Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3101.

Solve : Can virus cause the screen to go black??

Answer»

I was WALKING my DAD through installing AVG 8.0 - it identified some viruses - at the end it said scan was complete the only option was to close the program.

When he did it SHUT down and now the screen will not come on. He SAYS it sounds like the CPU is running but he can't see anything. How do you correct a problem without visibility to the screen? He is running XP
ThanksIs there Absolutely nothing on the screen? Even right when you turn the computer on?Also, how about SAFE Mode?Does the computer go past post or nothing at all when booting up???

3102.

Solve : AVG8.0?

Answer»

Hello all,

I hope I am in the right forum.

I recently upgraded to avg 8.0. Upon COMPLETION of the scan each day it comes up clean of any infections, however in the warnings tab I get about 25000 warnings!!! I remove them each day, however upon completion of every scan they return. Does anybody know how do deal with this?These warnings...

Are they RELATED to cookies? Have you tried clearing your internet cache of any of those cookies prior to the scanning process?SAVIOUR,

In the scan settings I have it set up not to scan for cookiesCan you tell us exactly what a few of the warnings say?Sure,

Internet Explore\Active X compatability\AD1E7FF5-2BAC-68DC-FA3C-OFEABD9092AA} Found Adware CoolWebSearch...........POTENTIALLY Dangerous.

Most entries are very similar to this one. I do regular AD-Aware/Spybot Search & Destroy scans........also have spyware blasterMoved to Computer Viruses and Spyware forum.

Run the scan HERE and post the logs when COMPLETE.

3103.

Solve : Laptop catched another spyware infection. Red background, spyware attack warning?

Answer»

Looks good.

.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
----------

The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    1. Double click OTMoveIt2.exe to launch it.
    Vista users right click and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
    5. Once complete exit out of OTMoveIt2

    ---------

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    .
    ----------

    INSTALL this. Let me know if it interferes with your web surfing and we can remove it. It will help to keep you away from dangerous sites and future infections.

    Save DelDomains.inf to the desktop.
    • IE users Right-click on the link and select Save As.
    • Firefox users Right-click on the link and choose Save link as...
    • Save it to the desktop.
    • From the desktop Right-click on DelDomains.inf
    • Select Install making sure Internet Explorer is closed.
    • You won't see anything happen so give it several seconds.
    Note:, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection.

    ----------

    It is possible that you will need to reinstall the programs and drivers related to these entries if the infections come back again. If so, and you need help finding out how then start a new topic in the software forum asking for help.

    These are the ones that have been patched,

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell\AccessDirect\dadapp.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\McAfee.com\MPS\mscifapp.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
    C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe
    C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
    c:\progra~1\mcafee\MCAFEE~1\masalert.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Yahoo!\Messenger\ypager.exe

    ----------

    How is everything now?
    Thanks again for your help !!



    Everything seems to be running pretty smoothly.

    With the DelDomains thing, thanks !! I really need something that will keep me away from dangerous sites.

    If I do stumble upon a site that will AUTOMATICALLY try and download malware or spyware or anything of that nature, will the DelDomains program alert me somehow?It will actually block the site so you can't get infected.

    Well, that's PERFECT !!

    Thanks [ again ] for your time, patience, and help !!

    No problem.

    I don't know if you did last time or not but another thing I would SUGGEST installing is SiteAdvisor. (Thanks SAVIOR )Cool. I'll get that one right now.
    3104.

    Solve : Some Useful Information...?

    Answer»

    I thought I had posted this before, but just did a search and can't FIND it...so, I guess I'll post it again...

    Have you ever received a dialog box when booting your computer stating a particular file was not found...usually pointint to a .dll file, or an .exe file?

    Uniblue's ProcessLibrary.com is a good place to go to search for questionable PROCESSES. Here, you can do a search to see if the file in question is related to an operating system and/or software program. It will also let you know if it's a potential threat.

    While you're there...you may want to download, install and EVEN run their ProcessScanner. This free application will give you a complete analysis of all the processes running on your PC, along with a risk analysis of each one...and it's ABSOLUTELY FREE!

    I HOPE all of you find this thread useful...


    All my best...

    -Steve

    3105.

    Solve : HELP basenados32 ????

    Answer»

    Just so you know Broni, I posted an updated HiJackThis and requested additional help while you are out. Here is the most recent HiJackThis:

    LOGFILE of Trend Micro HijackThis v2.0.2
    Scan saved at 12:07:50 PM, on 6/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\iWin Games\iWinGamesInstaller.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\UPS\WSTD\WSTDMessaging.exe
    C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
    C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\Dependent\HSChkProxyExe.exe
    C:\WINDOWS\system32\kdfmgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {6528C5A4-3DAC-4EE2-B7BA-9D6AA3053C9F} - C:\WINDOWS\system32\fccdedCu.dll (file missing)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {C0690CA5-C80B-4F09-8DAA-31C0924AE1B9} - C:\PROGRA~1\NETFIL~1\NETFIL~1.DLL
    O2 - BHO: TransactionProtector BHO - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
    O2 - BHO: {4ed99217-bff1-182a-d164-8d9111d6e31d} - {d13e6d11-19d8-461d-a281-1ffb71299de4} - C:\WINDOWS\system32\naagolro.dll (file missing)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
    O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: UPS WorldShip MESSAGING Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
    O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://secure.netlinksolution.com/includes/icaweb.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://moengco-srv0/connectcomputer/nshelp.dll
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/PiratePoppers.1.0.0.39.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mel-stark.spaces.live.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1213029730953
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = moengco.local
    O17 - HKLM\Software\..\Telephony: DomainName = moengco.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = moengco.local
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = moengco.local
    O20 - Winlogon Notify: rqRHxwUm - rqRHxwUm.dll (file missing)
    O20 - Winlogon Notify: vtUkifeb - vtUkifeb.dll (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: F-Prot Antivirus Update Monitor - Unknown owner - C:\Program Files\FSI\F-Prot\fpavupdm.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
    O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe (file missing)
    O23 - Service: Trend Micro UNAUTHORIZED Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

    --
    End of file - 10626 bytes
    While I'm checking HJT log, let me know what happened since last night.
    Did Windows repair work?The second repair did not work, but the above article I posted from Charlie White did work...thank god!*** Go Start>Control Panel>Add\Remove, and uninstall iWin Games (if present).

    1. Print this post out, since you won't have an access to it, at some point.

    2. Close all windows, except for HijackThis.

    3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

    - O2 - BHO: (no name) - {6528C5A4-3DAC-4EE2-B7BA-9D6AA3053C9F} - C:\WINDOWS\system32\fccdedCu.dll (file missing)
    - O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    - O2 - BHO: (no name) - {C0690CA5-C80B-4F09-8DAA-31C0924AE1B9} - C:\PROGRA~1\NETFIL~1\NETFIL~1.DLL
    - O2 - BHO: {4ed99217-bff1-182a-d164-8d9111d6e31d} - {d13e6d11-19d8-461d-a281-1ffb71299de4} - C:\WINDOWS\system32\naagolro.dll (file missing)
    - O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    - O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
    - O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
    - O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
    - O20 - Winlogon Notify: rqRHxwUm - rqRHxwUm.dll (file missing)
    - O20 - Winlogon Notify: vtUkifeb - vtUkifeb.dll (file missing)
    - O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe

    4. Click on Fix checked button.

    5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

    6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

    7. Delete following files/folders (if present):

    - spools.exe file from C:\WINDOWS\system32\drivers
    - cftmon.exe file from C:\Documents and Settings\LocalService
    - iWin Games folder from C:\Program Files

    8. Restart in Normal Mode.

    9. Post new HijackThis log.

    P. S. I just got home from work, so it may take a while until I post next replyLogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:13:15 PM, on 6/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\UPS\WSTD\WSTDMessaging.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
    C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: TransactionProtector BHO - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
    O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.exe
    O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://secure.netlinksolution.com/includes/icaweb.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://moengco-srv0/connectcomputer/nshelp.dll
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/PiratePoppers.1.0.0.39.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://mel-stark.spaces.live.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1213029730953
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = moengco.local
    O17 - HKLM\Software\..\Telephony: DomainName = moengco.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = moengco.local
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = moengco.local
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: F-Prot Antivirus Update Monitor - Unknown owner - C:\Program Files\FSI\F-Prot\fpavupdm.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
    O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe (file missing)
    O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

    --
    End of file - 9070 bytes
    Good job

    Your computer is clean

    1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" VERSION.
    Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
    Run CCleaner.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

    6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

    7. Let me know, how your computer is doing.

    Works great now Broni. You da MAN, thankk you!You're very welcome
    Happy computing!

    3106.

    Solve : I cannot uninstall "Trojan Hunter 5.0?

    Answer»

    My laptop has been slow lately, and I was suspecting the trojan hunter might have deleted some files needed for windows.
    I used the add/remove programs in control panel, and I get a window that says:
    File "c:\program files\trojan hunter 5.0\unins000.dat" does not exist. Cannot uninstall.

    It seems to me that part of the program is missing. I went to C\program files\trojan hunter and tried to delete it but I get:
    Cannot delete contmenu.dll: access is denied. Make sure that the DISK is not full or write protected and that the file is not currently in use.

    Hp pavilion dv8130us
    win. xp pro
    McAffee anti v
    AVG antispyware
    CCleaner
    Any ideas?
    JimYou will be directed to virus and spyware shortly.

    You are best to get help from one of our malware removal specialists.

    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    download this and save + post your log.

    Just so the guys know if there is anything else other that trojan remover to get rid of.OK thanksI installed and ran the hjt program, and it saved the results to the "hjt notepad" in My Documents.
    I have never done this before, but nothing in the list looks bad to me.
    How do I post it?
    JimJust post it in this thread. I will move this topic to the Computer Viruses and Spyware forum.How do I get it from My Documents to here?Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:59:49 PM, on 6/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Cisco SYSTEMS\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    C:\Program Files\McAfee\Common Framework\McTray.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Search Settings\SearchSettings.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\DOCUME~1\jplake\LOCALS~1\Temp\AutoDetect.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talti.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [StxTrayMenu] "F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Ceedo AutoDetect] C:\DOCUME~1\jplake\LOCALS~1\Temp\AutoDetect.exe /active
    O4 - Global Startup: VPN Client.lnk = ?
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O17 - HKLM\Software\..\Telephony: DomainName = Hydraquip.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    O23 - Service: Seagate Sync Service - Unknown owner - F:\ceedo\Program Files\Seagate\Sync\SeaSyncServices.exe (file missing)

    --
    End of file - 6615 bytes

    I tried copy/PASTE and I guess it worked!
    Jim
    Download Malwarebytes' Anti-Malware from here or here

    Double Click mbam-setup.exe to install the application.

    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

    ----------

    Download Deckard's System Scanner (DSS) to your Desktop.
    Note: You must be logged onto an account with administrator privileges.
    Vista users Right click DSS and Run as Administrator.

