12:01245,248------wC:\WINDOWS\ServicePackFiles\i386\mswsock.dll
      + 2008-03-25 04:50:58621,344------wC:\WINDOWS\ServicePackFiles\i386\mswstr10.dll
      + 2008-04-14 00:12:0124,576------wC:\WINDOWS\ServicePackFiles\i386\msxactps.dll
      + 2008-03-25 04:50:58355,104------wC:\WINDOWS\ServicePackFiles\i386\msxbde40.dll
      + 2008-04-14 00:12:01506,368------wC:\WINDOWS\ServicePackFiles\i386\msxml.dll
      + 2008-04-14 00:12:01701,440------wC:\WINDOWS\ServicePackFiles\i386\msxml2.dll
      + 2008-04-14 00:12:011,104,896------wC:\WINDOWS\ServicePackFiles\i386\msxml3.dll
      + 2008-04-14 00:12:0116,896------wC:\WINDOWS\ServicePackFiles\i386\msyuv.dll
      + 2004-08-04 03:41:40126,686------wC:\WINDOWS\ServicePackFiles\i386\mtlmnt5.sys
      + 2004-08-04 03:41:381,309,184------wC:\WINDOWS\ServicePackFiles\i386\mtlstrm.sys
      + 2008-04-14 00:12:29119,808------wC:\WINDOWS\ServicePackFiles\i386\mtstocom.exe
      + 2008-04-14 00:12:0166,560------wC:\WINDOWS\ServicePackFiles\i386\mtxclu.dll
      + 2008-04-14 00:12:0130,720------wC:\WINDOWS\ServicePackFiles\i386\mtxdm.dll
      + 2008-04-14 00:12:014,096------wC:\WINDOWS\ServicePackFiles\i386\mtxex.dll
      + 2008-04-14 00:12:0134,304------wC:\WINDOWS\ServicePackFiles\i386\mtxlegih.dll
      + 2008-04-14 00:12:0191,648------wC:\WINDOWS\ServicePackFiles\i386\mtxoci.dll
      + 2008-04-14 00:12:011,737,856------wC:\WINDOWS\ServicePackFiles\i386\mtxparhd.dll
      + 2004-08-04 03:29:38452,736------wC:\WINDOWS\ServicePackFiles\i386\mtxparhm.sys
      + 2008-04-14 00:12:2990,624------wC:\WINDOWS\ServicePackFiles\i386\muisetup.exe
      + 2008-04-13 19:17:05105,344------wC:\WINDOWS\ServicePackFiles\i386\mup.sys
      + 2008-04-13 18:43:5512,672------wC:\WINDOWS\ServicePackFiles\i386\mutohpen.sys
      + 2008-04-14 00:12:0190,624------wC:\WINDOWS\ServicePackFiles\i386\mydocs.dll
      + 2008-04-13 18:46:2585,248------wC:\WINDOWS\ServicePackFiles\i386\nabtsfec.sys
      + 2008-04-14 00:12:01221,184------wC:\WINDOWS\ServicePackFiles\i386\nac.dll
      + 2008-04-14 00:12:0130,208------wC:\WINDOWS\ServicePackFiles\i386\napipsec.dll
      + 2008-04-14 00:12:01193,024------wC:\WINDOWS\ServicePackFiles\i386\napmontr.dll
      + 2008-04-14 00:12:29176,640------wC:\WINDOWS\ServicePackFiles\i386\napstat.exe
      + 2008-04-14 00:12:2953,760------wC:\WINDOWS\ServicePackFiles\i386\narrator.exe
      + 2008-04-14 00:12:0136,352------wC:\WINDOWS\ServicePackFiles\i386\ncobjapi.dll
      + 2008-04-14 00:12:0147,104------wC:\WINDOWS\ServicePackFiles\i386\ncprov.dll
      + 2008-04-14 00:12:019,728------wC:\WINDOWS\ServicePackFiles\i386\ncpsres.dll
      + 2008-04-14 00:12:0117,920------wC:\WINDOWS\ServicePackFiles\i386\nddeapi.dll
      + 2008-04-14 00:12:294,096------wC:\WINDOWS\ServicePackFiles\i386\nddeapir.exe
      + 2008-04-14 00:12:0118,944------wC:\WINDOWS\ServicePackFiles\i386\nddenb32.dll
      + 2008-04-13 19:20:37182,656------wC:\WINDOWS\ServicePackFiles\i386\ndis.sys
      + 2008-04-13 18:46:2210,880------wC:\WINDOWS\ServicePackFiles\i386\ndisip.sys
      + 2008-04-14 00:12:0157,344------wC:\WINDOWS\ServicePackFiles\i386\ndisnpp.dll
      + 2008-04-13 18:57:2710,112------wC:\WINDOWS\ServicePackFiles\i386\ndistapi.sys
      + 2008-04-13 18:55:5814,592------wC:\WINDOWS\ServicePackFiles\i386\ndisuio.sys
      + 2008-04-13 19:20:4291,520------wC:\WINDOWS\ServicePackFiles\i386\ndiswan.sys
      + 2008-04-13 18:57:2940,576------wC:\WINDOWS\ServicePackFiles\i386\ndproxy.sys
      + 2008-04-14 00:12:2942,496------wC:\WINDOWS\ServicePackFiles\i386\net.exe
      + 2008-04-14 00:12:29124,928------wC:\WINDOWS\ServicePackFiles\i386\net1.exe
      + 2008-04-14 00:12:01337,408------wC:\WINDOWS\ServicePackFiles\i386\netapi32.dll
      + 2008-04-13 18:56:0234,688------wC:\WINDOWS\ServicePackFiles\i386\netbios.sys
      + 2008-04-13 19:21:00162,816------wC:\WINDOWS\ServicePackFiles\i386\netbt.sys
      + 2008-04-14 00:12:01622,592------wC:\WINDOWS\ServicePackFiles\i386\netcfgx.dll
      + 2008-04-14 00:12:29111,104------wC:\WINDOWS\ServicePackFiles\i386\netdde.exe
      + 2008-04-14 00:12:01139,264------wC:\WINDOWS\ServicePackFiles\i386\netid.dll
      + 2008-04-14 00:12:01407,040------wC:\WINDOWS\ServicePackFiles\i386\netlogon.dll
      + 2008-04-14 00:12:01198,144------wC:\WINDOWS\ServicePackFiles\i386\netman.dll
      + 2008-04-14 00:12:0177,312------wC:\WINDOWS\ServicePackFiles\i386\netoc.dll
      + 2008-04-14 00:12:01875,008------wC:\WINDOWS\ServicePackFiles\i386\netplwiz.dll
      + 2008-04-14 00:12:0111,776------wC:\WINDOWS\ServicePackFiles\i386\netrap.dll
      + 2008-04-14 00:16:51329,728------wC:\WINDOWS\ServicePackFiles\i386\netsetup.exe
      + 2008-04-14 00:12:2986,016------wC:\WINDOWS\ServicePackFiles\i386\netsh.exe
      + 2008-04-14 00:12:021,703,936------wC:\WINDOWS\ServicePackFiles\i386\netshell.dll
      + 2008-04-14 00:12:2936,864------wC:\WINDOWS\ServicePackFiles\i386\netstat.exe
      + 2008-04-14 00:12:0280,896------wC:\WINDOWS\ServicePackFiles\i386\netui0.dll
      + 2008-04-14 00:12:02245,760------wC:\WINDOWS\ServicePackFiles\i386\netui1.dll
      + 2004-08-04 03:31:42132,695------wC:\WINDOWS\ServicePackFiles\i386\netwlan5.sys
      + 2008-04-14 00:12:02247,808------wC:\WINDOWS\ServicePackFiles\i386\newdev.dll
      + 2008-04-13 18:51:2561,824------wC:\WINDOWS\ServicePackFiles\i386\nic1394.sys
      + 2008-04-14 00:12:0298,304------wC:\WINDOWS\ServicePackFiles\i386\nlhtml.dll
      + 2008-04-14 00:12:02229,376------wC:\WINDOWS\ServicePackFiles\i386\nmas.dll
      + 2008-04-14 00:12:0228,672------wC:\WINDOWS\ServicePackFiles\i386\nmasnt.dll
      + 2008-04-14 00:12:0281,920------wC:\WINDOWS\ServicePackFiles\i386\nmchat.dll
      + 2008-04-14 00:12:0277,824------wC:\WINDOWS\ServicePackFiles\i386\nmcom.dll
      + 2008-04-14 00:12:02151,552------wC:\WINDOWS\ServicePackFiles\i386\nmft.dll
      + 2008-04-14 00:12:0228,672------wC:\WINDOWS\ServicePackFiles\i386\nmmkcert.dll
      + 2008-04-13 18:53:0940,320------wC:\WINDOWS\ServicePackFiles\i386\nmnt.sys
      + 2008-04-14 00:12:02172,032------wC:\WINDOWS\ServicePackFiles\i386\nmoldwb.dll
      + 2008-04-14 00:12:02188,416------wC:\WINDOWS\ServicePackFiles\i386\nmwb.dll
      + 2008-04-14 00:12:2969,120------wC:\WINDOWS\ServicePackFiles\i386\notepad.exe
      + 2008-04-13 18:32:3930,848------wC:\WINDOWS\ServicePackFiles\i386\npfs.sys
      + 2008-04-14 00:12:2915,360------wC:\WINDOWS\ServicePackFiles\i386\nppagent.exe
      + 2008-04-14 00:12:0254,784------wC:\WINDOWS\ServicePackFiles\i386\npptools.dll
      + 2008-04-13 18:54:3628,672------wC:\WINDOWS\ServicePackFiles\i386\nscirda.sys
      + 2008-04-14 00:12:2976,800------wC:\WINDOWS\ServicePackFiles\i386\nslookup.exe
      + 2004-08-04 12:00:0047,564------wC:\WINDOWS\ServicePackFiles\i386\ntdetect.com
      + 2008-04-14 00:11:24706,048------wC:\WINDOWS\ServicePackFiles\i386\ntdll.dll
      + 2008-04-14 00:12:0267,072------wC:\WINDOWS\ServicePackFiles\i386\ntdsapi.dll
      + 2008-04-14 00:12:02212,992------wC:\WINDOWS\ServicePackFiles\i386\ntevt.dll
      + 2008-04-13 19:15:53574,976------wC:\WINDOWS\ServicePackFiles\i386\ntfs.sys
      + 2004-08-04 12:00:0033,840------wC:\WINDOWS\ServicePackFiles\i386\ntio.sys
      + 2004-08-04 12:00:0034,560------wC:\WINDOWS\ServicePackFiles\i386\ntio404.sys
      + 2004-08-04 12:00:0035,648------wC:\WINDOWS\ServicePackFiles\i386\ntio411.sys
      + 2004-08-04 12:00:0035,424------wC:\WINDOWS\ServicePackFiles\i386\ntio412.sys
      + 2004-08-04 12:00:0034,560------wC:\WINDOWS\ServicePackFiles\i386\ntio804.sys
      + 2008-04-13 19:24:372,145,280------wC:\WINDOWS\ServicePackFiles\i386\ntkrnlmp.exe
      + 2008-04-13 18:31:212,065,792------wC:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
      + 2008-04-13 18:31:212,023,936------wC:\WINDOWS\ServicePackFiles\i386\ntkrpamp.exe
      + 2008-04-14 00:12:0244,032------wC:\WINDOWS\ServicePackFiles\i386\ntlanman.dll
      + 2008-04-14 00:12:028,192------wC:\WINDOWS\ServicePackFiles\i386\ntlsapi.dll
      + 2008-04-14 00:12:02118,784------wC:\WINDOWS\ServicePackFiles\i386\ntmarta.dll
      + 2008-04-14 00:12:0240,960------wC:\WINDOWS\ServicePackFiles\i386\ntmsapi.dll
      + 2008-04-14 00:12:02179,200------wC:\WINDOWS\ServicePackFiles\i386\ntmsdba.dll
      + 2008-04-14 00:12:02488,448------wC:\WINDOWS\ServicePackFiles\i386\ntmsmgr.dll
      + 2008-04-14 00:12:02435,200------wC:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll
      + 2004-08-04 03:41:40180,360------wC:\WINDOWS\ServicePackFiles\i386\ntmtlfax.sys
      + 2008-04-14 00:12:0262,976------wC:\WINDOWS\ServicePackFiles\i386\ntoc.dll
      + 2008-04-13 19:27:532,188,928------wC:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
      + 2008-04-14 00:12:0291,136------wC:\WINDOWS\ServicePackFiles\i386\ntprint.dll
      + 2008-04-14 00:12:02143,360------wC:\WINDOWS\ServicePackFiles\i386\ntshrui.dll
      + 2008-04-14 00:12:30420,864------wC:\WINDOWS\ServicePackFiles\i386\ntvdm.exe
      + 2008-04-14 00:12:0215,360------wC:\WINDOWS\ServicePackFiles\i386\ntvdmd.dll
      + 2008-04-14 00:12:024,274,816------wC:\WINDOWS\ServicePackFiles\i386\nv4_disp.dll
      + 2004-08-04 03:29:561,897,408------wC:\WINDOWS\ServicePackFiles\i386\nv4_mini.sys
      + 2008-04-13 18:56:0688,320------wC:\WINDOWS\ServicePackFiles\i386\nwlnkipx.sys
      + 2008-04-14 00:12:02142,336------wC:\WINDOWS\ServicePackFiles\i386\nwprovau.dll
      + 2008-04-14 00:12:02270,336------wC:\WINDOWS\ServicePackFiles\i386\oakley.dll
      + 2008-04-14 00:10:30229,376------wC:\WINDOWS\ServicePackFiles\i386\obelog.dll
      + 2008-04-14 00:10:30966,656------wC:\WINDOWS\ServicePackFiles\i386\obemetal.dll
      + 2007-04-02 18:44:1177,824------wC:\WINDOWS\ServicePackFiles\i386\obemtllc.dll
      + 2008-04-14 00:10:3086,016------wC:\WINDOWS\ServicePackFiles\i386\obepopc.dll
      + 2008-04-14 00:12:02286,208------wC:\WINDOWS\ServicePackFiles\i386\objsel.dll
      + 2008-04-13 18:40:52405,504------wC:\WINDOWS\ServicePackFiles\i386\obrb041b.dll
      + 2008-04-13 18:40:56408,576------wC:\WINDOWS\ServicePackFiles\i386\obrb0424.dll
      + 2008-04-14 00:12:0296,256------wC:\WINDOWS\ServicePackFiles\i386\occache.dll
      + 2008-04-14 00:12:0215,360------wC:\WINDOWS\ServicePackFiles\i386\ocgen.dll
      + 2008-04-14 00:12:0267,584------wC:\WINDOWS\ServicePackFiles\i386\ocmanage.dll
      + 2008-04-14 00:12:0217,408------wC:\WINDOWS\ServicePackFiles\i386\ocmsn.dll
      + 2004-08-04 12:00:0026,224------wC:\WINDOWS\ServicePackFiles\i386\odbc16gt.dll
      + 2008-04-14 00:12:02249,856------wC:\WINDOWS\ServicePackFiles\i386\odbc32.dll