    • Close all applications and windows.
    • Double-click on dss.exe to run it, and follow the prompts.
    • When the scan is complete, two text files will open.
      • main.txt <- this one will be maximized
      • extra.txt <- this one will be minimized
    • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply.
    .
    You may need two posts to get all of the logs in, or you can add them as attachments. How to add attachments to a post
    ----------

    Next post add
    MBAM log
    DSS log(s)
    MBAM says it's clean:Malwarebytes' Anti-Malware 1.16
    Database version: 845

    10:01:33 PM 6/9/2008
    mbam-log-6-9-2008 (22-01-33).txt

    Scan type: Quick Scan
    Objects scanned: 42105
    Time elapsed: 5 minute(s), 46 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    Deckards System Scanner:Deckard's System Scanner v20071014.68
    Run by jplake on 2008-06-09 21:55:46
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    65: 2008-06-10 02:56:00 UTC - RP135 - Deckard's System Scanner Restore Point
    64: 2008-06-10 02:42:53 UTC - RP134 - Installed Java(TM) 6 Update 6
    63: 2008-06-10 01:33:14 UTC - RP133 - Removed Google Earth.
    62: 2008-06-09 23:41:46 UTC - RP132 - Software Distribution Service 3.0
    61: 2008-06-09 23:28:52 UTC - RP131 - Restore Operation


    -- First Restore Point --
    1: 2008-03-11 19:57:39 UTC - RP71 - System Checkpoint


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as jplake.exe) ----------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:56:45 PM, on 6/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    C:\Program Files\McAfee\Common Framework\McTray.exe
    C:\Program Files\Search Settings\SearchSettings.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\DOCUME~1\jplake\LOCALS~1\Temp\AutoDetect.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\Documents and Settings\jplake\My Documents\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\jplake.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talti.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [StxTrayMenu] "F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Ceedo AutoDetect] C:\DOCUME~1\jplake\LOCALS~1\Temp\AutoDetect.exe /active
    O4 - Global Startup: VPN Client.lnk = ?
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O17 - HKLM\Software\..\Telephony: DomainName = Hydraquip.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Hydraquip.com
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    O23 - Service: Seagate Sync Service - Unknown owner - F:\ceedo\Program Files\Seagate\Sync\SeaSyncServices.exe (file missing)

    --
    End of file - 6653 bytes

    -- File Associations -----------------------------------------------------------

    .scr - AutoCADLTScriptFile - shell\open\command - "C:\WINDOWS\system32\notepad.exe" "%1"


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    All drivers whitelisted.


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    S2 Seagate Sync Service - "f:\ceedo\program files\seagate\sync\seasyncservices.exe" (file missing)


    -- Device Manager: Disabled ----------------------------------------------------

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Cisco Systems VPN Adapter
    Device ID: ROOT\NET\0000
    Manufacturer: Cisco Systems
    Name: Cisco Systems VPN Adapter
    PNP Device ID: ROOT\NET\0000
    Service: CVirtA


    -- Files created between 2008-05-09 and 2008-06-09 -----------------------------

    2008-06-09 21:52:05 0 d-------- C:\Documents and Settings\jplake\Application Data\Malwarebytes
    2008-06-09 21:52:03 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-06-09 21:52:02 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-06-09 20:48:33 0 d-------- C:\Program Files\Trend Micro
    2008-06-09 19:36:06 0 d-------- C:\WINDOWS\pss
    2008-06-09 18:38:32 0 d-------- C:\Program Files\RealFlightG4
    2008-06-09 18:38:27 0 d-------- C:\Program Files\Common Files\KnifeEdge
    2008-06-09 18:32:10 0 dr-h----- C:\Documents and Settings\jplake\Recent
    2008-05-27 16:16:14 0 d-------- C:\Documents and Settings\jplake\UserData
    2008-05-11 21:13:40 0 d-------- C:\Documents and Settings\jplake\.housecall6.6


    -- Find3M Report ---------------------------------------------------------------

    2008-06-09 21:44:57 0 d-------- C:\Program Files\Java
    2008-06-09 18:38:27 0 d-------- C:\Program Files\Common Files
    2008-06-09 18:32:11 0 d-------- C:\Documents and Settings\jplake\Application Data\uTorrent
    2008-06-09 18:29:29 0 d-------- C:\Program Files\TrojanHunter 5.0
    2008-05-10 22:31:41 0 d-------- C:\Program Files\DivX
    2008-05-08 22:23:44 0 d-------- C:\Documents and Settings\jplake\Application Data\TrojanHunter
    2008-04-27 16:05:42 257 --a------ C:\Documents and Settings\jplake\Application Data\burnaware.ini
    2008-04-20 20:53:46 0 d-------- C:\Program Files\Sauer-Danfoss
    2008-04-10 07:14:27 0 d-------- C:\Program Files\uTorrent
    2008-03-31 16:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
    2008-03-31 16:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
    2008-03-31 16:25:46 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
    2008-03-31 16:25:46 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
    2008-03-31 16:25:46 682496 --a------ C:\WINDOWS\system32\DivX.dll
    2008-03-28 13:52:17 120 --a------ C:\drmHeader.bin
    2008-03-24 19:06:32 724992 --a------ C:\WINDOWS\iun6002.exe
    2008-03-21 15:30:08 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
    2008-03-21 15:28:54 196608 --a------ C:\WINDOWS\system32\dtu100.dll
    2008-03-21 15:28:54 81920 --a------ C:\WINDOWS\system32\dpl100.dll
    2008-03-21 15:28:20 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
    12/06/2007 12:58 PM1198432--a------C:\Program Files\Search Settings\kb125\SearchSettings.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [09/27/2005 10:05 PM]
    "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [12/13/2005 05:45 PM]
    "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [08/01/2005 03:26 PM]
    "Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [01/11/2008 06:54 PM]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/14/2006 05:02 PM]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM]
    "McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [11/17/2006 04:06 AM]
    "ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [01/24/2008 08:50 PM]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 04:25 AM]
    "StxTrayMenu"="F:\ceedo\Program Files\Seagate\SystemTray\StxMenuMgr.exe" []
    "@"="" []
    "SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [12/06/2007 12:58 PM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [02/28/2006 07:00 AM]
    "Eraser"="C:\Program Files\Eraser\Eraser.exe" [12/22/2007 06:03 PM]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
    "Ceedo AutoDetect"="C:\DOCUME~1\jplake\LOCALS~1\Temp\AutoDetect.exe" []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    VPN Client.lnk - C:\WINDOWS\Installer\{6DC47739-3BB0-4494-A43D-193BF54070AE}\Icon3E5562ED7.ico [2/13/2008 12:05:26 PM]
    WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [12/3/2007 12:10:00 PM]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=0 (0x0)


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    AutoRun\command- F:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13339713-123c-11dd-83ea-0014a52c498e}]
    AutoRun\command- F:\JDSecure\Windows\JDSecure31.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22272dbf-e8ae-11dc-8370-0014a52c498e}]
    AutoRun\command- F:\Autorun.exe /run
    Shell00\Command- F:\Autorun.exe /run
    Shell01\Command- F:\Autorun.exe /action
    Shell02\Command- F:\Autorun.exe /uninstall

    *Newly Created Service* - MBAMCATCHME



    -- End of Deckard's System Scanner: finished at 2008-06-09 21:57:41 ------------

    Deckards extra:Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.
    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows XP Professional (build 2600) SP 2.0
    Architecture: X86; Language: English

    CPU 0: AMD Turion(tm) 64 Mobile Technology ML-40
    Percentage of Memory in Use: 28%
    Physical Memory (total/avail): 1918.17 MiB / 1379.57 MiB
    Pagefile Memory (total/avail): 3811.8 MiB / 3411.91 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1931.73 MiB

    C: is Fixed (NTFS) - 111.78 GiB total, 87.93 GiB free.
    D: is Fixed (NTFS) - 111.79 GiB total, 55.69 GiB free.
    E: is CDROM (No Media)
    M: is Network (Unformatted)
    N: is Network (Unformatted)
    U: is Network (Unformatted)

    \\.\PHYSICALDRIVE0 - WDC WD1200BEVE-00UYT0 - 111.79 GiB - 1 partition
    \PARTITION0 (bootable) - Installable File System - 111.78 GiB - C:

    \\.\PHYSICALDRIVE1 - WDC WD1200BEVE-00UYT0 - 111.79 GiB - 1 partition
    \PARTITION0 - Installable File System - 111.79 GiB - D:



    -- Security Center -------------------------------------------------------------

    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is enabled.

    FirstRunDisabled is set.

    AV: McAfee VirusScan Enterprise v8.5.0.781 (McAfee, Inc.)

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
    "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
    "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
    "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"


    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\jplake\Application Data
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=JPLAKE-A05BD413
    ComSpec=C:\WINDOWS\system32\cmd.exe
    DEFLOGDIR=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\jplake
    HOMESHARE=\\houfs01\jplake
    LOGONSERVER=\\HOUEX01
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 36 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=2402
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\jplake\LOCALS~1\Temp
    TMP=C:\DOCUME~1\jplake\LOCALS~1\Temp
    USERDNSDOMAIN=HYDRAQUIP.COM
    USERDOMAIN=HYDRAQUIP
    USERNAME=jplake
    USERPROFILE=C:\Documents and Settings\jplake
    VSEDEFLOGDIR=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
    windir=C:\WINDOWS


    -- User Profiles ---------------------------------------------------------------

    jplake (admin)
    administrator (admin)
    jim (admin)


    -- Add/Remove Programs ---------------------------------------------------------

    --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    --> MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
    3D Live Pool v2.66 --> "C:\Program Files\3D Live Pool\unins000.exe"
    Adobe FLASH Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
    ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[emailprotected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    AutoCAD LT 2008 - English --> C:\Program Files\AutoCAD LT 2008\Setup\Setup.exe /P {5783F2D7-6009-0409-0002-0060B0CE6BBA} /M ACADLT
    Autodesk DWF Viewer 7 --> MsiExec.exe /I{9A346205-EA92-4406-B1AB-50379DA3F057}
    AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
    Broadcom 802.11 Wireless LAN Adapter --> "C:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Broadcom\Broadcom 802.11\Driver"
    BurnAware Free Edition 1.2.8 --> "C:\Program Files\BurnAware Free Edition\unins000.exe"
    CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
    CircuitEase LT 2008 v10r1 --> "C:\Program Files\unins000.exe"
    Cisco Systems VPN Client 4.6.00.0049 --> MsiExec.exe /X{6DC47739-3BB0-4494-A43D-193BF54070AE}
    Conexant AC-Link Audio --> C:\Program Files\CONEXANT\CNXT_AUDIO\UIU32a.exe -U -ICPL309BA.INF
    DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    Eraser --> "C:\Documents and Settings\All Users\Application Data\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646}\EraserSetup32.exe" REMOVE=TRUE MODIFY=FALSE
    Eraser --> C:\Documents and Settings\All Users\Application Data\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646}\EraserSetup32.exe
    H1 Offline Configurator --> MsiExec.exe /I{DE278733-2BB4-48EA-922A-E3BA1655D538}
    HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    HP Help and Support --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\Setup.exe" -l0x9 -removeonly
    HP Wireless Assistant 2.00 C1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\Setup.exe" -l0x9 hpquninst
    Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    Java(TM) 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
    Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    McAfee VirusScan Enterprise --> MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
    Media Player Codec Pack 2.2.0 --> C:\WINDOWS\system32\C2MP\Uninst.exe
    Microsoft COMPRESSION Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
    Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mozilla Firefox (2.0.0.14) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
    MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
    NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
    PandoraRecovery (Remove Only) --> "C:\Program Files\Pandora Recovery\Uninstall.exe"
    Qantel QIC-PC II --> MsiExec.exe /X{BEA1F96D-04DD-4778-94F6-347B48AD2E7A}
    Real Alternative 1.7.5 --> "C:\Program Files\Real Alternative\unins000.exe"
    RealFlight G4 R/C Simulator --> C:\Program Files\Common Files\KnifeEdge\LauncherHelperG4.exe -task=UninstallProduct -productname="RealFlight G4"
    Sauer-Danfoss Electronic Catalogue --> C:\PROGRA~1\SAUER-~1\UNWISE.EXE C:\PROGRA~1\SAUER-~1\INSTALL.LOG
    Search Settings --> MsiExec.exe /X{90529245-9C54-45B5-BBB3-B180CA04F248}
    Soft Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1002&DEV_4378\HXFSETUP.EXE -U -Icpl309bk.inf
    SouthPark Mario Bros 2.1 --> C:\WINDOWS\iun6002.exe "c:\spm2\irunin.ini"
    StompSoft Digital Vault --> C:\PROGRA~1\STOMPS~1\DIGITA~1\UNWISE.EXE C:\PROGRA~1\STOMPS~1\DIGITA~1\INSTALL.LOG
    Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    Texas Instruments PCIxx21/x515/xx12 drivers. --> C:\Program Files\InstallShield Installation Information\{AD7914E1-6453-4440-AEC7-02C72AD6FE5F}\setup.exe -runfromtemp -l0x0409
    TrojanHunter 5.0 --> "C:\Program Files\TrojanHunter 5.0\unins000.exe"
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) --> C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_6FE44FCD212D4A086C7BC0C98B9A619782073FB7\amdk8.inf
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    WinZip 11.1 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}
    Zune --> MsiExec.exe /X{7583239A-D4BE-48CA-A253-396122B3D3E9}
    Zune Language Pack (ES) --> MsiExec.exe /X{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
    Zune Language Pack (FR) --> MsiExec.exe /X{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}


    -- Application Event Log -------------------------------------------------------

    Event Record #/Type3715 / Error
    Event Submitted/Written: 06/09/2008 07:41:06 PM
    Event ID/Source: 15 / AutoEnrollment
    Event Description:
    Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
    Enrollment will not be performed.

    Event Record #/Type3712 / Error
    Event Submitted/Written: 06/09/2008 07:40:21 PM
    Event ID/Source: 1054 / Userenv
    Event Description:
    Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

    Event Record #/Type3710 / Error
    Event Submitted/Written: 06/09/2008 07:40:05 PM
    Event ID/Source: 1054 / Userenv
    Event Description:
    Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

    Event Record #/Type3706 / Error
    Event Submitted/Written: 06/09/2008 07:17:59 PM
    Event ID/Source: 15 / AutoEnrollment
    Event Description:
    Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted.
    Enrollment will not be performed.

    Event Record #/Type3705 / Error
    Event Submitted/Written: 06/09/2008 07:17:03 PM
    Event ID/Source: 1054 / Userenv
    Event Description:
    Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.



    -- Security Event Log ----------------------------------------------------------

    No Errors/Warnings found.


    -- System Event Log ------------------------------------------------------------

    Event Record #/Type13162 / Warning
    Event Submitted/Written: 06/09/2008 09:41:25 PM
    Event ID/Source: 8193 / LSASRV
    Event Description:
    The Security System could not establish a secured connection with the server DNS/faith.logixcom.net. No authentication protocol was available.

    Event Record #/Type13161 / Warning
    Event Submitted/Written: 06/09/2008 09:41:25 PM
    Event ID/Source: 8192 / LSASRV
    Event Description:
    The Security System detected an attempted downgrade attack for
    server DNS/faith.logixcom.net. The failure code from authentication protocol Kerberos
    was "There are currently no logon servers available to service the logon request.
    (0xc000005e)".

    Event Record #/Type13160 / Error
    Event Submitted/Written: 06/09/2008 09:25:34 PM
    Event ID/Source: 29 / W32Time
    Event Description:
    The time provider NtpClient is configured to acquire time from one or more
    time sources, however none of the sources are currently accessible.
    No attempt to contact a source will be made for 119 minutes.
    NtpClient has no source of accurate time.

    Event Record #/Type13159 / Warning
    Event Submitted/Written: 06/09/2008 09:25:34 PM
    Event ID/Source: 14 / W32Time
    Event Description:
    The time provider NtpClient was unable to find a domain controller to use as a time
    source. NtpClient will try again in 120 minutes.

    Event Record #/Type13157 / Warning
    Event Submitted/Written: 06/09/2008 08:41:24 PM
    Event ID/Source: 8193 / LSASRV
    Event Description:
    The Security System could not establish a secured connection with the server DNS/faith.logixcom.net. No authentication protocol was available.



    -- End of Deckard's System Scanner: finished at 2008-06-09 21:57:41 ------------

    Open Hijackthis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    • O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
    • O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    .
    Important: Close all windows except for Hijackthis and then click Fix checked.

    Exit Hijackthis.

    ----------

    Go to add/remove programs and uninstall:

    • Java(TM) 6 Update 3
    • Java(TM) 6 Update 5
    • Search Settings
    ----------

    Try this first.

    Go to Start > Run and copy/paste this in the window then click OK.

    C:\Program Files\TrojanHunter 5.0\unins000.exe

    If that doesn't work we will remove it manually.

    I uninstalled the java 3&5, and the search settings.
    Ran the hjt and there was no search settings stuff listed.
    I copy/pasted the trojan uninstaller in the "run" and it would not work. I got:
    c:\program files\trojan hunter 5.0\unins000.dat" does not exist. Cannot uninstall.

    So far today, I ran the McAfee on demand scan, and the AVG antispyware,MalwareBytes and the Deckards.
    The only thing that came up was the Search Settings.(really I don't know what that is)
    Hope I can get the Trojan Hunter out. Is that actually a legit program?
    JimTrojan Hunter is a legit program but you shouldn't have a problem removing it.

    Hold on a minute while I work up a removal fix.

    Be right back.....Now download The Avenger by Swandog46 and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Code box below, and paste it into the Input script here window:
    Code: [Select]Comment:

    Files to delete:
    C:\Program Files\TrojanHunter 5.0\unins000.exe

    Folders to delete:
    C:\Program Files\TrojanHunter 5.0
    C:\Documents and Settings\jplake\Application Data\TrojanHunter


    Note: the above instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system


    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    • Add the Avenger log in your next post.
    3107.

    Solve : MASSIVE virus?

    Answer»

    EDIT: nvm it finally finished. here it is:

    [attachment deleted by admin]Give it a little while longer. 10 minutes or so. If it doesn't create the log then look for it in C:\combofix.txt.

    If needed the restart the computer manually. Give it a few more minutes though first.i just edit my above post since it finished very shortly after i posted the message.Are these yours?

    Quote

    2009-05-29 14:42 . 2009-05-29 14:42--------d-----wc:\users\admin\AppData\Roaming\KillProcess
    2009-05-29 14:41 . 2009-05-29 14:41--------d-----wc:\program files\KillProcess
    2009-05-29 12:05 . 2009-05-29 12:05--------d-----wC:\Kelahx
    the top two are. theres nothing in the bottom folder but i can delete it if i need to.
    i never made it.


    The top two is a program i installed to kill multiple processes at once. came in handy when i had to delete 400 processes otherwise it would have been one at a time.

    im also on chat so if you think it would be quicker talking there then thats fine. OK. I just need to know what I'm seeing.

    Also let me know how the computer is running now?

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    Folder::
    C:\Kelahx

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\whtcg]

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeWell my pc seems to be running fine. Nothing suspicious seems to be running in the process list.


    And some of my taskbar icons are gone. But thats cool. They are the one i wanted gone :p

    attached is the new log

    [attachment deleted by admin]OK you should run a full virus scan now to make sure nothing is hiding.

    First...

    Go to Start > Run and type notepad.exe then click OK

    Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

    Code: [Select]REGEDIT4

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      Locate fixme.reg on your Desktop and double-click it. Answer
    Yes when prompted to merge with the Registry.

    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

    Delete the fixme.reg from the Desktop.

    ----------

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main MENU to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    Run the F-Secure Online Scanner for Viruses, Spyware and RootKits.

    Note: This Scanner is for Internet Explorer Only!

    • Click on Online Services and then Online Scanner
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
    ok here it is:

    Scanning Report
    Friday, May 29, 2009 15:26:56 - 18:27:52

    Computer name: HOME
    Scanning type: Scan system for malware, spyware and rootkits
    Target: C:\ D:\ E:\
    10 malware found
    TrackingCookie.2o7 (spyware)

    * System (Disinfected)

    TrackingCookie.Advertising (spyware)

    * System (Disinfected)

    TrackingCookie.Atdmt (spyware)

    * System (Disinfected)

    Client-IRC.Win32.mIRC (spyware)

    * System (Disinfected)

    TrackingCookie.Doubleclick (spyware)

    * System (Disinfected)

    TrackingCookie.Webtrends (spyware)

    * System (Disinfected)

    RiskTool.Win32.PsKill (spyware)

    * System (Disinfected)

    TrackingCookie.Tradedoubler (spyware)

    * System (Disinfected)

    TrackingCookie.Statcounter (spyware)

    * System (Disinfected)

    TrackingCookie.Yieldmanager (spyware)

    * System (Disinfected)



    Statistics
    Scanned:

    * Files: 253041
    * System: 7246
    * Not scanned: 24

    Actions:

    * Disinfected: 10
    * Renamed: 0
    * Deleted: 0
    * Not cleaned: 0
    * Submitted: 0

    Files not scanned:

    * C:\HIBERFIL.SYS
    * C:\PAGEFILE.SYS
    * C:\WINDOWS\SYSTEM32\CONFIG\COMPONENTS
    * C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
    * C:\WINDOWS\SYSTEM32\CONFIG\SAM
    * C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
    * C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
    * C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\COMPONENTS
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\DEFAULT
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SECURITY
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SAM
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SOFTWARE
    * C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SYSTEM
    * C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
    * C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
    * C:\USERS\ALL USERS\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\D170E603AFD15CC2442279AF79CB9C32_76A95DD8-23B2-4EC8-AC8E-0362A6DCF90D
    * C:\USERS\ADMIN\APPDATA\LOCAL\TEMP\HSPERFDATA_ADMIN\6032
    * C:\SYSTEM VOLUME INFORMATION\{0C9FEA18-4534-11DE-BF67-001BB9FB9F7A}{3808876B-C176-4E48-B7AE-04046E6CC752}
    * C:\SYSTEM VOLUME INFORMATION\{3507940F-4B85-11DE-BAAD-001BB9FB9F7A}{3808876B-C176-4E48-B7AE-04046E6CC752}
    * C:\SYSTEM VOLUME INFORMATION\{0C9FEAA0-4534-11DE-BF67-001BB9FB9F7A}{3808876B-C176-4E48-B7AE-04046E6CC752}
    * C:\SYSTEM VOLUME INFORMATION\{BDDD2F1F-4598-11DE-9989-001BB9FB9F7A}{3808876B-C176-4E48-B7AE-04046E6CC752}
    * C:\PROGRAMDATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\D170E603AFD15CC2442279AF79CB9C32_76A95DD8-23B2-4EC8-AC8E-0362A6DCF90D
    * C:\BOOT\BCD

    Options
    Scanning engines:

    Scanning options:

    * Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
    * Use advanced heuristics

    Copyright © 1998-2009 Product support | Send virus sample to F-Secure
    F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide WEB pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name. This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.

    That didn't find anything unexpected. Is the computer running OK now?it seems like it is. Running normal speed right now. So i guess its gone. Iv run scans with everything i can think of.I think it's gone.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.I've done a little studying with your virus, so all I am asking is to go to my computer>c:\ and look for some EXE files that are labeled with number and have a picture on them of a colorful baby with weird blue eyes.


    When i was reaserching I saw about 40000 files like that.
    3108.

    Solve : Keyloggers?

    Answer»

    Klicker, give this a go......

    To remove and reinstall all USB controllers, follow these steps:

    Click Start, click Run, type sysdm.cpl in the Open box, and then click OK.
    Click the HARDWARE tab.
    Click the Device Manager button.
    Expand Universal Serial Bus controllers.
    Right-click EVERY device under the Universal Serial Bus controllers node, and then click Uninstall to remove them one at a time.
    Restart the computer, and then reinstall the USB controllers.
    Plug in the removable USB storage device, and then test to make sure that the issue is RESOLVED.

    3109.

    Solve : Firefox & IE search results go to wrong page. Can't run HijackThis. HELP Please?

    Answer»

    I've been reading the forums here and have learned a lot including there are some folks on this board that really help people in a jam. Here's my situation. Hopefully someone can help me.

    Sometime at the end of May my Firefox browser would go tot he wrong web page when I click on a link. For example I would search something in Google, click on one of the results and it would bring me to a totally wrong page or another search site. I ran McAfee (currently updated) and it found 2 viruses and deleted them. I ran it again and they were there again. I ran it in safe mode and it did not help. I attempted to restore to a point before the problems and my computer will not let me do it. So I have turned to this site for some help. I followed all of the direction and here are my results:

    I Downloaded CCleaner and used it successfully

    I downloaded SUPERAntiSpyware Free Edition. I attempted to install it and was unsuccessful. I received the following error.

    “SUPERAntiSpyware has encountered a problem and needs to close. We are sorry for the inconvenience.