      + 2008-04-14 00:12:0216,384------wC:\WINDOWS\ServicePackFiles\i386\odbc32gt.dll
      + 2008-04-14 00:12:3032,768------wC:\WINDOWS\ServicePackFiles\i386\odbcad32.exe
      + 2008-04-14 00:12:0224,576------wC:\WINDOWS\ServicePackFiles\i386\odbcbcp.dll
      + 2008-04-14 00:12:02135,168------wC:\WINDOWS\ServicePackFiles\i386\odbcconf.dll
      + 2008-04-14 00:12:3069,632------wC:\WINDOWS\ServicePackFiles\i386\odbcconf.exe
      + 2008-04-14 00:12:02106,496------wC:\WINDOWS\ServicePackFiles\i386\odbccp32.dll
      + 2008-04-14 00:12:0265,536------wC:\WINDOWS\ServicePackFiles\i386\odbccr32.dll
      + 2008-04-14 00:12:0265,536------wC:\WINDOWS\ServicePackFiles\i386\odbccu32.dll
      + 2008-04-13 17:26:0594,208------wC:\WINDOWS\ServicePackFiles\i386\odbcint.dll
      + 2008-04-14 00:10:3153,279------wC:\WINDOWS\ServicePackFiles\i386\odbcji32.dll
      + 2008-04-14 00:12:02278,559------wC:\WINDOWS\ServicePackFiles\i386\odbcjt32.dll
      + 2008-04-13 17:26:0512,288------wC:\WINDOWS\ServicePackFiles\i386\odbcp32r.dll
      + 2008-04-14 00:12:02147,456------wC:\WINDOWS\ServicePackFiles\i386\odbctrac.dll
      + 2008-04-14 00:12:0220,511------wC:\WINDOWS\ServicePackFiles\i386\oddbse32.dll
      + 2008-04-14 00:12:0220,510------wC:\WINDOWS\ServicePackFiles\i386\odexl32.dll+ 2008-04-14 00:12:02104,448------wC:\WINDOWS\ServicePackFiles\i386\oeimport.dll
      + 2008-04-14 00:12:3060,416------wC:\WINDOWS\ServicePackFiles\i386\oemig50.exe
      + 2008-04-14 00:12:0235,328------wC:\WINDOWS\ServicePackFiles\i386\oemiglib.dll
      + 2008-04-14 00:12:02192,000------wC:\WINDOWS\ServicePackFiles\i386\offfilt.dll
      + 2008-04-13 18:46:1861,696------wC:\WINDOWS\ServicePackFiles\i386\ohci1394.sys
      + 2008-04-14 00:12:021,287,168------wC:\WINDOWS\ServicePackFiles\i386\ole32.dll
      + 2008-04-14 00:12:02551,936------wC:\WINDOWS\ServicePackFiles\i386\oleaut32.dll
      + 2008-04-14 00:12:0274,752------wC:\WINDOWS\ServicePackFiles\i386\olecli32.dll
      + 2008-04-14 00:12:0237,376------wC:\WINDOWS\ServicePackFiles\i386\olecnv32.dll
      + 2008-04-14 00:12:02487,424------wC:\WINDOWS\ServicePackFiles\i386\oledb32.dll
      + 2008-04-14 00:12:0265,536------wC:\WINDOWS\ServicePackFiles\i386\oledb32r.dll
      + 2008-04-14 00:12:02122,880------wC:\WINDOWS\ServicePackFiles\i386\oledlg.dll
      + 2008-04-14 00:12:02107,008------wC:\WINDOWS\ServicePackFiles\i386\oleprn.dll
      + 2008-04-14 00:12:0284,992------wC:\WINDOWS\ServicePackFiles\i386\olepro32.dll
      + 2008-04-14 00:12:02144,384------wC:\WINDOWS\ServicePackFiles\i386\onex.dll
      + 2008-04-14 00:12:3151,200------wC:\WINDOWS\ServicePackFiles\i386\oobebaln.exe
      + 2008-04-14 00:12:02713,728------wC:\WINDOWS\ServicePackFiles\i386\opengl32.dll
      + 2008-04-13 18:32:32166,912------wC:\WINDOWS\ServicePackFiles\i386\oschoice.exe
      + 2008-04-14 00:12:31215,552------wC:\WINDOWS\ServicePackFiles\i386\osk.exe
      + 2008-04-13 18:31:43230,400------wC:\WINDOWS\ServicePackFiles\i386\osloader.exe
      + 2008-04-14 00:12:0267,584------wC:\WINDOWS\ServicePackFiles\i386\osuninst.dll
      + 2008-04-14 00:12:02153,600------wC:\WINDOWS\ServicePackFiles\i386\p2p.dll
      + 2008-04-14 00:12:02105,472------wC:\WINDOWS\ServicePackFiles\i386\p2pgasvc.dll
      + 2008-04-14 00:12:02313,856------wC:\WINDOWS\ServicePackFiles\i386\p2pgraph.dll
      + 2008-04-14 00:12:02115,712------wC:\WINDOWS\ServicePackFiles\i386\p2pnetsh.dll
      + 2008-04-14 00:12:02554,496------wC:\WINDOWS\ServicePackFiles\i386\p2psvc.dll
      + 2008-04-13 18:31:3142,752------wC:\WINDOWS\ServicePackFiles\i386\p3.sys
      + 2008-04-14 00:12:3158,368------wC:\WINDOWS\ServicePackFiles\i386\packager.exe
      + 2008-04-13 18:40:1080,128------wC:\WINDOWS\ServicePackFiles\i386\parport.sys
      + 2008-04-13 18:40:4919,712------wC:\WINDOWS\ServicePackFiles\i386\partmgr.sys
      + 2008-04-14 00:12:0267,584------wC:\WINDOWS\ServicePackFiles\i386\pautoenr.dll
      + 2004-08-04 03:31:2429,502------wC:\WINDOWS\ServicePackFiles\i386\pca200e.sys
      + 2008-04-14 00:12:02102,912------wC:\WINDOWS\ServicePackFiles\i386\pchshell.dll
      + 2008-04-14 00:12:0238,400------wC:\WINDOWS\ServicePackFiles\i386\pchsvc.dll
      + 2008-04-13 18:36:4468,224------wC:\WINDOWS\ServicePackFiles\i386\pci.sys
      + 2008-04-13 18:40:2924,960------wC:\WINDOWS\ServicePackFiles\i386\pciidex.sys
      + 2007-05-15 08:08:11288,768------wC:\WINDOWS\ServicePackFiles\i386\pcl4res.dll
      + 2007-05-15 08:08:131,058,816------wC:\WINDOWS\ServicePackFiles\i386\pcl5eres.dll
      + 2007-05-15 08:08:141,057,280------wC:\WINDOWS\ServicePackFiles\i386\pcl5ures.dll
      + 2007-05-15 08:08:14207,872------wC:\WINDOWS\ServicePackFiles\i386\pclxl.dll
      + 2008-04-13 18:36:43120,192------wC:\WINDOWS\ServicePackFiles\i386\pcmcia.sys
      + 2004-08-04 03:06:18169,984------wC:\WINDOWS\ServicePackFiles\i386\pcx500.sys
      + 2008-04-14 00:12:02284,160------wC:\WINDOWS\ServicePackFiles\i386\pdh.dll
      + 2008-04-14 00:12:0239,936------wC:\WINDOWS\ServicePackFiles\i386\perfctrs.dll
      + 2008-04-14 00:12:0226,624------wC:\WINDOWS\ServicePackFiles\i386\perfdisk.dll
      + 2008-04-14 00:12:3115,872------wC:\WINDOWS\ServicePackFiles\i386\perfmon.exe
      + 2008-04-14 00:12:0217,920------wC:\WINDOWS\ServicePackFiles\i386\perfnet.dll
      + 2008-04-14 00:12:0225,088------wC:\WINDOWS\ServicePackFiles\i386\perfos.dll
      + 2008-04-14 00:12:0234,816------wC:\WINDOWS\ServicePackFiles\i386\perfproc.dll
      + 2008-04-13 18:44:2927,904------wC:\WINDOWS\ServicePackFiles\i386\perm2.sys
      + 2008-04-14 00:10:34211,584------wC:\WINDOWS\ServicePackFiles\i386\perm2dll.dll
      + 2008-04-13 18:44:3028,032------wC:\WINDOWS\ServicePackFiles\i386\perm3.sys
      + 2008-04-14 00:10:34259,328------wC:\WINDOWS\ServicePackFiles\i386\perm3dd.dll
      + 2008-04-14 00:12:02176,128------wC:\WINDOWS\ServicePackFiles\i386\photowiz.dll
      + 2008-04-14 00:12:0235,328------wC:\WINDOWS\ServicePackFiles\i386\pid.dll
      + 2008-04-13 18:35:2224,064------wC:\WINDOWS\ServicePackFiles\i386\pidgen.dll
      + 2008-04-14 00:12:31281,088------wC:\WINDOWS\ServicePackFiles\i386\pinball.exe
      + 2008-04-14 00:12:3117,920------wC:\WINDOWS\ServicePackFiles\i386\ping.exe
      + 2008-04-14 00:12:0215,360------wC:\WINDOWS\ServicePackFiles\i386\pjlmon.dll
      + 2008-04-14 00:12:0244,544------wC:\WINDOWS\ServicePackFiles\i386\plotter.dll
      + 2008-04-14 00:12:0252,736------wC:\WINDOWS\ServicePackFiles\i386\plotui.dll
      + 2008-04-14 00:12:02412,160------wC:\WINDOWS\ServicePackFiles\i386\pmh.dll
      + 2008-04-14 00:12:0239,424------wC:\WINDOWS\ServicePackFiles\i386\pngfilt.dll
      + 2008-04-14 00:12:0258,880------wC:\WINDOWS\ServicePackFiles\i386\pnrpnsp.dll
      + 2008-04-14 00:12:02105,472------wC:\WINDOWS\ServicePackFiles\i386\polstore.dll
      + 2008-04-13 19:19:41146,048------wC:\WINDOWS\ServicePackFiles\i386\portcls.sys
      + 2008-04-14 00:12:3149,152------wC:\WINDOWS\ServicePackFiles\i386\powercfg.exe
      + 2008-04-13 18:40:568,832------wC:\WINDOWS\ServicePackFiles\i386\powerfil.sys
      + 2008-04-14 00:12:0317,408------wC:\WINDOWS\ServicePackFiles\i386\powrprof.dll
      + 2008-04-13 18:41:0017,664------wC:\WINDOWS\ServicePackFiles\i386\ppa3.sys
      + 2008-04-14 00:12:03560,640------wC:\WINDOWS\ServicePackFiles\i386\printui.dll
      + 2008-04-13 18:31:3035,840------wC:\WINDOWS\ServicePackFiles\i386\processr.sys
      + 2008-04-14 00:12:0327,648------wC:\WINDOWS\ServicePackFiles\i386\profmap.dll
      + 2008-04-14 00:12:31109,568------wC:\WINDOWS\ServicePackFiles\i386\progman.exe
      + 2008-04-14 00:12:3250,176------wC:\WINDOWS\ServicePackFiles\i386\proquota.exe
      + 2008-04-14 00:12:03237,056------wC:\WINDOWS\ServicePackFiles\i386\provthrd.dll
      + 2008-04-14 00:12:329,216------wC:\WINDOWS\ServicePackFiles\i386\proxycfg.exe
      + 2008-04-14 00:12:03728,576------wC:\WINDOWS\ServicePackFiles\i386\ps5ui.dll
      + 2008-04-14 00:12:0323,040------wC:\WINDOWS\ServicePackFiles\i386\psapi.dll
      + 2008-04-14 00:12:0396,768------wC:\WINDOWS\ServicePackFiles\i386\psbase.dll
      + 2008-04-13 18:56:3869,120------wC:\WINDOWS\ServicePackFiles\i386\psched.sys
      + 2008-04-14 00:12:03543,232------wC:\WINDOWS\ServicePackFiles\i386\pscript5.dll
      + 2008-04-14 00:12:03363,520------wC:\WINDOWS\ServicePackFiles\i386\psisdecd.dll
      + 2008-04-14 00:12:0343,520------wC:\WINDOWS\ServicePackFiles\i386\pstorec.dll
      + 2008-04-14 00:12:0334,304------wC:\WINDOWS\ServicePackFiles\i386\pstorsvc.dll
      + 2008-04-14 00:12:03159,232------wC:\WINDOWS\ServicePackFiles\i386\ptpusd.dll
      + 2008-04-14 00:12:03150,528------wC:\WINDOWS\ServicePackFiles\i386\qagent.dll
      + 2008-04-14 00:12:03291,328------wC:\WINDOWS\ServicePackFiles\i386\qagentrt.dll
      + 2008-04-14 00:12:03237,568------wC:\WINDOWS\ServicePackFiles\i386\qasf.dll
      + 2008-04-14 00:12:03192,512------wC:\WINDOWS\ServicePackFiles\i386\qcap.dll
      + 2008-04-14 00:12:0362,464------wC:\WINDOWS\ServicePackFiles\i386\qcliprov.dll
      + 2008-04-14 00:12:03279,040------wC:\WINDOWS\ServicePackFiles\i386\qdv.dll
      + 2008-04-14 00:12:03386,048------wC:\WINDOWS\ServicePackFiles\i386\qdvd.dll
      + 2008-04-14 00:12:03562,176------wC:\WINDOWS\ServicePackFiles\i386\qedit.dll
      + 2008-04-13 17:21:32733,696------wC:\WINDOWS\ServicePackFiles\i386\qedwipes.dll
      + 2008-04-13 18:40:526,016------wC:\WINDOWS\ServicePackFiles\i386\qic157.sys
      + 2008-04-14 00:12:03409,088------wC:\WINDOWS\ServicePackFiles\i386\qmgr.dll
      + 2008-04-14 00:12:0318,944------wC:\WINDOWS\ServicePackFiles\i386\qmgrprxy.dll
      + 2008-04-14 00:12:3219,968------wC:\WINDOWS\ServicePackFiles\i386\qprocess.exe
      + 2008-04-14 00:12:031,288,192------wC:\WINDOWS\ServicePackFiles\i386\quartz.dll
      + 2008-04-14 00:12:031,435,648------wC:\WINDOWS\ServicePackFiles\i386\query.dll
      + 2008-04-14 00:12:0376,800------wC:\WINDOWS\ServicePackFiles\i386\qutil.dll
      + 2008-04-14 00:12:0343,520------wC:\WINDOWS\ServicePackFiles\i386\racpldlg.dll
      + 2008-04-13 18:41:2320,736------wC:\WINDOWS\ServicePackFiles\i386\ramdisk.sys
      + 2008-04-14 00:12:037,680------wC:\WINDOWS\ServicePackFiles\i386\rasadhlp.dll
      + 2008-04-14 00:12:03237,056------wC:\WINDOWS\ServicePackFiles\i386\rasapi32.dll
      + 2008-04-14 00:12:0388,576------wC:\WINDOWS\ServicePackFiles\i386\rasauto.dll
      + 2008-04-14 00:12:0379,872------wC:\WINDOWS\ServicePackFiles\i386\raschap.dllYou can just UPLOAD it here http://savefile.com/