    Error Signature
    AppName: superantispyware.exe AppVer: 4.26.0.1004 ModName: superantispyware.exe
    ModVer: 4.26.0.1004 Offset: 000039e0"

    I then downloaded Malwarebytes' Anti-Malware and installed it. When I attempted to open it nothing happened. I used the randmbam.exe program and it worked. I attached the log.

    I downloaded HijackThis, installed it and renamed the exe file to Sniper.exe. It will not run. I double click on it and nothing happens. I tried running it under its original name and it still did not work.

    This is driving me crazy!!

    Josh


    [attachment deleted by admin]Try running the programs in safe mode, same as McAfee, if you haven't already.I did earlier and it didn't work. That was before I got Malwarebytes to work! SUPERAntiSpyware still gave me an error but HijackThis worked. Here is the log and thanks for the suggestion!

    ***Update***

    I was finally able to run all of the programs in normal mode. I redid all of the steps and here are the logs.

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 06/04/2009 at 03:24 AM

    Application Version : 4.26.1004

    Core Rules Database Version : 3923
    Trace Rules Database Version: 1867

    Scan type : Complete Scan
    Total Scan Time : 05:14:32

    Memory items scanned : 532
    Memory threats detected : 0
    Registry items scanned : 6057
    Registry threats detected : 26
    File items scanned : 167679
    File threats detected : 46

    Trojan.Unknown Origin
    HKU\.DEFAULT\Software\ColdWare
    HKU\S-1-5-18\Software\ColdWare

    Rootkit.Agent/Gen-GXServ
    HKLM\Software\gxvxc
    HKLM\Software\gxvxc\disallowed
    HKLM\Software\gxvxc\disallowed#avp.exe
    HKLM\Software\gxvxc\disallowed#klif.sys
    HKLM\Software\gxvxc\disallowed#mrt.exe
    HKLM\Software\gxvxc\disallowed#spybotsd.exe
    HKLM\Software\gxvxc\disallowed#sasdifsv.sys
    HKLM\Software\gxvxc\disallowed#saskutil.sys
    HKLM\Software\gxvxc\disallowed#sasenum.sys
    HKLM\Software\gxvxc\disallowed#superantispyware.exe
    HKLM\Software\gxvxc\disallowed#szkg.sys
    HKLM\Software\gxvxc\disallowed#szserver.exe
    HKLM\Software\gxvxc\disallowed#mbam.exe
    HKLM\Software\gxvxc\disallowed#mbamswissarmy.sys
    HKLM\Software\gxvxc\disallowed#pctssvc.sys
    HKLM\Software\gxvxc\disallowed#pctcore.sys
    HKLM\Software\gxvxc\disallowed#mchinjdrv.sys
    HKLM\Software\gxvxc\disallowed#avgfwdx.sys
    HKLM\Software\gxvxc\disallowed#avgldx86.sys
    HKLM\Software\gxvxc\disallowed#avgmfx86.sys
    HKLM\Software\gxvxc\disallowed#avgrkx86.sys
    HKLM\Software\gxvxc\disallowed#avgtdix.sys
    HKLM\Software\gxvxc\disallowed#hijackthis.exe
    HKLM\Software\gxvxc\disallowed#combofix.exe

    Adware.Tracking Cookie
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][4].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][5].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt



    Malwarebytes' Anti-Malware 1.37
    Database version: 2227
    Windows 5.1.2600 Service Pack 3

    6/4/2009 6:37:12 AM
    mbam-log-2009-06-04 (06-37-12).txt

    Scan type: Quick Scan
    Objects scanned: 102406
    Time elapsed: 7 minute(s), 24 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:40:38 AM, on 6/4/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
    C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\StartupMonitor.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
    C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\SUPERAntiSpyware\Karate Chop.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Trend Micro\HijackThis\Sniper.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
    O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed LAUNCHER] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
    O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /ini "uinstaller.ini" /fromrun /starthidden
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175650032531
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175650027171
    O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

    --
    End of file - 8635 bytes


    [attachment deleted by admin]Download DDS by sUBs and save it to your desktop. Alternate DDS download link

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.Thanks for helping me out. Here are the logs.


    DDS (Ver_09-05-14.01) - NTFSx86
    Run by Owner at 20:14:38.18 on Thu 06/04/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.250 [GMT -5:00]

    AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
    C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\StartupMonitor.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
    C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\SUPERAntiSpyware\Karate Chop.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Microsoft Money 2007\MNYCoreFiles\mnybbsvc.exe
    C:\Program Files\Microsoft Office\Office10\1033\msohelp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Money 2007\MNYCoreFiles\mnybb.exe
    C:\Documents and Settings\Owner\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/ig?hl=en
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
    BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
    uRun: [Universal Installer] "c:\program files\comcastui\universal installer\uinstaller.exe" /fromrun /starthidden
    uRun: [Desktop Software] "c:\program files\comcastui\universal installer\uinstaller.exe" /ini "uinstaller.ini" /fromrun /starthidden
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [BCMSMMSG] BCMSMMSG.exe
    mRun: [EPSON Stylus CX4600 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
    mRun: [Name of App] c:\program files\samsung\fw liveupdate\FWManager.exe r
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Run StartupMonitor] StartupMonitor.exe
    mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    Trusted Zone: turbotax.com
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175650032531
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175650027171
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} - hxxp://216.249.24.62/code/iPIX-ImageWell-ipix.cab
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\577il9vi.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
    FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll

    ============= SERVICES / DRIVERS ===============

    R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-25 214024]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
    R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-6-2 210216]
    R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-2 359952]
    R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-2 144704]
    R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-2 606736]
    R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-2 79880]
    R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-2 35272]
    R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-2 40552]
    R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
    S3 ICAM3NT5;Intel USB Video Camera III;c:\windows\system32\drivers\Icam3.sys [2008-4-12 141056]
    S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-2 34216]

    =============== Created Last 30 ================

    2009-06-04 20:13--d-h---c:\windows\PIF
    2009-06-03 20:47--d-----c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
    2009-06-03 20:40--d-----c:\program files\SUPERAntiSpyware
    2009-06-03 20:40--d-----c:\docume~1\owner\applic~1\SUPERAntiSpyware.com
    2009-06-03 20:40--d-----c:\program files\common files\Wise Installation Wizard
    2009-06-02 20:13--d-----c:\docume~1\owner\applic~1\Malwarebytes
    2009-06-02 20:0040,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-02 20:0019,096a-------c:\windows\system32\drivers\mbam.sys
    2009-06-02 20:00--d-----c:\program files\Malwarebytes' Anti-Malware
    2009-06-02 20:00--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-06-02 19:52--d-----c:\program files\CCleaner
    2009-06-02 17:09--d-----C:\HJT
    2009-06-02 16:39--d-----c:\program files\Spybot - Search & Destroy2
    2009-06-02 16:246,751a-------c:\windows\system32\Config.MPF
    2009-06-02 06:4679,880a-------c:\windows\system32\drivers\mfeavfk.sys
    2009-06-02 06:4640,552a-------c:\windows\system32\drivers\mfesmfk.sys
    2009-06-02 06:4635,272a-------c:\windows\system32\drivers\mfebopk.sys
    2009-06-02 06:46120,136a-------c:\windows\system32\drivers\Mpfp.sys
    2009-06-02 06:45--d-----c:\program files\common files\McAfee
    2009-06-02 06:45--d-----c:\program files\McAfee.com
    2009-06-02 06:45--d-----c:\program files\McAfee
    2009-06-02 06:4134,216a-------c:\windows\system32\drivers\mferkdk.sys
    2009-06-01 21:3681,920a-------c:\windows\system32\Startup.cpl
    2009-06-01 21:26--d-----c:\program files\Trend Micro
    2009-06-01 21:15--d-----c:\program files\Spybot - Search & Destroy
    2009-06-01 21:15--d-----c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

    ==================== Find3M ====================

    2009-06-04 16:3827,584a-------c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
    2009-03-09 14:085,248a-------c:\windows\system32\giveio.sys
    2009-03-09 05:19410,984a-------c:\windows\system32\deploytk.dll
    2008-08-22 03:0732,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082220080823\index.dat

    ============= FINISH: 20:15:25.04 ===============


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-05-14.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/3/2007 7:38:08 PM
    System Uptime: 6/4/2009 6:18:42 AM (14 hours ago)

    Motherboard: Dell Computer Corp. | | 0G1548
    Processor: Intel(R) Pentium(R) 4 CPU 2.20GHz | Microprocessor | 2192/400mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 74 GiB total, 10.586 GiB free.
    D: is CDROM ()
    E: is CDROM (CDFS)
    G: is FIXED (FAT32) - 466 GiB total, 55.595 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP800: 3/7/2009 12:07:04 AM - System Checkpoint
    RP801: 3/8/2009 12:09:04 AM - System Checkpoint
    RP802: 3/9/2009 2:09:04 AM - System Checkpoint
    RP803: 3/10/2009 3:54:35 AM - System Checkpoint
    RP804: 3/11/2009 9:12:08 AM - Software Distribution Service 3.0
    RP805: 3/12/2009 10:03:27 AM - System Checkpoint
    RP806: 3/13/2009 11:25:35 AM - System Checkpoint
    RP807: 3/14/2009 2:00:20 AM - Software Distribution Service 3.0
    RP808: 3/14/2009 6:47:21 PM - Removed Java(TM) 6 Update 11
    RP809: 3/14/2009 6:48:11 PM - Installed Java(TM) 6 Update 12
    RP810: 3/15/2009 9:17:24 PM - System Checkpoint
    RP811: 3/16/2009 10:06:58 PM - System Checkpoint
    RP812: 3/17/2009 10:21:12 PM - System Checkpoint
    RP813: 3/18/2009 11:54:30 PM - System Checkpoint
    RP814: 3/20/2009 12:20:43 AM - System Checkpoint
    RP815: 3/21/2009 2:20:39 AM - System Checkpoint
    RP816: 3/22/2009 4:20:39 AM - System Checkpoint
    RP817: 3/23/2009 11:00:28 AM - System Checkpoint
    RP818: 3/24/2009 7:40:03 PM - System Checkpoint
    RP819: 3/25/2009 9:03:27 PM - System Checkpoint
    RP820: 3/26/2009 9:33:12 PM - System Checkpoint
    RP821: 3/27/2009 11:02:10 PM - System Checkpoint
    RP822: 3/29/2009 1:14:10 AM - System Checkpoint
    RP823: 3/30/2009 9:30:23 AM - System Checkpoint
    RP824: 3/31/2009 11:27:48 AM - System Checkpoint
    RP825: 4/1/2009 1:18:00 PM - System Checkpoint
    RP826: 4/2/2009 6:38:40 PM - System Checkpoint
    RP827: 4/3/2009 9:14:18 PM - System Checkpoint
    RP828: 4/5/2009 1:29:15 PM - System Checkpoint
    RP829: 4/7/2009 7:26:07 AM - System Checkpoint
    RP830: 4/8/2009 8:12:54 AM - System Checkpoint
    RP831: 4/9/2009 10:58:33 AM - System Checkpoint
    RP832: 4/10/2009 1:01:47 PM - System Checkpoint
    RP833: 4/11/2009 2:47:38 PM - System Checkpoint
    RP834: 4/13/2009 5:50:59 PM - System Checkpoint
    RP835: 4/14/2009 9:26:48 PM - System Checkpoint
    RP836: 4/15/2009 4:34:01 PM - Software Distribution Service 3.0
    RP837: 4/16/2009 4:55:18 PM - System Checkpoint
    RP838: 4/17/2009 5:03:37 PM - Installed Java(TM) 6 Update 13
    RP839: 4/19/2009 7:18:19 AM - System Checkpoint
    RP840: 4/20/2009 7:53:20 AM - System Checkpoint
    RP841: 4/21/2009 8:12:10 AM - System Checkpoint
    RP842: 4/22/2009 10:12:22 AM - System Checkpoint
    RP843: 4/23/2009 12:52:15 PM - System Checkpoint
    RP844: 4/24/2009 2:12:15 PM - System Checkpoint
    RP845: 4/25/2009 4:13:25 PM - System Checkpoint
    RP846: 4/26/2009 6:12:18 PM - System Checkpoint
    RP847: 4/27/2009 10:17:25 PM - System Checkpoint
    RP848: 4/29/2009 12:26:21 AM - System Checkpoint
    RP849: 4/30/2009 6:41:06 AM - System Checkpoint
    RP850: 5/1/2009 3:49:58 PM - System Checkpoint
    RP851: 5/2/2009 5:36:39 PM - System Checkpoint
    RP852: 5/3/2009 8:41:18 PM - System Checkpoint
    RP853: 5/4/2009 9:22:37 PM - System Checkpoint
    RP854: 5/5/2009 10:49:44 PM - System Checkpoint
    RP855: 5/7/2009 6:46:08 AM - System Checkpoint
    RP856: 5/8/2009 8:42:28 AM - System Checkpoint
    RP857: 5/9/2009 11:14:37 AM - System Checkpoint
    RP858: 5/10/2009 12:07:22 PM - System Checkpoint
    RP859: 5/11/2009 8:51:41 PM - System Checkpoint
    RP860: 5/12/2009 10:13:56 PM - System Checkpoint
    RP861: 5/13/2009 7:06:51 AM - Software Distribution Service 3.0
    RP862: 5/14/2009 8:44:18 AM - System Checkpoint
    RP863: 5/15/2009 8:45:18 AM - System Checkpoint
    RP864: 5/16/2009 9:21:38 AM - System Checkpoint
    RP865: 5/16/2009 12:50:31 PM - Installed TBS WMP Plug-in
    RP866: 5/16/2009 12:52:27 PM - Configured TBS WMP Plug-in
    RP867: 5/17/2009 7:53:29 PM - System Checkpoint
    RP868: 5/18/2009 8:12:12 PM - System Checkpoint
    RP869: 5/19/2009 9:48:50 PM - System Checkpoint
    RP870: 5/20/2009 10:07:29 PM - System Checkpoint
    RP871: 5/21/2009 10:22:47 PM - System Checkpoint
    RP872: 5/23/2009 12:21:44 AM - System Checkpoint
    RP873: 5/24/2009 2:21:44 AM - System Checkpoint
    RP874: 5/25/2009 10:49:42 AM - System Checkpoint
    RP875: 5/26/2009 3:33:57 PM - System Checkpoint
    RP876: 5/26/2009 8:50:31 PM - Installed TBS WMP Plug-in
    RP877: 6/3/2009 8:34:27 PM - Microsoft OneCare Protection Checkpoint

    ==== Installed Programs ======================


    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 7.0
    Adobe Reader 8.1.4
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft Software Suite
    Audacity 1.2.6
    AutoUpdate
    BCM V.92 56K Modem
    Bonjour
    Broadcom 440x 10/100 Integrated Controller
    CCleaner (remove only)
    Comcast Universal Installer v1.2
    Critical Update for Windows Media Player 11 (KB959772)
    Dell ResourceCD
    DellConnect
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    DVD Decrypter (Remove Only)
    DVD Shrink 3.2
    EPSON CardMonitor
    EPSON Copy Utility 3
    EPSON CX4600 Reference Guide
    EPSON PhotoStarter3.2
    EPSON Printer Software
    EPSON Scan
    EPSON Smart Panel
    EuroTalk Talk Now Plus!
    FW LiveUpdate
    Garmin Communicator Plugin
    Garmin POI Loader
    Google Earth
    Google Gmail Notifier
    Google Updater
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Intel(R) Extreme Graphics Driver
    iTunes
    Java(TM) 6 Update 13
    Java(TM) 6 Update 2
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    LightScribe 1.4.89.1
    Malwarebytes' Anti-Malware
    McAfee SecurityCenter
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Money 2007
    Microsoft Money Shared Libraries
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional with FrontPage
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    MobileMe Control Panel
    Mozilla Firefox (3.0.10)
    Nero Suite
    QuickTime
    ScanToWeb
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 8 (KB917734)
    Security Update for Windows Media Player 9 (KB911565)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    SoundMAX
    SSC Service Utility v4.20
    StartupMonitor
    SUPERAntiSpyware Free Edition
    TBS WMP Plug-in
    TurboTax 2008
    TurboTax 2008 WinPerFedFormset
    TurboTax 2008 WinPerProgramHelp
    TurboTax 2008 WinPerReleaseEngine
    TurboTax 2008 WinPerTaxSupport
    TurboTax 2008 WinPerUserEducation
    TurboTax 2008 wrapper
    TurboTax Deluxe 2007
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    WD Diagnostics
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3

    ==== Event Viewer Messages From Past Week ========

    6/2/2009 9:03:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MPFP MRxSmb NetBIOS NetBT OMCI RasAcd Rdbss Tcpip
    6/2/2009 8:29:30 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde
    6/2/2009 8:28:50 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    6/2/2009 7:32:50 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
    6/2/2009 7:22:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    6/2/2009 5:17:54 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McShield with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
    6/1/2009 9:45:00 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/1/2009 9:42:41 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb MSFWHLPR NetBIOS NetBT OMCI RasAcd Rdbss Tcpip
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The OneCare Firewall service depends on the MSFWDrv service which failed to start because of the following error: The dependency service or group failed to start.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The Network Location Awareness (NLA) service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The MSFWDrv service depends on the IP Traffic Filter Driver service which failed to start because of the following error: The dependency service or group failed to start.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The IP Traffic Filter Driver service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:41 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/1/2009 9:42:18 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    6/1/2009 9:37:15 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
    6/1/2009 8:28:56 PM, error: OneCareMP [1008] -
    6/1/2009 6:34:25 AM, error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 2 time(s).
    6/1/2009 6:28:59 AM, error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 1 time(s).
    5/31/2009 8:51:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
    5/31/2009 8:51:06 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    5/31/2009 8:46:58 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
    5/31/2009 8:46:46 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT OMCI RasAcd Rdbss Tcpip

    ==== End Of File ===========================
    Go to Add or Remove Programs and uninstall (if found):

    - AutoUpdate

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    DO NOT run it yet!

    Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they COULD damage the workings of your system

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    DDS::
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    ----------

    Your Java is out of date.

    Older versions have vulnerabilities that malicious sites can use to infect your system.

    First install the new Sun Java Runtime Environment

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close all browser windows before beginning the install.

    Remove the old version(s)

    Download JavaRa

    • Unzip the file and open the JavaRa.exe
    • Click Remove Older Versions
    • JavaRa will search for and remove any outdated version of Java and remove any that are found.
    • Click Additional Tasks
    • Place a check next to Remove Useless JRE Files and click Go
    • Exit JavaRa
    • Delete the JavaRa files from the Desktop
    .
    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.
    I followed your instructions. Here is the combofix log.


    ComboFix 09-06-04.06 - Owner 06/04/2009 21:04.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.310 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\drivers\gxvxchymaibdhttpwlxvbsqvufafdfexobsvv.sys
    c:\windows\system32\gxvxcuvhtqgtfqlstwowdsocppjbmfwcqjuee.dll
    c:\windows\system32\gxvxcviyiautbldtlyvdwhxtekonohcxjjvbv.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_GXVXCSERV.SYS


    ((((((((((((((((((((((((( Files Created from 2009-05-05 to 2009-06-05 )))))))))))))))))))))))))))))))
    .

    2009-06-05 01:13 . 2009-06-05 01:13--------d--h--w-c:\windows\PIF
    2009-06-04 01:48 . 2009-06-04 11:21117760----a-w-c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-06-04 01:47 . 2009-06-04 01:47--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-06-04 01:40 . 2009-06-04 01:41--------d-----w-c:\program files\SUPERAntiSpyware
    2009-06-04 01:40 . 2009-06-04 01:40--------d-----w-c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
    2009-06-04 01:40 . 2009-06-04 01:40--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-06-03 01:13 . 2009-06-03 01:13--------d-----w-c:\documents and settings\Owner\Application Data\Malwarebytes
    2009-06-03 01:00 . 2009-05-26 18:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-03 01:00 . 2009-06-03 01:13--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2009-06-03 01:00 . 2009-06-03 01:00--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-06-03 01:00 . 2009-05-26 18:1919096----a-w-c:\windows\system32\drivers\mbam.sys
    2009-06-03 00:52 . 2009-06-03 00:52--------d-----w-c:\program files\CCleaner
    2009-06-02 22:09 . 2009-06-03 00:49--------d-----w-C:\HJT
    2009-06-02 21:39 . 2009-06-02 21:51--------d-----w-c:\program files\Spybot - Search & Destroy2
    2009-06-02 11:46 . 2009-03-25 16:0640552----a-w-c:\windows\system32\drivers\mfesmfk.sys
    2009-06-02 11:46 . 2009-03-25 16:0679880----a-w-c:\windows\system32\drivers\mfeavfk.sys
    2009-06-02 11:46 . 2009-03-25 16:0635272----a-w-c:\windows\system32\drivers\mfebopk.sys
    2009-06-02 11:46 . 2008-10-23 18:08120136----a-w-c:\windows\system32\drivers\Mpfp.sys
    2009-06-02 11:45 . 2009-06-02 11:46--------d-----w-c:\program files\Common Files\McAfee
    2009-06-02 11:45 . 2009-06-02 11:45--------d-----w-c:\program files\McAfee.com
    2009-06-02 11:45 . 2009-06-04 02:59--------d-----w-c:\program files\McAfee
    2009-06-02 11:41 . 2009-03-25 16:0534216----a-w-c:\windows\system32\drivers\mferkdk.sys
    2009-06-02 03:44 . 2009-06-02 03:4427584----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-06-02 02:38 . 2009-06-02 02:381078----a-r-c:\documents and settings\Owner\Application Data\Microsoft\Installer\{76EFAC4F-1712-401F-B2AE-590B170C9BCE}\_60c11ac7.exe
    2009-06-02 02:26 . 2009-06-03 01:05--------d-----w-c:\program files\Trend Micro
    2009-06-02 02:15 . 2009-06-02 22:10--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-02 02:15 . 2009-06-02 03:49--------d-----w-c:\program files\Spybot - Search & Destroy
    2009-06-01 11:22 . 2009-06-01 11:22--------d-----w-c:\documents and settings\Owner\Local Settings\Application Data\SupportSoft

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-04 22:39 . 2008-11-27 04:37--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
    2009-06-03 00:31 . 2008-12-21 15:53--------d-----w-c:\program files\Coupons
    2009-06-02 21:31 . 2007-04-04 03:25--------d-----w-c:\documents and settings\All Users\Application Data\McAfee
    2009-06-02 11:35 . 2007-04-04 01:00--------d--h--w-c:\documents and settings\Owner\Application Data\GTek
    2009-05-27 15:11 . 2008-10-04 23:01--------d-----w-c:\documents and settings\LocalService\Application Data\SACore
    2009-05-27 01:50 . 2007-04-04 00:54--------d--h--w-c:\program files\InstallShield Installation Information
    2009-05-25 15:28 . 2007-04-05 02:15--------d-----w-c:\documents and settings\Owner\Application Data\U3
    2009-05-25 04:19 . 2007-10-24 23:42--------d-----w-c:\documents and settings\Owner\Application Data\LimeWire
    2009-04-19 12:05 . 2009-04-19 12:04--------d-----w-c:\program files\iTunes
    2009-04-19 12:05 . 2009-04-19 12:04--------d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    2009-04-19 12:04 . 2009-04-19 12:04--------d-----w-c:\program files\iPod
    2009-04-19 12:04 . 2007-07-08 17:37--------d-----w-c:\program files\Common Files\Apple
    2009-04-19 12:02 . 2009-04-19 12:02--------d-----w-c:\program files\Bonjour
    2009-04-19 12:00 . 2009-04-19 11:59--------d-----w-c:\program files\QuickTime
    2009-04-19 11:46 . 2009-04-19 11:4675048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
    2009-04-17 22:04 . 2007-10-24 23:40--------d-----w-c:\program files\Java
    2009-04-17 22:01 . 2009-04-17 22:01152576----a-w-c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-04-10 18:03 . 2009-04-10 18:03--------d-----w-c:\windows\system32\config\systemprofile\Application Data\SACore
    2009-03-25 16:06 . 2009-03-25 16:06214024----a-w-c:\windows\system32\drivers\mfehidk.sys
    2009-03-19 21:32 . 2009-03-19 21:3223400----a-w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
    2009-03-19 21:32 . 2008-01-29 17:0123400----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
    2009-03-15 00:26 . 2009-03-15 00:26152576----a-w-c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
    2009-03-09 19:08 . 2009-03-09 19:085248----a-w-c:\windows\system32\giveio.sys
    2009-03-09 10:19 . 2008-12-05 15:35410984----a-w-c:\windows\system32\deploytk.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-12 1961984]
    "Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
    "Desktop Software"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
    "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
    "EPSON Stylus CX4600 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" [2004-03-04 98304]
    "Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\FWManager.exe" [2008-07-07 675935]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-03-25 645328]
    "BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
    "Run StartupMonitor"="StartupMonitor.exe" - c:\windows\StartupMonitor.exe [2000-05-20 86016]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-4-6 113664]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 17:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
    "wave"= serwvdrv.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
    R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/2/2009 6:49 AM 210216]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-30 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2009-06-05 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-27 05:06]