      Post the LINK to it BACK here.

      2140.

      Solve : google and search engine virus.?

      Answer»

      I seemed to have picked up a virus possible from a rapidshare file. whenever i try and click a link found from google i am redirected to spyware/advertisment site. Everytime i restart my computer my windows file wall is disabled. interent explorer does not load at all it just freezes my computer. i have tried to open both spy bot and ad aware but they wont work it says they cant connect to server. also when i try and acess the site to download them again it will not let me on to any antivirus/spyware website. I have a basic understanding of computers but this is a little over my head. any help would be areally appreciated. if i reformat the disk what are the chances of the virus still being there. I am using a fujisiemens computer running xp. thanks for you help emilyi have done a malwarebytes scan and this is the results

      Malwarebytes' Anti-Malware 1.28
      Database version: 1222
      Windows 5.1.2600 Service Pack 2

      30/09/2008 01:22:40
      mbam-log-2008-09-30 (01-22-40).txt

      Scan type: Quick Scan
      Objects scanned: 48018
      Time elapsed: 11 minute(s), 41 second(s)

      Memory Processes Infected: 1
      Memory Modules Infected: 0
      Registry Keys Infected: 2
      Registry Values Infected: 1
      Registry Data Items Infected: 2
      Folders Infected: 0
      Files Infected: 7

      Memory Processes Infected:
      C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\ (Trojan.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\tdssinit.dll (Rootkit.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\tdssmain.dll (Rootkit.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\tdssserf.dll (Rootkit.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\drivers\tdssserv.sys (Rootkit.Agent) -> Delete on reboot.
      Download TrendMicro HijackThis.exe (HJT) to the Desktop.