    2009-06-02 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-02 15:53]

    2009-06-02 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-02 15:53]
    .
    - - - - ORPHANS REMOVED - - - -

    SafeBoot-mfehidk
    SafeBoot-mferkdk
    SafeBoot-mfetdik
    SafeBoot-mfetdik.sys
    SafeBoot-procexp90.Sys


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/ig?hl=en
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
    Trusted Zone: turbotax.com
    FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\577il9vi.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-04 21:10
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(632)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    Completion time: 2009-06-05 21:13
    ComboFix-quarantined-files.txt 2009-06-05 02:13

    Pre-Run: 11,309,228,032 bytes free
    Post-Run: 11,376,951,296 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

    191--- E O F ---2009-05-13 12:12
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete: ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if REQUIRED.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Run CCleaner.

    ----------

    Use the Kaspersky Lab Online Scanner

    In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

    • Click on SCAN NOW
    • Click Accept.
    • The program will then begin downloading the latest definition files.
    • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
    • The scan will TAKE a while, so be patient and let it finish.
    When the scan is done, in the Scan is complete window, any infection is displayed.
    There is no option to clean/disinfect, however, we need to analyze the information on the report.

    To obtain the report:
    Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop.
    • In the File name area use KScan, or something similar.
    • In Save as type: click the drop arrow and select: Text file [*.txt]
    • Then, click: Save


    Copy and paste the Kaspersky Online Scanner Report in your next reply.

    Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

    If needed, this animation will guide you through the process.Followed your instructions and here is the scan


    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0 REPORT
    Friday, June 5, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Friday, June 05, 2009 05:55:16
    Records in database: 2309311
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    G:\

    Scan statistics:
    Files scanned: 174908
    Threat name: 0
    Infected objects: 0
    Suspicious objects: 0
    Duration of the scan: 03:57:51

    No malware has been detected. The scan area is clean.

    The selected area was scanned.
    Looks good.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Well all I can say is Thank You!. Everything seems to working perfectly now. You have truly been a help and I can't say thank you enough. I would like to make a donation to a charity or website of your choice as a thank you for your time and your help. Let me know where to make it. Thanks again!
    3110.

    Solve : Multiple infections, problems connecting to Internet?

    Answer»

    Your welcome.

    Safe SURFING...

    3111.

    Solve : Virus removal?

    Answer»

    Hi I had posted at an earlier date about some viruses I had in my computer. I followed the steps given to me by patio for malware removal. I ran a scan and the viruses are gone but Hijack says I may need to remove some things but not to before I consult an expert. Here are the logs. Do I need to do anything more?


    Here is the superanti spyware log...

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 05/23/2009 at 12:58 PM

    Application Version : 4.26.1002

    Core Rules Database Version : 3908
    Trace Rules Database Version: 1853

    Scan type : Complete Scan
    Total Scan Time : 00:45:29

    Memory items scanned : 553
    Memory threats detected : 0
    Registry items scanned : 4899
    Registry threats detected : 0
    File items scanned : 64111
    File threats detected : 1

    Adware.Casino Games (Golden Palace Casino)
    C:\HOLDEMV6\CASINO.EXE




    Here is the log for the anti-malware


    Malwarebytes' Anti-Malware 1.36
    Database version: 2170
    Windows 5.1.2600 Service Pack 3

    5/23/2009 1:26:08 PM
    mbam-log-2009-05-23 (13-26-08).txt

    Scan type: Quick Scan
    Objects scanned: 75560
    Time elapsed: 2 minute(s), 44 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 16

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\WINDOWS\system32\NetworkService32 (Worm.Archive) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\NetworkService32\117.crack.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\117.crack.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\118.keygen.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\118.keygen.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\119.serial.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\119.serial.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\120.setup.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\120.setup.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\121.music.mp3 (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\121.music.mp3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\122.music.snd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\122.music.snd.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\123.music.au (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\123.music.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\124.video.wmv (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\124.video.wmv.kwd (Worm.Archive) -> Quarantined and deleted successfully.


    Hijack This log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:51:24 PM, on 5/23/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\INF\MSI\SlowDownCPU\SlowDownCPU.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\Eastlink Internet Security\Common\FSM32.EXE
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\hphmon05.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Eastlink Internet Security\Anti-VIRUS\fsgk32st.exe
    C:\Program Files\Eastlink Internet Security\Common\FSMA32.EXE
    C:\Program Files\Eastlink Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\Eastlink Internet Security\Common\FSMB32.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Eastlink Internet Security\Common\FCH32.EXE
    C:\Program Files\Eastlink Internet Security\Common\FAMEH32.EXE
    C:\Program Files\Eastlink Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\Eastlink Internet Security\FSGUI\fsguidll.exe
    C:\Program Files\Eastlink Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Eastlink Internet Security\FSAUA\program\fsaua.exe
    C:\Program Files\Eastlink Internet Security\FWES\Program\fsdfwd.exe
    C:\Program Files\Eastlink Internet Security\FSAUA\program\fsus.exe
    C:\Program Files\Eastlink Internet Security\Anti-Virus\fsav32.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myeastlink.ca/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! TOOLBAR - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [SlowDownCPU] C:\WINDOWS\INF\MSI\SlowDownCPU\SlowDownCPU.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Eastlink Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Eastlink Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Exif Launcher.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Stacy Wessell\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Stacy Wessell\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} (NeroVersionCheckerControl Control) - http://www.nero.com/doc/NeroVersionCheckerControl.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\WINDOWS\System32\dmdlgs32.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: c65d58d579 - C:\WINDOWS\System32\dmdlgs32.dll (file missing)
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Eastlink Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Eastlink Internet Security\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Eastlink Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Eastlink Internet Security\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Eastlink Internet Security\ORSP Client\fsorsp.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 9762 bytes



    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - O20 - AppInit_DLLs: C:\WINDOWS\System32\dmdlgs32.dll

    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis.

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **NOTE: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixHello, I followed the last set of instructions and Ran Combo Fix here is the log for that.

    Combofix Log:

    ComboFix 09-05-26.05 - Stacy Wessell 05/28/2009 10:06.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.703.314 [GMT -3:00]
    Running from: c:\documents and settings\Stacy Wessell\Desktop\PCRepair.exe
    AV: Eastlink Internet Security Services 8.02 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
    FW: Eastlink Internet Security Services 8.02 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Stacy Wessell\Application Data\02000000ac9a31c7579C.manifest
    c:\documents and settings\Stacy Wessell\Application Data\02000000ac9a31c7579O.manifest
    c:\documents and settings\Stacy Wessell\Application Data\02000000ac9a31c7579P.manifest
    c:\documents and settings\Stacy Wessell\Application Data\02000000ac9a31c7579S.manifest
    c:\windows\system32\EV02
    c:\windows\system32\GroupPolicy000.dat
    c:\windows\system32\ZblRPFPG3mLsS.vbs

    .
    ((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-28 )))))))))))))))))))))))))))))))
    .

    2009-05-25 19:07 . 2009-05-06 18:064784464----a-wc:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{7D42730E-E8A7-4BB8-B0E9-7DA8C36AB4D0}\mpengine.dll
    2009-05-24 16:05 . 2009-05-24 16:0557344----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-2172ceff-n\Decora-SSE.dll
    2009-05-24 16:05 . 2009-05-24 16:0524064----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-47437baa-n\Decora-D3D.dll
    2009-05-24 16:05 . 2009-05-24 16:0520480----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-496f5b54-n\jogl_awt.dll
    2009-05-24 16:05 . 2009-05-24 16:05114688----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-496f5b54-n\jogl_cg.dll
    2009-05-24 16:05 . 2009-05-24 16:05315392----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-496f5b54-n\jogl.dll
    2009-05-24 16:05 . 2009-05-24 16:05499712----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-25adae60-n\msvcp71.dll
    2009-05-24 16:05 . 2009-05-24 16:05348160----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-25adae60-n\msvcr71.dll
    2009-05-24 16:05 . 2009-05-24 16:0520480----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-16c72392-n\gluegen-rt.dll
    2009-05-24 16:05 . 2009-05-24 16:05499712----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-25adae60-n\jmc.dll
    2009-05-23 19:37 . 2009-05-23 19:37--------d-----wc:\program files\Trend Micro
    2009-05-23 16:21 . 2009-05-23 16:21--------d-----wc:\documents and settings\Stacy Wessell\Application Data\Malwarebytes
    2009-05-23 16:21 . 2009-04-06 18:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-05-23 16:21 . 2009-04-06 18:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-05-23 16:21 . 2009-05-23 16:21--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-05-23 16:21 . 2009-05-23 16:21--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-05-23 15:08 . 2009-05-24 14:00117760----a-wc:\documents and settings\Stacy Wessell\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-05-23 15:07 . 2009-05-23 15:07--------d-----wc:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-05-23 15:07 . 2009-05-23 15:07--------d-----wc:\program files\SUPERAntiSpyware
    2009-05-23 15:07 . 2009-05-23 15:07--------d-----wc:\documents and settings\Stacy Wessell\Application Data\SUPERAntiSpyware.com
    2009-05-23 15:07 . 2009-05-23 15:07--------d-----wc:\program files\Common Files\Wise Installation Wizard
    2009-05-23 14:57 . 2009-05-23 14:58--------d-----wc:\program files\CCleaner
    2009-05-19 22:31 . 2009-05-06 18:064784464----a-wc:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
    2009-05-19 22:30 . 2009-05-19 22:30--------d-----wc:\program files\Windows Defender
    2009-05-19 22:26 . 2009-05-19 22:2736---h--rc:\windows\sued.dat
    2009-05-19 21:14 . 2009-05-19 21:1464160----a-wc:\windows\system32\drivers\Lbd.sys
    2009-05-19 21:14 . 2009-05-19 21:1464160----a-wc:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
    2009-05-19 21:12 . 2009-05-19 21:12--------dc-h--wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-05-19 21:12 . 2009-03-12 08:172902048-c--a-wc:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-28 05:12 . 2008-08-23 23:38--------d-----wc:\program files\Eastlink Internet Security
    2009-05-27 17:44 . 2008-08-29 14:01--------d-----wc:\documents and settings\Stacy Wessell\Application Data\LimeWire
    2009-05-26 13:33 . 2009-04-24 12:52--------d-----wc:\program files\Full Tilt Poker
    2009-05-24 22:16 . 2009-03-10 19:35--------d-----wc:\program files\PacificPoker
    2009-05-23 19:25 . 2008-08-29 14:00--------d-----wc:\program files\Java
    2009-05-23 19:24 . 2009-04-10 15:55152576----a-wc:\documents and settings\Stacy Wessell\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-05-19 21:14 . 2008-11-02 13:48--------d-----wc:\documents and settings\All Users\Application Data\Lavasoft
    2009-05-19 21:01 . 2008-10-01 16:26--------d---a-wc:\documents and settings\All Users\Application Data\TEMP
    2009-05-19 12:32 . 2009-03-10 19:35--------d-----wc:\documents and settings\Stacy Wessell\Application Data\PacificPoker
    2009-05-15 15:15 . 2008-10-29 13:40--------d-----wc:\program files\LivePix 2.0
    2009-05-15 14:44 . 2008-08-26 17:381080----a-wc:\windows\AUTOLNCH.REG
    2009-05-14 18:46 . 2008-11-14 18:01--------d-----wc:\program files\PKR
    2009-04-27 15:54 . 2008-09-29 11:09--------d-----wc:\program files\PokerStars
    2009-04-24 12:52 . 2008-08-25 09:53--------d--h--wc:\program files\InstallShield Installation Information
    2009-03-12 10:26 . 2009-03-12 01:5033408----a-wc:\windows\system32\drivers\fsbts.sys
    2009-03-09 08:19 . 2008-12-19 00:15410984----a-wc:\windows\system32\deploytk.dll
    2009-03-06 14:22 . 2004-08-04 12:00284160----a-wc:\windows\system32\pdh.dll
    2009-03-03 00:18 . 2004-08-04 12:00826368----a-wc:\windows\system32\wininet.dll
    2004-07-22 13:51 . 2004-07-22 13:513432656----a-wc:\program files\ManagedDX.CAB
    2004-07-20 01:58 . 2004-07-20 01:581156363----a-wc:\program files\BDANT.cab
    2004-07-20 01:53 . 2004-07-20 01:53976020----a-wc:\program files\BDAXP.cab
    2004-07-09 17:17 . 2004-07-09 17:1713265040----a-wc:\program files\dxnt.cab
    2004-07-09 12:13 . 2004-07-09 12:1315493481----a-wc:\program files\DirectX.cab
    2004-07-09 12:13 . 2004-07-09 12:13703080----a-wc:\program files\BDA.cab
    2004-07-09 07:08 . 2004-07-09 07:08472576----a-wc:\program files\dxsetup.exe
    2004-07-09 07:08 . 2004-07-09 07:082242560----a-wc:\program files\dsetup32.dll
    2004-07-09 06:03 . 2004-07-09 06:0362976----a-wc:\program files\DSETUP.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-01 68856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SlowDownCPU"="c:\windows\INF\MSI\SlowDownCPU\SlowDownCPU.exe" [2005-06-09 212992]
    "F-Secure Manager"="c:\program files\Eastlink Internet Security\Common\FSM32.EXE" [2009-02-19 182936]
    "F-Secure TNB"="c:\program files\Eastlink Internet Security\FSGUI\TNBUtil.exe" [2009-02-19 957024]
    "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]
    "HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-20 49152]
    "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-08-20 221184]
    "HPHmon05"="c:\windows\system32\hphmon05.exe" [2003-08-20 483328]
    "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
    "QuickFinder Scheduler"="c:\program files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" [2001-10-02 77887]
    "NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-08-07 155648]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-26 518488]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
    "VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2004-06-21 143360]
    "VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2004-10-01 53248]