      • Double-click on HJTInstall.
      • Click on the Install button.
      • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
      • Upon install, HijackThis should open for you.
      • Click on the Do a system scan and save a log file button
      • HijackThis will scan and then a log will open in notepad.
      • Copy and then paste the entire contents of the log in your post.
      • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
      here are the results for hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 01:40:35, on 30/09/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\a-squared Free\a2service.exe
      C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      C:\WINDOWS\system32\CTsvcCDA.exe
      C:\Program Files\FolderSize\FolderSizeSvc.exe
      C:\Program Files\Kontiki\KService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\StkASv2K.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      C:\WINDOWS\sm56hlpr.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\update\update.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/iplayer
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
      O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
      O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
      O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
      O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
      O4 - HKCU\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
      O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
      O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)
      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

      --
      End of file - 7509 bytesDownload ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

      Also let me know how things are now.here is the report. thinks seem to be running better no longer have the problem with google. what do you think the problem was?

      ComboFix 08-09-28.03 - e 2008-09-30 2:16:31.2 - NTFSx86
      Running from: C:\Documents and Settings\e\Desktop\ComboFix.exe

      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      ---- Previous Run -------
      .
      C:\WINDOWS\system32\TDSSadw.dll
      C:\WINDOWS\system32\TDSSerrors.log
      C:\WINDOWS\system32\tdssl.dll
      C:\WINDOWS\system32\tdsslog.dll
      C:\WINDOWS\system32\TDSSserf1.dll
      C:\WINDOWS\system32\tdssservers.dat

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_TDSSSERV
      -------\Service_TDSSserv


      ((((((((((((((((((((((((( Files CREATED from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
      .

      2008-09-30 01:43 . 2008-09-30 01:43d--------C:\Program Files\SUPERAntiSpyware
      2008-09-30 01:42 . 2008-09-30 01:42d--------C:\Program Files\Common Files\Wise Installation Wizard
      2008-09-30 01:39 . 2008-09-30 01:39d--------C:\Program Files\Trend Micro
      2008-09-30 01:39 . 2008-06-10 02:3273,728--a------C:\WINDOWS\system32\javacpl.cpl
      2008-09-30 01:24 . 2008-09-30 01:2461,440--a------C:\WINDOWS\system32\drivers\sbalb.sys
      2008-09-30 00:04 . 2008-09-30 02:16d--------C:\WINDOWS\system32\CatRoot_bak
      2008-09-28 18:29 . 2008-09-28 18:29d--------C:\Program Files\Ares
      2008-09-28 12:52 . 2008-09-30 02:0054,156--ah-----C:\WINDOWS\QTFont.qfn
      2008-09-28 12:52 . 2008-09-28 12:521,409--a------C:\WINDOWS\QTFont.for
      2008-09-24 09:00 . 2008-09-24 09:00d--------C:\Program Files\TeaTimer (Spybot - Search & Destroy)
      2008-09-17 15:45 . 2008-09-17 15:45d--------C:\Program Files\Cucusoft
      2008-09-17 15:45 . 2008-09-17 15:45d--------C:\ConverterOutput
      2008-09-17 15:45 . 2003-03-30 20:08372,736--a------C:\WINDOWS\system32\xvid.ax
      2008-09-17 13:45 . 2008-09-17 15:36d--------C:\Documents and Settings\e\Application Data\Creative
      2008-09-17 13:35 . 2006-10-05 23:1753,248---------C:\WINDOWS\Ctregrun.exe
      2008-09-17 13:34 . 2008-09-17 13:34d--------C:\Program Files\Audible
      2008-09-17 13:34 . 2008-09-17 13:34417,792--a------C:\WINDOWS\system32\awrdscdc.ax
      2008-09-17 13:33 . 2008-09-17 13:43d--------C:\Documents and Settings\All Users\Application Data\Creative
      2008-09-17 13:31 . 2008-09-17 13:33d--h-----C:\Program Files\Creative Installation Information
      2008-09-17 13:31 . 2008-09-17 13:35d--------C:\Program Files\Creative
      2008-09-17 13:31 . 2008-09-17 13:31d--------C:\Program Files\Common Files\Creative
      2008-09-17 13:31 . 1999-12-12 18:0144,032---------C:\WINDOWS\system32\CTSVCCDA.EXE
      2008-09-17 13:31 . 1999-11-17 18:0025,088---------C:\WINDOWS\system32\CTSVCCTL.EXE
      2008-09-17 00:36 . 2008-09-17 00:36d--------C:\Program Files\Alwil Software
      2008-09-16 22:41 . 2007-05-02 09:51d--------C:\Documents and Settings\Administrator\Application Data\InterVideo
      2008-09-16 22:41 . 2008-09-16 22:54d--------C:\Documents and Settings\Administrator
      2008-09-16 17:17 . 2008-09-16 17:17d--------C:\Program Files\NCH Software
      2008-09-16 11:09 . 2008-09-29 23:45d--------C:\Program Files\a-squared Free
      2008-09-16 10:59 . 2008-09-16 10:59d--------C:\Documents and Settings\All Users\Application Data\PC Tools
      2008-09-16 10:59 . 2008-04-24 16:5212,608--a------C:\WINDOWS\system32\drivers\TfKbMon.sys
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Program Files\Malwarebytes' Anti-Malware
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Documents and Settings\e\Application Data\Malwarebytes
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-16 10:58 . 2008-09-10 00:0438,528--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-09-16 10:58 . 2008-09-10 00:0317,200--a------C:\WINDOWS\system32\drivers\mbam.sys
      2008-09-16 10:54 . 2008-09-16 10:54d--------C:\Documents and Settings\e\Application Data\SUPERAntiSpyware.com
      2008-09-16 10:54 . 2008-09-16 10:54d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
      2008-09-16 10:31 . 2008-09-16 22:56d--------C:\Documents and Settings\All Users\Application Data\avg8
      2008-09-10 18:01 . 2008-09-17 15:11d--------C:\Program Files\FlashGet
      2008-09-10 17:31 . 2008-09-17 15:10d--------C:\downloads
      2008-09-10 17:31 . 2008-09-10 17:58d--------C:\Documents and Settings\e\Application Data\Orbit
      2008-09-10 17:31 . 2008-09-10 17:43d--------C:\Documents and Settings\e\Application Data\GrabPro
      2008-09-09 11:58 . 2008-09-09 11:58d--------C:\Program Files\7-Zip
      2008-09-09 10:04 . 2008-09-09 10:04d--------C:\Program Files\uTorrent
      2008-09-09 10:04 . 2008-09-27 12:04d--------C:\Documents and Settings\e\Application Data\uTorrent
      2008-09-08 18:18 . 2008-04-08 00:169,200---------C:\WINDOWS\system32\drivers\cdralw2k.sys
      2008-09-08 18:18 . 2008-04-08 00:169,072---------C:\WINDOWS\system32\drivers\cdr4_xp.sys
      2008-09-08 18:17 . 2008-09-08 18:17d--------C:\WINDOWS\system32\IOSUBSYS
      2008-09-08 15:11 . 2008-09-08 15:11d--------C:\Program Files\Siber Systems
      2008-09-08 15:11 . 2008-09-08 15:11d--------C:\Documents and Settings\All Users\Application Data\RoboForm
      2008-09-08 14:46 . 2008-09-08 16:35d--------C:\Documents and Settings\e\Pavark
      2008-09-07 14:32 . 2008-09-07 14:35d--------C:\Program Files\JkDefragGUI
      2008-09-07 14:32 . 2008-08-31 21:47238,592--a------C:\WINDOWS\system32\JkDefragScreenSaver.exe
      2008-09-07 14:32 . 2008-08-31 21:4798,304--a------C:\WINDOWS\system32\JkDefragScreenSaver.scr
      2008-08-29 18:18 . 2008-08-29 18:182,302,017--a------C:\WINDOWS\system32\GPhotos.scr
      2008-08-15 18:07 . 2008-08-15 18:0731,232--a------C:\WINDOWS\system\vdremote.dll
      2008-08-15 18:07 . 2008-08-15 18:0725,088--a------C:\WINDOWS\system\vdsvrlnk.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-09-30 01:21---------d-----wC:\Documents and Settings\All Users\Application Data\Kontiki
      2008-09-30 00:39---------d-----wC:\Program Files\Java
      2008-09-29 22:45---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-09-20 18:53---------d--h--wC:\Program Files\InstallShield Installation Information
      2008-09-16 23:16---------d-----wC:\Documents and Settings\e\Application Data\Skype
      2008-09-16 23:13---------d-----wC:\Documents and Settings\e\Application Data\skypePM
      2008-09-16 22:24---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP
      2008-09-16 22:24---------d-----wC:\Program Files\SpywareBlaster
      2008-09-16 22:03---------d-----wC:\Program Files\RegScrubXP
      2008-09-16 09:32---------d-----wC:\Program Files\DivX
      2008-09-16 09:28---------d-----wC:\Program Files\Yahoo!
      2008-09-16 09:25---------d-----wC:\Documents and Settings\All Users\Application Data\Grisoft
      2008-09-08 17:17---------d-----wC:\Program Files\Google
      2008-09-07 11:49---------d-----wC:\Documents and Settings\e\Application Data\DNA
      2008-09-06 14:40---------d-----wC:\Program Files\DNA
      2008-03-11 23:2132----a-wC:\Documents and Settings\All Users\Application Data\ezsid.dat
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "VIDC.I420"= i420vfw.dll
      "vidc.yv12"= yv12vfw.dll
      "vidc.CDVC"= cdvccodc.dll

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
      backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
      backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
      backup=C:\WINDOWS\pss\Printkey2000.lnkCommon Startup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
      --a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
      --a------ 2005-09-09 01:18 57344 C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
      --a------ 2006-12-01 18:10 286720 C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
      --------- 2007-11-06 11:08 397312 C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
      --------- 2006-10-05 23:17 53248 C:\WINDOWS\Ctregrun.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
      --------- 2007-07-17 11:03 868352 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
      --a------ 2008-01-04 15:43 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
      --a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      --------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
      --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      --a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
      -ra------ 2008-02-01 18:22 21898024 C:\Program Files\Skype\Phone\Skype.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
      --a------ 2006-11-02 13:43 472632 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      --a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
      --a------ 2008-09-03 14:07 1576176 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
      --a------ 2008-01-04 15:42 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
      --a------ 2007-11-13 16:48 3411968 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
      --a------ 2005-11-10 04:44 557056 C:\WINDOWS\sm56hlpr.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
      --a------ 2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
      --a------ 2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
      --a------ 2005-11-01 04:15 163840 C:\WINDOWS\system32\VTTrayp.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "SSScsiSV"=3 (0x3)
      "avg8wd"=2 (0x2)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "C:\\Program Files\\uTorrent\\uTorrent.exe"=
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
      "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
      "C:\\WINDOWS\\system32\\java.exe"=
      "C:\\Program Files\\Ares\\Ares.exe"=

      R1 aswSP;avast! SELF Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
      R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
      R2 StkASSrv;Syntek STK1160 Service;C:\WINDOWS\System32\StkASv2K.exe [2006-05-23 24576]
      R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys [2005-01-14 5504]
      S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service [ ]
      S3 Mouqmmr;Mouqmmr;C:\WINDOWS\system32\blastcln.exe [2004-08-04 71680]
      S3 StkAMini;Syntek STK1160;C:\WINDOWS\system32\Drivers\StkAMini.sys [2006-11-15 242139]
      S3 StkScan;Syntek STK1160 Still Image;C:\WINDOWS\system32\Drivers\StkScan.sys [2006-06-27 4772]
      .
      - - - - ORPHANS REMOVED - - - -

      MSConfigStartUp-!AVG Anti-Spyware - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      MSConfigStartUp-AVG8_TRAY - C:\PROGRA~1\AVG\AVG8\avgtray.exe
      MSConfigStartUp-ThreatFire - C:\Program Files\ThreatFire\TFTray.exe


      .
      ------- Supplementary Scan -------
      .
      FireFox -: Profile - C:\Documents and Settings\e\Application Data\Mozilla\Firefox\Profiles\o83xzkld.default\
      FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.uk/
      FF -: plugin - C:\Documents and Settings\e\Application Data\Mozilla\Firefox\Profiles\o83xzkld.default\extensions\[emailprotected]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
      FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
      FF -: plugin - C:\Program Files\Google\Picasa3\npPicasa3.dll
      FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
      FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
      FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
      .

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-09-30 02:21:49
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      Completion time: 2008-09-30 2:28:22
      ComboFix-quarantined-files.txt 2008-09-30 01:28:15

      Pre-Run: 20,696,715,264 bytes free
      Post-Run: 21,159,137,280 bytes free

      214--- E O F ---2008-09-29 23:07:00
      Quote
      what do you think the problem was?

      Clicked a bad link...opened an infected email attachment...bad codec.... the possibilities are many.

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      Driver::
      TDSSSERV
      TDSSserv
      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezehere is the results

      ComboFix 08-09-28.03 - e 2008-09-30 2:50:14.3 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.184 [GMT 1:00]
      Running from: C:\Documents and Settings\e\Desktop\ComboFix.exe
      Command switches used :: C:\Documents and Settings\e\Desktop\CFScript.txt
      * Created a new restore point

      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .

      ((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
      .

      2008-09-30 01:43 . 2008-09-30 01:43d--------C:\Program Files\SUPERAntiSpyware
      2008-09-30 01:42 . 2008-09-30 01:42d--------C:\Program Files\Common Files\Wise Installation Wizard
      2008-09-30 01:39 . 2008-09-30 01:39d--------C:\Program Files\Trend Micro
      2008-09-30 01:39 . 2008-06-10 02:3273,728--a------C:\WINDOWS\system32\javacpl.cpl
      2008-09-30 01:24 . 2008-09-30 01:2461,440--a------C:\WINDOWS\system32\drivers\sbalb.sys
      2008-09-30 00:04 . 2008-09-30 02:16d--------C:\WINDOWS\system32\CatRoot_bak
      2008-09-28 18:29 . 2008-09-28 18:29d--------C:\Program Files\Ares
      2008-09-24 09:00 . 2008-09-24 09:00d--------C:\Program Files\TeaTimer (Spybot - Search & Destroy)
      2008-09-17 15:45 . 2008-09-17 15:45d--------C:\Program Files\Cucusoft
      2008-09-17 15:45 . 2008-09-17 15:45d--------C:\ConverterOutput
      2008-09-17 15:45 . 2003-03-30 20:08372,736--a------C:\WINDOWS\system32\xvid.ax
      2008-09-17 13:45 . 2008-09-17 15:36d--------C:\Documents and Settings\e\Application Data\Creative
      2008-09-17 13:35 . 2006-10-05 23:1753,248---------C:\WINDOWS\Ctregrun.exe
      2008-09-17 13:34 . 2008-09-17 13:34d--------C:\Program Files\Audible
      2008-09-17 13:34 . 2008-09-17 13:34417,792--a------C:\WINDOWS\system32\awrdscdc.ax
      2008-09-17 13:33 . 2008-09-17 13:43d--------C:\Documents and Settings\All Users\Application Data\Creative
      2008-09-17 13:31 . 2008-09-17 13:33d--h-----C:\Program Files\Creative Installation Information
      2008-09-17 13:31 . 2008-09-17 13:35d--------C:\Program Files\Creative
      2008-09-17 13:31 . 2008-09-17 13:31d--------C:\Program Files\Common Files\Creative
      2008-09-17 13:31 . 1999-12-12 18:0144,032---------C:\WINDOWS\system32\CTSVCCDA.EXE
      2008-09-17 13:31 . 1999-11-17 18:0025,088---------C:\WINDOWS\system32\CTSVCCTL.EXE
      2008-09-17 00:36 . 2008-09-17 00:36d--------C:\Program Files\Alwil Software
      2008-09-16 22:41 . 2007-05-02 09:51d--------C:\Documents and Settings\Administrator\Application Data\InterVideo
      2008-09-16 22:41 . 2008-09-16 22:54d--------C:\Documents and Settings\Administrator
      2008-09-16 17:17 . 2008-09-16 17:17d--------C:\Program Files\NCH Software
      2008-09-16 11:09 . 2008-09-29 23:45d--------C:\Program Files\a-squared Free
      2008-09-16 10:59 . 2008-09-16 10:59d--------C:\Documents and Settings\All Users\Application Data\PC Tools
      2008-09-16 10:59 . 2008-04-24 16:5212,608--a------C:\WINDOWS\system32\drivers\TfKbMon.sys
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Program Files\Malwarebytes' Anti-Malware
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Documents and Settings\e\Application Data\Malwarebytes
      2008-09-16 10:58 . 2008-09-16 10:58d--------C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-09-16 10:58 . 2008-09-10 00:0438,528--a------C:\WINDOWS\system32\drivers\mbamswissarmy.sys
      2008-09-16 10:58 . 2008-09-10 00:0317,200--a------C:\WINDOWS\system32\drivers\mbam.sys
      2008-09-16 10:54 . 2008-09-16 10:54d--------C:\Documents and Settings\e\Application Data\SUPERAntiSpyware.com
      2008-09-16 10:54 . 2008-09-16 10:54d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
      2008-09-16 10:31 . 2008-09-16 22:56d--------C:\Documents and Settings\All Users\Application Data\avg8
      2008-09-10 18:01 . 2008-09-17 15:11d--------C:\Program Files\FlashGet
      2008-09-10 17:31 . 2008-09-17 15:10d--------C:\downloads
      2008-09-10 17:31 . 2008-09-10 17:58d--------C:\Documents and Settings\e\Application Data\Orbit
      2008-09-10 17:31 . 2008-09-10 17:43d--------C:\Documents and Settings\e\Application Data\GrabPro
      2008-09-09 11:58 . 2008-09-09 11:58d--------C:\Program Files\7-Zip
      2008-09-09 10:04 . 2008-09-09 10:04d--------C:\Program Files\uTorrent
      2008-09-09 10:04 . 2008-09-27 12:04d--------C:\Documents and Settings\e\Application Data\uTorrent
      2008-09-08 18:18 . 2008-04-08 00:169,200---------C:\WINDOWS\system32\drivers\cdralw2k.sys
      2008-09-08 18:18 . 2008-04-08 00:169,072---------C:\WINDOWS\system32\drivers\cdr4_xp.sys
      2008-09-08 18:17 . 2008-09-08 18:17d--------C:\WINDOWS\system32\IOSUBSYS
      2008-09-08 15:11 . 2008-09-08 15:11d--------C:\Program Files\Siber Systems
      2008-09-08 15:11 . 2008-09-08 15:11d--------C:\Documents and Settings\All Users\Application Data\RoboForm
      2008-09-08 14:46 . 2008-09-08 16:35d--------C:\Documents and Settings\e\Pavark
      2008-09-07 14:32 . 2008-09-07 14:35d--------C:\Program Files\JkDefragGUI
      2008-09-07 14:32 . 2008-08-31 21:47238,592--a------C:\WINDOWS\system32\JkDefragScreenSaver.exe
      2008-09-07 14:32 . 2008-08-31 21:4798,304--a------C:\WINDOWS\system32\JkDefragScreenSaver.scr
      2008-08-29 18:18 . 2008-08-29 18:182,302,017--a------C:\WINDOWS\system32\GPhotos.scr
      2008-08-15 18:07 . 2008-08-15 18:0731,232--a------C:\WINDOWS\system\vdremote.dll
      2008-08-15 18:07 . 2008-08-15 18:0725,088--a------C:\WINDOWS\system\vdsvrlnk.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-09-30 01:55---------d-----wC:\Documents and Settings\All Users\Application Data\Kontiki
      2008-09-30 00:39---------d-----wC:\Program Files\Java
      2008-09-29 22:45---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-09-20 18:53---------d--h--wC:\Program Files\InstallShield Installation Information
      2008-09-16 23:16---------d-----wC:\Documents and Settings\e\Application Data\Skype
      2008-09-16 23:13---------d-----wC:\Documents and Settings\e\Application Data\skypePM
      2008-09-16 22:24---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP
      2008-09-16 22:24---------d-----wC:\Program Files\SpywareBlaster
      2008-09-16 22:03---------d-----wC:\Program Files\RegScrubXP
      2008-09-16 09:32---------d-----wC:\Program Files\DivX
      2008-09-16 09:28---------d-----wC:\Program Files\Yahoo!
      2008-09-16 09:25---------d-----wC:\Documents and Settings\All Users\Application Data\Grisoft
      2008-09-08 17:17---------d-----wC:\Program Files\Google
      2008-09-07 11:49---------d-----wC:\Documents and Settings\e\Application Data\DNA
      2008-09-06 14:40---------d-----wC:\Program Files\DNA
      2008-03-11 23:2132----a-wC:\Documents and Settings\All Users\Application Data\ezsid.dat
      .