    c:\documents and settings\Stacy Wessell\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-8-21 147456]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2008-8-25 200704]
    HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 15:05356352----a-wc:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=

    R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [3/11/2009 10:50 PM 33408]
    R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [8/23/2008 8:39 PM 79872]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/19/2009 6:14 PM 64160]
    R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Eastlink Internet Security\HIPS\drivers\fshs.sys [3/11/2009 10:49 PM 67808]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 2:22 PM 72944]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
    R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Eastlink Internet Security\Anti-Virus\minifilter\fsgk.sys [8/23/2008 8:38 PM 86648]
    R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Eastlink Internet Security\ORSP Client\fsorsp.exe [3/11/2009 10:49 PM 55904]
    R3 SlowDownCPU;SlowDownCPU;c:\windows\inf\MSI\SlowDownCPU\NTGLM7X.SYS [8/23/2008 7:36 PM 25088]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 4:06 PM 1005904]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]
    S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Eastlink Internet Security\Anti-Virus\win2k\fsfilter.sys [8/23/2008 8:38 PM 39776]
    S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Eastlink Internet Security\Anti-Virus\win2k\fsrec.sys [8/23/2008 8:38 PM 25184]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 21:14]

    2009-05-24 c:\windows\Tasks\HP DArC Task 2003-08-20 09:23ewlett-Packard77002003-08-20 17:57Y37S1325MJE.job
    - c:\program files\HP\hpcoretech\comp\hpdarc.exe [2003-08-20 17:57]

    2009-05-28 c:\windows\Tasks\HP Usg Daily.job
    - c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe [2008-08-24 21:23]

    2009-05-28 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]
    .
    - - - - ORPHANS REMOVED - - - -

    Notify-c65d58d579 - c:\windows\System32\dmdlgs32.dll
    SafeBoot-procexp90.Sys


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.myeastlink.ca/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    DPF: {680285A8-96D3-43DA-9D3D-51DD987D0B77} - hxxp://www.nero.com/doc/NeroVersionCheckerControl.cab
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-28 10:07
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan COMPLETED successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(620)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    Completion time: 2009-05-28 10:09
    ComboFix-quarantined-files.txt 2009-05-28 13:09

    Pre-Run: 138,389,540,864 bytes free
    Post-Run: 138,481,037,312 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    189--- E O F ---2009-05-25 19:07

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      How is the computer running now?
    All virus removed and computer running normal, thanks evil fantasy. so if I run into this problem again can I use the same steps to resolve. What was the - O20 - AppInit_DLLs: C:\WINDOWS\System32\dmdlgs32.dll that I removed when I ran HiJack this? thanks again

    Dwayne Austin
    I'm not sure what the dmdlgs32.dll was. I do know it wasn't supposed to be there.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    3112.

    Solve : help re: HJT log please.?

    Answer»

    ComboFix 09-06-07.02 - mike 07/06/2009 22:43:52.2 - NTFSx86
    Microsoft Windows XP HOME Edition 5.1.2600.3.1252.44.1033.18.959.488 [GMT 1:00]
    Running from: C:\Documents and Settings\mike\Desktop\Combo-Fix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: ZONEALARM Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    ((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
    .

    2009-06-07 21:19:29 . 2009-06-07 21:24:21 0 d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-06-07 16:22:51 . 2009-06-07 16:23:00 0 d-----w- C:\Program Files\Spybot - Search & Destroy
    2009-05-31 12:56:59 . 2009-05-31 13:02:31 0 d-----w- C:\Documents and Settings\mike\Application Data\HouseCall 6.6
    2009-05-30 11:00:55 . 2009-05-26 12:20:08 40160 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2009-05-30 11:00:54 . 2009-06-07 17:02:30 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
    2009-05-30 11:00:54 . 2009-05-26 12:19:56 19096 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
    2009-05-30 10:49:38 . 2009-05-31 09:56:35 0 d-----w- C:\Program Files\SUPERAntiSpyware
    2009-05-14 18:09:18 . 2009-05-14 18:09:18 0 d-----w- C:\Documents and Settings\mike\Local Settings\Application Data\Ahead

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-07 21:23:11 . 2008-12-27 14:36:49 0 d-----w- C:\Program Files\Google
    2009-06-07 21:05:23 . 2008-12-28 19:09:59 0 d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater
    2009-06-07 16:35:36 . 2008-12-28 18:43:30 0 d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-07 16:14:26 . 2009-04-02 20:16:59 117760 ----a-w- C:\Documents and Settings\mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-06-07 15:47:50 . 2009-06-07 15:48:26 1664000 ----a-w- C:\WINDOWS\Internet Logs\xDB5.tmp
    2009-05-31 13:10:13 . 2008-12-27 14:16:35 0 d-----w- C:\Program Files\Common Files\Wise Installation Wizard
    2009-05-31 10:24:47 . 2008-12-28 19:12:42 1324 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
    2009-05-28 16:53:21 . 2009-05-28 16:56:04 341504 ----a-w- C:\WINDOWS\Internet Logs\xDB4.tmp
    2009-05-27 17:32:38 . 2009-01-29 19:33:37 0 d-----w- C:\Documents and Settings\All Users\Application Data\WinZip
    2009-05-20 17:50:42 . 2008-12-27 13:59:29 11952 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
    2009-05-20 17:50:42 . 2008-12-27 13:59:25 325896 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
    2009-05-20 17:50:42 . 2008-12-27 13:59:24 27784 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
    2009-05-20 17:50:38 . 2008-12-27 13:59:28 108552 ----a-w- C:\WINDOWS\system32\drivers\avgtdix.sys
    2009-05-17 19:02:32 . 2009-05-18 18:44:20 322048 ----a-w- C:\WINDOWS\Internet Logs\xDB3.tmp
    2009-05-13 18:53:53 . 2008-12-27 19:51:33 0 d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2009-05-12 20:18:56 . 2009-05-13 18:11:08 2709504 ----a-w- C:\WINDOWS\Internet Logs\xDB2.tmp
    2009-04-17 18:36:45 . 2009-04-13 18:16:10 0 d-----w- C:\Program Files\Common Files\Adobe AIR
    2009-04-17 18:36:39 . 2009-04-13 18:09:58 38208 ----a-w- C:\Documents and Settings\mike\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2009-04-17 18:23:20 . 2009-04-17 18:23:20 0 d-----w- C:\Program Files\Secunia
    2009-04-13 18:15:38 . 2008-12-27 19:16:34 0 d-----w- C:\Program Files\Common Files\Adobe
    2009-04-13 18:10:05 . 2009-04-13 18:10:05 0 d-----w- C:\Documents and Settings\mike\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2009-04-13 17:59:25 . 2008-12-27 14:11:26 0 d-----w- C:\Program Files\Java
    2009-04-13 17:58:33 . 2009-04-13 17:58:33 152576 ----a-w- C:\Documents and Settings\mike\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-04-09 17:37:26 . 2009-04-02 19:28:36 0 d-----w- C:\Documents and Settings\All Users\Application Data\STOPzilla!
    2009-03-24 11:03:08 . 2009-03-24 11:03:08 7808 ----a-w- C:\WINDOWS\system32\drivers\psi_mf.sys
    2009-03-15 20:00:26 . 2009-03-16 09:29:22 2754560 ----a-w- C:\WINDOWS\Internet Logs\xDB1.tmp
    .