      ((((((((((((((((((((((((((((( [emailprotected]_ 2.27.54.32 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2008-09-30 01:53:5016,384----atwC:\WINDOWS\Temp\Perflib_Perfdata_564.dat
      + 2008-09-30 01:53:5716,384----atwC:\WINDOWS\Temp\Perflib_Perfdata_7cc.dat
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "VIDC.I420"= i420vfw.dll
      "vidc.yv12"= yv12vfw.dll
      "vidc.CDVC"= cdvccodc.dll

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
      backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
      backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
      backup=C:\WINDOWS\pss\Printkey2000.lnkCommon Startup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
      --a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
      --a------ 2005-09-09 01:18 57344 C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
      --a------ 2006-12-01 18:10 286720 C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
      --------- 2007-11-06 11:08 397312 C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
      --------- 2006-10-05 23:17 53248 C:\WINDOWS\Ctregrun.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
      --------- 2007-07-17 11:03 868352 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
      --a------ 2008-01-04 15:43 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
      --a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      --------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
      --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      --a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
      -ra------ 2008-02-01 18:22 21898024 C:\Program Files\Skype\Phone\Skype.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
      --a------ 2006-11-02 13:43 472632 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      --a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
      --a------ 2008-09-03 14:07 1576176 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
      --a------ 2008-01-04 15:42 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
      --a------ 2007-11-13 16:48 3411968 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
      --a------ 2005-11-10 04:44 557056 C:\WINDOWS\sm56hlpr.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
      --a------ 2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
      --a------ 2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
      --a------ 2005-11-01 04:15 163840 C:\WINDOWS\system32\VTTrayp.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "SSScsiSV"=3 (0x3)
      "avg8wd"=2 (0x2)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "C:\\Program Files\\uTorrent\\uTorrent.exe"=
      "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
      "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
      "C:\\WINDOWS\\system32\\java.exe"=
      "C:\\Program Files\\Ares\\Ares.exe"=

      R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
      R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
      R2 StkASSrv;Syntek STK1160 Service;C:\WINDOWS\System32\StkASv2K.exe [2006-05-23 24576]
      R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys [2005-01-14 5504]
      S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service [ ]
      S3 Mouqmmr;Mouqmmr;C:\WINDOWS\system32\blastcln.exe [2004-08-04 71680]
      S3 StkAMini;Syntek STK1160;C:\WINDOWS\system32\Drivers\StkAMini.sys [2006-11-15 242139]
      S3 StkScan;Syntek STK1160 Still Image;C:\WINDOWS\system32\Drivers\StkScan.sys [2006-06-27 4772]
      .

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-09-30 02:54:19
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      ------------------------ Other Running Processes ------------------------
      .
      C:\WINDOWS\system32\WLTRYSVC.EXE
      C:\WINDOWS\system32\BCMWLTRY.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\a-squared Free\a2service.exe
      C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
      C:\WINDOWS\system32\CTSVCCDA.EXE
      C:\Program Files\FolderSize\FolderSizeSvc.exe
      C:\Program Files\Kontiki\KService.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      .
      **************************************************************************
      .
      Completion time: 2008-09-30 3:01:14 - machine was rebooted [e]
      ComboFix-quarantined-files.txt 2008-09-30 02:01:05
      ComboFix2.txt 2008-09-30 01:28:24

      Pre-Run: 21,082,935,296 bytes free
      Post-Run: 21,078,179,840 bytes free

      205--- E O F ---2008-09-29 23:07:00


      thanks for your help so far
        Looks GOOD. Things running OK now?

        • Click START then RUN
        • Now type Combofix /u in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.

      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Remove the old versions of Java

      • Download JavaRa and unzip the file to your Desktop.
      • Open JavaRA.exe and choose Remove Older Versions
      • Once complete exit JavaRA and delete the program.
      • Run CCleaner.
      .
      ----------

      If you don't have CCleaner...

      Download CCleaner Slim and save it to your Desktop.
      When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
      Follow the prompts to install the program.
      Complete the installation then:

      • Double-click the CCleaner shortcut on the desktop to start the program.
      • Click on the Options block on the left, then choose Cookies.
        • Under Cookies to Delete, highlight any cookies you would like to retain permanently
        • Click the right arrow > to move them to the Cookies to Keep window.
      • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
      • Click Cleaner on the left then Run Cleaner on the right to run the program.
      • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
      • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
      • Exit CCleaner after it has completed its process.
      .
      ----------

      Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide or Windows Vista System Restore Guide
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. SAFETY ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
      yes i think it is all working again now thanks very much for your help No problem.

      Safe surfing....
      2141.

      Solve : Help with viruses needed!?

      Answer»

      Everything looks pretty good, thank you so much for you help!

      The only thing that is left that seems a bit off is that the clock in the lower right corner is in 24-hour clock format (this changed when I was originally infected), and I'm not sure how to change it BACK to 12-hour.

        • Click START then RUN
        • Now type Combofix /u in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.

      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      1. Double click OTMoveIt2.exe to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup PROCESS?)
      5. Once complete exit out of OTMoveIt2

      ----------

      Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to USE System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide or Windows Vista System Restore Guide
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

      Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

      To prevent unknown applications from being installed on your computer install WinPatrol 2008
      * Using Winpatrol to protect your computer from malicious software

      I SUGGEST using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth."Windows cannot find combofix"
      Do I need to install this first?To change military time to standard time

      Go to Start > Control Panel > Regional and Language Options
      Click the Customize button
      Select the Time tab
      In the Time Format area use the down arrow to select: h:mm:ss tt
      Click Apply
      Click OK
      Click Apply
      Click OK

      Restart the computer.
      2142.

      Solve : Virus in start up??

      Answer»

      seems to WORK a lot faster and less sluggish.

      24 mounted Trojans were picked up and deleted so yeah. It was a good harvest.Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

      • Go to START &GT; Programs > ACCESSORIES > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore GUIDE or Windows Vista System Restore Guide
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.
      2143.

      Solve : VIRUS ALERT! Next to time in system tray. Help Please?

      Answer»

      As said in topic title the first thing I noticed was VIRUS ALERT! Next to time in SYSTEM tray. Then I noticed that I do not have many of my START MENU items such as My Computer, Run, My Documents ect. Here are my logs. I think I almost have it solved.
      Code: [Select]SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 09/28/2008 at 08:18 PM

      Application Version : 4.21.1004a

      Core Rules Database Version : 3581
      Trace Rules Database Version: 1569

      Scan type : Complete Scan
      Total Scan Time : 02:34:31

      Memory items scanned : 398
      Memory threats detected : 0
      Registry items scanned : 7153
      Registry threats detected : 0
      File items scanned : 136160
      File threats detected : 1

      Adware.Vundo Variant/Rel
      I:\WINDOWS\SYSTEM32\MCRH.TMP

      Code: [Select]Malwarebytes' Anti-Malware 1.24
      Database version: 1026
      Windows 5.1.2600 Service Pack 2

      8:39:53 PM 9/28/2008
      mbam-log-9-28-2008 (20-39-53).txt

      Scan type: Quick Scan
      Objects scanned: 41244
      Time elapsed: 6 minute(s), 41 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 1
      Registry Values Infected: 0
      Registry Data Items Infected: 15
      Folders Infected: 0
      Files Infected: 4

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> QUARANTINED and deleted successfully.

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (55274-640-5989533-23289) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (h:mm:ss tt) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      I:\WINDOWS\system32\lmirvdqp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      I:\WINDOWS\system32\pqdvriml.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      I:\WINDOWS\emrg.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      I:\WINDOWS\Temp\cd1fe456-eae2-43a4-b0c1-20bafd75f6a4.tmp (Heuristics.Malware) -> Quarantined and deleted successfully.

      Code: [Select]Logfile of Trend Micro HijackThis v2.0.2
      Scan SAVED at 19:55: VIRUS ALERT!, on 9/28/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      I:\WINDOWS\System32\smss.exe
      I:\WINDOWS\system32\winlogon.exe
      I:\WINDOWS\system32\services.exe
      I:\WINDOWS\system32\lsass.exe
      I:\WINDOWS\system32\svchost.exe
      I:\Program Files\Windows Defender\MsMpEng.exe
      I:\WINDOWS\System32\svchost.exe
      I:\WINDOWS\system32\svchost.exe
      I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      I:\WINDOWS\Explorer.EXE
      I:\WINDOWS\system32\spoolsv.exe
      I:\Program Files\Winamp\winampa.exe
      I:\Documents and Settings\[name]\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      I:\Program Files\WinZip\WZQKPICK.EXE
      I:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      I:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      i:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      i:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      I:\Program Files\McAfee\VirusScan\McShield.exe
      I:\Program Files\McAfee\MPF\MPFSrv.exe
      I:\PROGRA~1\AVG\AVG8\avgam.exe
      I:\WINDOWS\system32\nvsvc32.exe
      I:\WINDOWS\system32\svchost.exe
      I:\PROGRA~1\AVG\AVG8\avgrsx.exe
      I:\PROGRA~1\AVG\AVG8\avgnsx.exe
      i:\PROGRA~1\mcafee.com\agent\mcagent.exe
      I:\PROGRA~1\AVG\AVG8\avgemc.exe
      I:\WINDOWS\system32\wscntfy.exe
      I:\WINDOWS\system32\ctfmon.exe
      I:\WINDOWS\system32\WgaTray.exe
      I:\Program Files\Opera\opera.exe
      I:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      I:\PROGRA~1\MICROS~3\rapimgr.exe
      I:\Program Files\Microsoft ActiveSync\wcescomm.exe
      I:\Documents and Settings\[name]\Desktop\HiJackThis.exe
      I:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      I:\Documents and Settings\[name]\Desktop\sniper.exe

      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - I:\Program Files\McAfee\VirusScan\scriptsn.dll
      O4 - HKLM\..\Run: [WinampAgent] "I:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] I:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [EnGraph QuickTimeKiller] C:\Program Files\EnGraph\QuickTimeKiller\QuickTimeKiller.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "I:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [Google Update] "I:\Documents and Settings\[name]\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "I:\Program Files\Microsoft ActiveSync\wcescomm.exe"
      O4 - Global Startup: WinZip Quick Pick.lnk = I:\Program Files\WinZip\WZQKPICK.EXE
      O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - I:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - I:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - I:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - I:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - i:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - I:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - i:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - I:\Program Files\McAfee\VirusScan\McShield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - I:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - I:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe

      --
      End of file - 4240 bytes
      You didn't take the advice about running two antivirus?McAfee, NOD32, Kasparsky, and AVG.You should only have one antivirus and one firewall installed at any time. If you have two of either installed then uninstall one now before continuing.

      If not uninstalled all but one needs to be disabled to where none of the real time protection is running.

      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - I:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - I:\PROGRA~1\AVG\AVG8\avgwdsvc.exe


      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - I:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - i:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - I:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - i:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - I:\Program Files\McAfee\VirusScan\McShield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - I:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - I:\Program Files\McAfee\MPF\MPFSrv.exe

      2144.

      Solve : virus/malware help needed logs attatched?

      Answer»

      For some reason it seems like my computer has been bogged down and I have ran CCleaner and it still is VERY slow.

      [Saving space - attachment deleted by admin]Go to Add or Remove Programs and uninstall one of the antivirus, either BitDefender or AVG. Running two will just cause problems.

      ----------

      Go to download the program HostsXpert

      • Unzip HostXpert to your Desktop
      • Open up the HostXpert program.
      • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
      • Click Create Back Up
      • Then click on Restore Microsoft's Host Files
      • Close the HostXpert program
      .
      Note: if you use SpywareBlaster, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection they afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

      ----------

      Run this online scan.

      Requires Internet Explorer or Firefox using the IE Tab Add-on

      Use the ESET Nod32 Online Scanner

      1. Check the box next to YES, I accept the Terms of Use.
      2. Click Start
      3. When asked, allow the activex control to install
      4. Click Start
      5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
      6. Click Scan
      7. Wait for the scan to finish
      8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.

      ----------

      Now run a new HijackThis scan and post the log.Okay thanks! Also, when i try to delete bitdefender it says: xcommsvr.exe cannot be deleted access is denied make sure that the disk is not full or write-protected and that the file is not currently in use (which it is not because I deleted it a long time ago)

      [Saving space - attachment deleted by admin]If you don't use it go to add/remove programs and uninstall Ask Search or anything with Ask in the name.

      ----------

      Open HijackThis and select Do a system scan only then place a check mark next to:

      R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
      O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/player/Install3.0/Installer.exe


      ----------

      Download OTMoveIt2 by OldTimer and save it to your Desktop.

      Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

      1. Double-click OTMoveIt2.exe to run it.
      2. Copy the lines in the codebox below.

      Code: [Select][kill explorer]
      C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
      EmptyTemp
      [start explorer]
      3. Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
      4. Click the red Moveit! button.
      5. Copy everything in the Results window (under the green bar) and paste it in your next reply.
      6. Close OTMoveIt2

      ----------

      Use the BitDefender Antivirus Removal Tool: http://www.bitdefender.com/uninstall

      After running it you will need to reboot your computer for the changes to take effect.

      ----------

      How is everything now?ok thanks! but when I try to remove the Ask toolbar thing it gives me that same access is denied thing. Also, When I ran OTmoveit2 for the first time (and ran the code) it froze and I had to restart the program so I dont know if that would affect what the log says but here it is anyways:
      _______________________________________ __________________________
      Unable to kill explorer.exe
      File/Folder C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe not found.
      < EmptyTemp >
      Temp folders emptied.
      IE temp folders emptied.
      Explorer started successfully

      OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09292008_160026
      _______________________________________ __________________________

      Also, do you have any suggestions or programs that would boost my computer speed besides getting more RAM because I have already tried that option lol
      Download ComboFix by sUBs from one of the below LINKS. Be sure top save it to the Desktop.

      LINK #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.ok

      [Saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      - R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
      - O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
      - O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


      Important: Close all windows except for HijackThis and then click Fix checked.

      Exit HijackThis.

      ----------

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      File::
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

      Registry::
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
      "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=-

      [-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

      [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezethanks!

      [Saving space - attachment deleted by admin]
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete:
        • ComboFix and its associated files and folders.
        • VundoFix backups, if present
        • The C:\Deckard folder, if present
        • The C:_OtMoveIt folder, if present
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .
        ----------

        1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you WANT to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first SCREEN then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore SECTION to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
        2145.

        Solve : Computer Viruses and?

        Answer»

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:23:24 PM, on 9/29/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet EXPLORER v7.00 (7.00.6000.16711)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\zHotkey.exe
        C:\Windows\ModPS2Key.exe
        C:\Windows\sttray.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Windows\WindowsMobile\wmdSync.exe
        C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = https://login.yahoo.com/config/mail?.intl=us
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
        O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
        O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
        O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
        O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
        O4 - HKCU\..\Run: [WindowsWelcomeCenter] "rundll32.exe" oobefldr.dll,ShowWelcomeCenter
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
        O9 - Extra 'Tools' MENUITEM: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O17 - HKLM\System\CCS\Services\Tcpip\..\{60805DFF-9EA9-471F-8C39-A0213FDCBBA6}: NameServer = 68.94.156.1 68.94.157.1
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
        O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
        O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
        O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

        --
        End of file - 8022 bytes
        Can you describe what problems you are having?

        2146.

        Solve : Computer acting extremely strange?

        Answer»

        Restart manually.

        The log will be saved in C:\combofix.txtComboFix 08-09-27.01 - Ben 2008-09-27 23:26:45.2 - NTFSx86
        Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.661 [GMT -4:00]
        Running from: E:\Documents and Settings\Ben\Desktop\ComboFix.exe
        Command switches used :: E:\Documents and Settings\Ben\Desktop\CFScript.txt
        * Created a new restore point

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        ((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
        .

        2008-09-27 21:31 . 2008-09-27 21:31d--h-----E:\$AVG8.VAULT$
        2008-09-27 10:31 . 2008-09-27 10:32d--------E:\WINDOWS\ERUNT
        2008-09-27 10:24 . 2008-09-27 10:51d--------E:\SDFix
        2008-09-27 01:15 . 2008-09-27 01:16d--------E:\rsit
        2008-09-27 00:27 . 2008-09-27 00:27d--------E:\Program Files\SUPERAntiSpyware
        2008-09-27 00:27 . 2008-09-27 00:27d--------E:\Documents and Settings\Ben\Application Data\SUPERAntiSpyware.com
        2008-09-27 00:27 . 2008-09-27 00:27d--------E:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
        2008-09-27 00:21 . 2008-09-27 21:35d--------E:\WINDOWS\system32\drivers\Avg
        2008-09-27 00:21 . 2008-09-27 00:21d--------E:\Program Files\AVG
        2008-09-27 00:21 . 2008-09-27 00:24d--------E:\Documents and Settings\All Users\Application Data\avg8
        2008-09-27 00:21 . 2008-09-27 00:2197,928--a------E:\WINDOWS\system32\drivers\avgldx86.sys
        2008-09-27 00:21 . 2008-09-27 00:2176,040--a------E:\WINDOWS\system32\drivers\avgtdix.sys
        2008-09-27 00:21 . 2008-09-27 00:2110,520--a------E:\WINDOWS\system32\avgrsstx.dll
        2008-09-27 00:06 . 2008-06-10 02:3273,728--a------E:\WINDOWS\system32\javacpl.cpl
        2008-09-26 23:58 . 2008-09-26 23:58d--------E:\Program Files\CCleaner
        2008-09-26 21:37 . 2008-09-26 21:37d--------E:\Documents and Settings\NetworkService\Application Data\Webroot
        2008-09-26 18:43 . 2008-09-26 21:393,182--a------E:\WINDOWS\system32\tmp.reg
        2008-09-26 17:11 . 2008-09-27 00:26d--------E:\Program Files\Common Files\Wise INSTALLATION Wizard
        2008-09-26 17:11 . 2008-09-26 17:12d--------E:\Documents and Settings\All Users\Application Data\Lavasoft
        2008-09-26 16:21 . 2008-09-26 21:34d--------E:\Documents and Settings\Ben\Application Data\.purple
        2008-09-26 16:20 . 2008-09-26 16:21d--------E:\Program Files\Pidgin
        2008-09-26 16:20 . 2008-09-26 16:21d--------E:\Program Files\Aspell
        2008-09-26 15:37 . 2008-09-26 15:37d--------E:\Program Files\XP Codec Pack
        2008-09-26 15:37 . 2008-07-09 04:05421,888--a------E:\WINDOWS\system32\ac3filter.acm
        2008-09-13 09:47 . 2008-09-26 13:53d--------E:\Program Files\Veetle
        2008-09-13 09:47 . 2008-09-13 09:4748,396--a------E:\WINDOWS\UninstVeetleTVPlayer.exe
        2008-08-28 10:02 . 2008-08-28 10:02d--------E:\WINDOWS\system32\CatRoot_bak

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-09-27 14:23---------d-----wE:\Documents and Settings\Ben\Application Data\U3
        2008-09-27 05:13---------d-----wE:\Program Files\Trend Micro
        2008-09-27 04:08---------d-----wE:\Program Files\Java
        2008-09-27 03:30---------d-----wE:\Program Files\Mozilla Thunderbird
        2008-09-27 02:01---------d-----wE:\Program Files\Roxio
        2008-09-27 02:01---------d-----wE:\Program Files\Common Files\Roxio Shared
        2008-09-27 02:01---------d-----wE:\Documents and Settings\All Users\Application Data\Roxio
        2008-09-26 21:12---------d-----wE:\Program Files\Lavasoft
        2008-09-26 21:12---------d-----wE:\Documents and Settings\Ben\Application Data\Lavasoft
        2008-09-26 20:55---------d-----wE:\Program Files\FlashFXP
        2008-09-26 20:21---------d-----wE:\Documents and Settings\Ben\Application Data\.gaim
        2008-09-26 20:20---------d-----wE:\Program Files\Gaim
        2008-09-26 18:07---------d-----wE:\Program Files\7-Zip
        2008-09-26 17:57---------d-----wE:\Program Files\skiStunt
        2008-09-26 17:52---------d-----wE:\Program Files\Quake III Arena
        2008-09-26 17:52---------d-----wE:\Program Files\MegaSpoof
        2008-09-26 17:51---------d-----wE:\Program Files\Project64 1.6
        2008-09-26 17:50---------d-----wE:\Program Files\PokerOffice
        2008-09-26 17:43---------d--h--wE:\Program Files\InstallShield Installation Information
        2008-09-26 17:43---------d-----wE:\Documents and Settings\All Users\Application Data\Apple Computer
        2008-09-26 17:40---------d-----wE:\Documents and Settings\All Users\Application Data\Laconic Software
        2008-09-26 17:39---------d-----wE:\Program Files\DivX
        2008-09-26 17:15---------d-----wE:\Program Files\Azureus
        2008-09-26 17:14---------d-----wE:\Program Files\Acoustica Beatcraft
        2008-09-16 17:19---------d-----wE:\Documents and Settings\Ben\Application Data\Azureus
        2008-08-17 03:58---------d-----wE:\Documents and Settings\All Users\Application Data\Comcast
        2007-03-23 19:053,580----a-wE:\Program Files\INSTALL.LOG
        2005-07-31 17:2876---ha-wE:\Program Files\Desktop.ini
        2004-10-01 19:31109----a-wE:\Documents and Settings\Ben\Application Data\tvmcwrd.dll
        2004-09-27 22:010----a-wE:\Documents and Settings\Ben\Application Data\wklnhst.dat
        2001-09-28 21:00164,864----a-wE:\Program Files\UNWISE.EXE
        .

        ((((((((((((((((((((((((((((( [emailprotected]_21.50.07.17 )))))))))))))))))))))))))))))))))))))))))
        .
        - 2008-09-28 01:46:28218,472----a-wE:\WINDOWS\system32\inetsrv\MetaBase.bin
        + 2008-09-28 03:31:12218,472----a-wE:\WINDOWS\system32\inetsrv\MetaBase.bin
        .
        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ctfmon.exe"="E:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
        "STYLEXP"="E:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-03-14 1159168]
        "MSMSGS"="E:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
        "H/PC Connection Agent"="E:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 401491]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ASUS Probe"="E:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
        "zBrowser Launcher"="E:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
        "RegistryMechanic"="E:\Program Files\Registry Mechanic\RegMech.exe" [2004-07-05 1183744]
        "UpdReg"="E:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
        "Jet Detection"="E:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
        "ATIPTA"="E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-29 344064]
        "SpySweeper"="E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2006-01-25 3405312]
        "ddoctorv2"="E:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
        "SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
        "AVG8_TRAY"="E:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-27 1235736]
        "Logitech Utility"="Logi_MwX.Exe" [2003-12-11 E:\WINDOWS\LOGI_MWX.EXE]
        "P17Helper"="P17.dll" [2005-05-02 E:\WINDOWS\system32\P17.dll]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
        "UIHost"="E:\\Program Files\\TGTSoft\\StyleXP\\CurrentLogon.EXE"

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=avgrsstx.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "MSACM.CEGSM"= mobilev.acm
        "vidc.ffds"= ffdshow.ax
        "msacm.ac3filter"= ac3filter.acm

        [HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
        path=E:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
        backup=E:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

        [HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
        path=E:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
        backup=E:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

        [HKLM\~\startupfolder\E:^Documents and Settings^Ben^Start Menu^Programs^Startup^Konfabulator.lnk]
        path=E:\Documents and Settings\Ben\Start Menu\Programs\Startup\Konfabulator.lnk
        backup=E:\WINDOWS\pss\Konfabulator.lnkStartup

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
        --a------ 2004-02-03 01:42 401491 E:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
        --a------ 2004-10-13 12:24 1694208 E:\Program Files\Messenger\msmsgs.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
        --a------ 2005-06-03 03:52 36975 E:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
        --a------ 2002-07-02 17:56 24576 E:\WINDOWS\system32\CTHELPER.EXE

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
        "RoxWatch"=2 (0x2)
        "RoxUpnpServer"=2 (0x2)
        "RoxUPnPRenderer"=3 (0x3)
        "RoxMediaDB"=3 (0x3)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "E:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
        "E:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
        "E:\\Program Files\\Mozilla Firefox\\firefox.exe"=
        "E:\\Program Files\\FlashFXP\\flashfxp.exe"=
        "E:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
        "E:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
        "E:\\Program Files\\TVAnts\\Tvants.exe"=
        "E:\\Program Files\\Windows Media Player\\wmplayer.exe"=
        "E:\\Program Files\\SopCast\\SopCast.exe"=
        "E:\\Documents and Settings\\Ben\\Application Data\\SopCast\\adv\\SopAdver.exe"=
        "E:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
        "E:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
        "E:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
        "41952:TCP"= 41952:TCP:41952

        R0 SSI;SSI;E:\WINDOWS\system32\Drivers\SSI.SYS [2006-01-25 78336]
        R1 AvgLdx86;AVG Free AVI Loader Driver x86;E:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-27 97928]
        R2 avg8emc;AVG Free8 E-mail Scanner;E:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-27 875288]
        R2 avg8wd;AVG Free8 WatchDog;E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-27 231704]
        R2 AvgTdiX;AVG Free8 Network Redirector;E:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-27 76040]
        S3 ASUSHWIO;ASUSHWIO;E:\WINDOWS\system32\drivers\ASUSHWIO.sys [ ]
        S3 LCcfltr;Logitech USB Filter Driver;E:\WINDOWS\system32\Drivers\LCcFltr.Sys [2003-12-11 14092]
        S3 pohci13F;pohci13F;E:\DOCUME~1\Ben\LOCALS~1\Temp\pohci13F.sys [ ]
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-09-27 23:31:59
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...


        E:\WINDOWS\TEMP\8273c39e-1d1f-4926-ad2e-daff87b9b72e.tmp 0 bytes

        scan completed successfully
        hidden files: 1

        **************************************************************************
        .
        ------------------------ Other Running Processes ------------------------
        .
        E:\WINDOWS\system32\ati2evxx.exe
        E:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        E:\Program Files\Executive Software\Diskeeper\DkService.exe
        E:\WINDOWS\system32\inetsrv\inetinfo.exe
        E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        E:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
        E:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
        E:\Program Files\AVG\AVG8\avgrsx.exe
        E:\WINDOWS\system32\ati2evxx.exe
        E:\WINDOWS\system32\wscntfy.exe
        E:\WINDOWS\system32\rundll32.exe
        E:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
        .
        **************************************************************************
        .
        Completion time: 2008-09-27 23:37:37 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-09-28 03:37:29
        ComboFix2.txt 2008-09-28 01:51:39

        Pre-Run: 72,553,689,088 bytes free
        Post-Run: 72,538,308,608 bytes free

        191--- E O F ---2008-09-11 08:00:56

          Looks good. Is the computer running any better?

          Some cleanup and then a (hopefully) final scan to make sure nothing else is hiding.

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • Make sure there's a space between Combofix and /u
          • Then hit Enter.
          .

        • The above procedure will:
        • Delete the following:
        • ComboFix and its associated files and folders.
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .

        ----------

        Download ATF Cleaner by Atribune to your Desktop.

        Alternate download link

        Note: Vista users must use Run As Administrator
        • Under Main: Select Files to Delete choose: Select All.
        • Click the Empty Selected button.
        • If you use Firefox browser click Firefox at the top and choose: Select All
        • Click the Empty Selected button.
          If you WOULD like to keep your saved passwords click No at the prompt.
        • If you use Opera browser click Opera at the top and choose: Select All
        • Click the Empty Selected button.
          If you would like to keep your saved passwords click No at the prompt.
        • Click Exit on the Main menu to close the program.
        .
        Note that your system will run slower for a reboot or two after having used this tool so don't panic.

        ----------

        Download OTCleanIt.exe and save it to your Desktop.
        • Double-click OTCleanIt.exe.
        • Click the CleanUp! button.
        • Select Yes when the "Begin cleanup Process?" prompt appears.
        • If you are prompted to Reboot during the cleanup, select Yes.
        • The tool will delete itself once it finishes, if not delete it yourself.
        .
        Important: Restart the computer before continuing.

        ----------

        Run this online scan. Requires Internet Explorer

        Use the ESET Nod32 Online Scanner

        1. Check the box next to YES, I accept the Terms of Use.
        2. Click Start
        3. When asked, allow the activex control to install
        4. Click Start
        5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
        6. Click Scan
        7. Wait for the scan to finish
        8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
        9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Yea it seems to be working much better. I haven't gone through the final step from your LAST post yet but will here shortly.

        AVG has popped up a couple times saying that there is a threat detected in E:\System Volume Information\_restore...etc.

        Is this just trojan files that are present in the restore files I assume?# version=4
        # OnlineScanner.ocx=1.0.0.635
        # OnlineScannerDLLA.dll=1, 0, 0, 79
        # OnlineScannerDLLW.dll=1, 0, 0, 78
        # OnlineScannerUninstaller.exe=1, 0, 0, 49
        # vers_standard_module=3478 (20080928)
        # vers_arch_module=1.064 (20080214)
        # vers_adv_heur_module=1.066 (20070917)
        # EOSSerial=61ea1c437661b948b4fdb06f9b362522
        # end=finished
        # remove_checked=true
        # unwanted_checked=true
        # utc_time=2008-09-28 03:01:37
        # local_time=2008-09-28 11:01:37 (-0500, Eastern Daylight Time)
        # country="United States"
        # osver=5.1.2600 NT Service Pack 2
        # scanned=318220
        # found=0
        # scan_time=2600
        Quote from: 20Deep on September 28, 2008, 07:49:06 AM

        AVG has popped up a couple times saying that there is a threat detected in E:\System Volume Information\_restore...etc.

        Is this just trojan files that are present in the restore files I assume?

        Yes and we will take care of that now in the final steps.

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor RATES sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Awesome.

        I can't explain how much help you have been. Glad it worked out for the good!!

        2147.

        Solve : cannot access system restore or internet explorer?

        Answer»

        oops sorry doing that now its scanningok scanned for along time and then just disappearedUmmm....What?

        It just disappears?

        Can you try again, but this time don't do anything else.YES tried again scan ran and finished and went back to desktop still MISSING DLLS etcI found this:
        http://support.microsoft.com/kb/274092Try repairing System Restore.

        Go to Start > Run and type notepad.exe then click OK

        Copy and paste the text in the Quote box below to Notepad and save as fixme.reg to Your Desktop

        Quote

        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
        "DisableConfig"=dword:00000000
        "DisableSR"=dword:00000000

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
        "NoSaveSettings"=dword:00000000

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr]
        "Type"=dword:00000002
        "Start"=dword:00000000
        "ErrorControl"=dword:00000001
        "Tag"=dword:00000004
        "ImagePath"=hex(2):53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,\
        52,00,49,00,56,00,45,00,52,00,53,00,5c,00,73,00,72,00,2e,00,73,00,79,00,73,\
        00,00,00
        "DisplayName"="System Restore Filter Driver"
        "Group"="FSFilter System Recovery"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Parameters]
        "FirstRun"=dword:00000000
        "DontBackup"=dword:00000000
        "MachineGuid"="{EAAFAEEC-4AFE-42BE-83D9-C12FDD4942A6}"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Security]
        "Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
        00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
        00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
        05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
        20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
        00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
        00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr\Enum]
        "0"="Root\\LEGACY_SR\\0000"
        "Count"=dword:00000001
        "NextInstance"=dword:00000001

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalMachine\Software\Policies\Microsoft\Windows NT\SystemRestore]
        "DisableSR"=dword:00000000

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalMachine\Software\Policies\Microsoft\Windows NT\SystemRestore]
        "DisableConfig"=dword:00000000

        [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalMachine\Software\Policies\Microsoft\Windows NT\SystemRestore]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
        [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalMachine\Software\Policies\Microsoft\Windows NT\SystemRestore]

        LOCATE fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

        Accept any warnings.

        2148.

        Solve : panda active scan says i'm infected?

        Answer»

        No PROBLEM. HOPE you GET it FIGURED out.

        2149.

        Solve : My dvd player with usb reader infected by autorun.inf?

        Answer»

        I have a dvd PLAYER with USB reader (just INSERT a flash drive with a movie file and you can view it). Unfortunately, my FRIEND flash drive has an autorun.inf virus that when he inserted his flash drive to my dvd player it became infected with this virus. Can anybody help me how I can remove this virus from my dvd player? I will APPRECIATE any technical advice that is given. Thanks in advance.

        2150.

        Solve : malwarebytes' anti-malware not open?

        Answer»

        I have updated "MALWAREBYTES' anti-malware" today.But when complete the UPDATING PROCESS a message show:

        "Microsoft visual c++ RUNTIME LIBRARY"(window title)

        "Runtime error!"

        "programe: c:\programe files\malwarebytes' anti-malware\mbam.exe."

        "This application has requested the runtime to terminate it in an unusual way........".

        Aftar this when I am trying to open this programe show the same message.Then I uninstall and download again.But same window popped up.why?Please help me. My os windows xp pro (sp 2),anti-virus AVG.Is this the free or paid version?It is free version.See here: http://www.malwarebytes.org/forums/index.php?showtopic=19388