    ((((((((((((((((((((((((((((( [emailprotected]_15.59.06 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-06-07 21:25:25 . 2009-06-07 21:25:25 16384 C:\WINDOWS\Temp\Perflib_Perfdata_664.dat
    + 2006-02-28 12:00:00 . 2009-06-07 21:29:29 60740 C:\WINDOWS\system32\perfc009.dat
    - 2006-02-28 12:00:00 . 2009-06-07 15:52:29 60740 C:\WINDOWS\system32\perfc009.dat
    + 2006-02-28 12:00:00 . 2009-06-07 21:29:29 400772 C:\WINDOWS\system32\perfh009.dat
    - 2006-02-28 12:00:00 . 2009-06-07 15:52:29 400772 C:\WINDOWS\system32\perfh009.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "STManager"="C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" [2003-10-16 13:25:32 118784]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 00:12:28 1695232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38:38 866816]
    "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-05-20 17:50:39 1947928]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50:42 155648]
    "SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22:30 155648]
    "OpwareSE3"="C:\Program Files\ScanSoft\OmniPageSE3.0\OpwareSE3.exe" [2005-05-23 19:22:14 57344]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00:48 33648]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-09-17 23:55:00 13574144]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-09-17 23:55:00 86016]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 15:18:56 981904]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-03-09 04:19:17 148888]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 16:10:28 35696]
    "nwiz"="nwiz.exe" - C:\WINDOWS\system32\nwiz.exe [2008-09-17 23:55:00 1657376]

    C:\Documents and Settings\mike\Start Menu\Programs\STARTUP\
    Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe [2009-3-24 748840]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-9-23 415072]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 09:13:36 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05:34 356352 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-05-20 17:50:42 11952 ----a-w- C:\WINDOWS\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LUMIX Simple Viewer.lnk
    backup=C:\WINDOWS\pss\LUMIX Simple Viewer.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "RTHDCPL"=RTHDCPL.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\SpeedTouch\\Dr SpeedTouch\\drst.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\drivers\avgldx86.sys [27/12/2008 14:59:25 325896]
    R1 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\drivers\avgtdix.sys [27/12/2008 14:59:28 108552]
    R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [26/05/2009 10:05:54 9968]
    R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [26/05/2009 10:05:52 72944]
    R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [27/12/2008 14:59:21 908568]
    R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [27/12/2008 14:59:20 298776]
    R2 olMntrService;olMntrService;C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe [03/01/2006 12:36:32 69632]
    R3 PSI;PSI;C:\WINDOWS\system32\drivers\psi_mf.sys [24/03/2009 12:03:08 7808]
    S2 gupdate1c969202e758636;Google Update Service (gupdate1c969202e758636);C:\Program Files\Google\Update\GoogleUpdate.exe [28/12/2008 20:12:04 133104]
    S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe --> C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [?]
    S3 SASENUM;SASENUM;C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [26/05/2009 10:05:56 7408]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-07 C:\WINDOWS\Tasks\Google Software Updater.job
    - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-27 14:36:54 . 2009-03-26 19:18:30]

    2009-06-07 C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
    - C:\Program Files\Google\Update\GoogleUpdate.exe [2008-12-28 19:12:04 . 2009-02-11 19:15:25]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.co.uk/
    uSearchMigratedDefaultURL = hxxp://search.orange.co.uk/all?brand=ouk&tab=web&p=_adr&q={searchTerms}
    IE: Add to Google Photos Screensa&ver - C:\WINDOWS\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: {B87CCE2B-6BD3-40FB-8856-4D7E8D914875} = 193.36.79.100 80.10.246.1
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-07 22:45:24
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************Looks Ok.

    Is there a reason that this is in the NteSvcs?

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUpMy Dad used to have Tune up Utilities installed.
    Thanks again for all your help.Your WELCOME. Sorry to pressure you but it's kind of frustrating feeling like I may be leaving a computer half fixed.

    These are important steps to finish up.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete: ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.
    3113.

    Solve : is it possible for a virus or spyware to open ports in my router??

    Answer»

    I typically open a single port for TORRENTS, and leave it alone. Upon coming back home from college HOWEVER, I noticed that my family's NETWORK for OPENING ports is filled with randomly opened ports for ips in the network. I've closed the ports and opened ports for myself, but that is undone after some degree of time with a new set of opened ports. No one else in the family is doing it, and I've since taken security precautions. Previously, the network had no password, but I now changed the router password from default and I've added WPA-2 Personal password. However, the ports keep on opening (and overriding mine). I've asked the people in my family to run virus checks, although I'm not sure all of them have.

    So, back to the question:
    Could this be a virus or spyware?
    I also found this term on wikipedia:
    http://en.wikipedia.org/wiki/Firewall_pinhole

    Could that be RELATED to my plight?

    3114.

    Solve : Thomas Bailey spyware prob??

    Answer»

    Ok 4th times a dream! Using File Dropper so you can see the dialogue boxes I get.

    1st screen shot is after I have plugged in my HP Deskjet to ANY USB port...comp. shuts down in 60 secs. I'm running a second printer off the Printer port with no issues.

    2nd shot is the dialog box I get up restart.

    3rd shot is the status of my sound devices.

    note the my ipod also sends up a dialogue box telling me that the sound interface will not work well either.

    [attachment deleted by admin]Please stay in one topic. I closed the other one.

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-ENABLE your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixRan C F with no glitches.



    [attachment deleted by admin]

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Download
    ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    How is the computer now?Thanks, again!
    The computer can now operate the HP printer just fine but the Sounds and Audio Devices does not show anything. As it was before the "cleaners" did their work.

    Don't know if this dialogue box is related to Sounds and devices, but upon boot I get the "Welcome to the found new hardware wizard" and I don't know what CD it wants to locate the needed files.

    By the way my computer isn't slower, but what do you believe was living in my O.S.? Yes, the kids use this computer for gaming as well. Should I kick them off and remove their games? Or did my or my wifes email cause this problem.

    Any ideas on getting my S&A D to work? Or should I repost in Hardware?

    Great help you all are, I really can't believe my luck in discovering Comp. Hope years ago.Quote
    By the way my computer isn't slower, but what do you believe was living in my O.S.? ...... Or did my or my wifes email cause this problem.

    I'm still not sure what was or is wrong.

    Quote
    the kids use this computer for gaming as well. Should I kick them off and remove their games?

    I can't make that call.


    Download Rooter.exe to your desktop

    * Double click Rooter.exe to start the tool.
    * A DOS window will appear and show the scan progress.
    * Once complete a notepad file containing the report will open.
    * Copy & paste the results in your next reply.
    * Close notepad and Rooter will close.

    A log will also save at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have Windows installed).Here you go....

    [attachment deleted by admin]OK you can delete Rooter.

    Have you tried looking in the Device Manager and updating or rolling back the sound DRIVERS?Evilfantasy, went ahead and ROLLED back the driver for the PCI DEV. that was "yellowed/ exclaim marked in PCI devices and a found new HW box came up asking for a RealTek HD Audio driver...fired the CD at it and BOOM!, we are back.


    But, do you have any idea on what "gummed up" my my system? Or is it that bad things happen to O.K. people?

    Peace and care for your patience.

    I'll Twitter about Comp. Hope this afternoon.

    Sincerely'
    Thom BaileyI'm not sure what happened. What we did find shouldn't have effected all that it did but then you never know what malware might do...

    OK we can finish up now.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything LISTED.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    3115.

    Solve : Why would my IE Slow But Chrome is Fast...VIRUS maybe.....?

    Answer»

    I sometimes see that a huge issue is if you have a lot of toolbars installed on IE. My brother's computer had like 4 and it took FOREVER to load. I removed them, and it started right up.There is no way I have over 2 million 3 hundred thousand files on my computer. Could SUPERantispyware just keep repeating the scan over and over. I have started this scan over 5 days ago now. Could this be harmful to my laptop CPU to be running like this. It is maxed out CONSTANTLY. Should I stop the scan and run in safe mode?Superantispyware is most likely not repeating the search over and over again. It might be that it is stuck on trying to scan a file. Did you check the screen to see what it's scanning? Is it still scanning or attempting to scan the same file or something with same filename?I think Evilfantasy would agree after 5 days it's time to move on to the next program and post your log of SAS if you get one.Quote from: 2x3i5x on June 05, 2009, 03:59:01 PM

    Superantispyware is most likely not repeating the search over and over again. It might be that it is stuck on trying to scan a file. Did you check the screen to see what it's scanning? Is it still scanning or attempting to scan the same file or something with same filename?
    Like if there are too many folders in one directory (about 10000), then dir just freezes.So I finally stopped SUPERantispyware after it was reading almost 2400000 files. I posted an earier log this year to show you the boost in files scanned from before til now. My logs are attached below. I laso had error messages during HJT. I pressed ok but included a screenshot before I did it. Thanks for any help. Will post Older SUPERscan I did in January showing the influx in files.

    [attachment deleted by admin]Here is the older scan

    [attachment deleted by admin]Quote
    I laso had error messages during HJT. I pressed ok but included a screenshot before I did it.

    Because you didn't use the 'Run as Administrator' option as stated in the instructions.

    --

    This does not appear to be malware but we can do some cleanup as well as double check for anything that might be hiding.

    Download DDS by sUBs and save it to your desktop. Alternate DDS download link

    Vista users right click on dds and select Run as administrator (you will receive a UAC PROMPT, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.dds doesn't give me a run as administrator option, It just gives me test, configure, or install at the top. Should I install it. I definitely right clicked it. You were correct about my HJT error. Sorry about that. Just double click it. It should run.Here are the completed logs. It worked by double clicking it I attached the logs instead. I didn't think they would FIT in the reply. I appreciate your help Evilfantasy.


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-05-14.01)

    Microsoft® Windows Vista™ Home Basic
    Boot Device: \Device\HarddiskVolume1
    Install Date: 9/2/2008 12:25:46 AM
    System Uptime: 6/6/2009 3:53:06 PM (5 hours ago)

    Motherboard: TOSHIBA | | Portable PC
    Processor: Intel(R) Pentium(R) M processor 1.60GHz | mFCPGA | 1595/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 74 GiB total, 10.938 GiB free.
    D: is CDROM ()
    E: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Intel(R) PRO/Wireless 2200BG Network Connection
    Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27418086&REV_05\4&15FA4845&0&20F0
    Manufacturer: Intel Corporation
    Name: Intel(R) PRO/Wireless 2200BG Network Connection
    PNP Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27418086&REV_05\4&15FA4845&0&20F0
    Service: NETw2v32

    Class GUID: {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
    Description: SDA Standard Compliant SD Host Controller
    Device ID: PCI\VEN_104C&DEV_8034&SUBSYS_FF101179&REV_00\4&15FA4845&0&34F0
    Manufacturer: SDA Standard Compliant SD Host Controller Vendor
    Name: SDA Standard Compliant SD Host Controller
    PNP Device ID: PCI\VEN_104C&DEV_8034&SUBSYS_FF101179&REV_00\4&15FA4845&0&34F0
    Service: sdbus

    Class GUID: {4d36e96d-e325-11ce-bfc1-08002be10318}
    Description: TOSHIBA Software Modem
    Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_00011179&REV_04\3&33FD14CA&0&F3
    Manufacturer: Agere
    Name: TOSHIBA Software Modem
    PNP Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_00011179&REV_04\3&33FD14CA&0&F3
    Service: Modem

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    AC3Filter (remove only)
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.4
    Adobe Shockwave Player
    AutoSizer
    AVG 8.5
    Canon iP2600 series
    CCleaner (remove only)
    Choice Guard
    Compatibility Pack for the 2007 Office system
    G-Force
    Google Chrome
    Google Earth
    HijackThis 2.0.2
    honestech TVR
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    InterActual Player
    InterVideo WinDVD Creator 2
    InterVideo WinDVD for TOSHIBA
    Java(TM) 6 Update 13
    LimeWire PRO 4.12.3
    Linksys WCG200 Wireless-G Cable Gateway(B)
    Linksys Wireless-N Notebook Adapter Driver - WPC300N
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB929729)
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Office Live Add-in 1.3
    Microsoft Office Professional Edition 2003
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.0b5)
    MSVCRT
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    Native Instruments - Traktor 1.06
    ObjectDock
    PeerGuardian 2.0
    PowerISO
    Project64 1.6
    RealPlayer
    Realtek AC'97 Audio
    Rhapsody Player Engine
    Roxio Burn Engine
    Screenshot Captor 2.56.01
    SD Secure Module
    Secunia PSI
    Sonique
    SoundMAX
    SpywareBlaster 4.2
    SUPERAntiSpyware Free Edition
    Symantec KB-DocID:2003093015493306
    Texas Instruments PCIxx21/x515 drivers.
    TIxx21/x515
    Torrent Harvester
    TOSHIBA Assist
    TOSHIBA Controls
    TOSHIBA Hotkey Utility
    TOSHIBA PC Diagnostic Tool
    TOSHIBA Power Saver
    Toshiba Registration
    TOSHIBA Software Upgrades
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    Toshiba Tbiosdrv Driver
    TOSHIBA TouchPad ON/Off Utility
    TOSHIBA Utilities
    TOSHIBA Virtual Sound
    TOSHIBA Zooming Utility
    Touch and Launch
    Viewpoint Media Player
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    WhiteCap
    Winamp
    Winamp Remote
    Windows Defender
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Player 11
    WinRAR archiver
    WOT for Internet Explorer
    Xvid 1.1.2 final uninstall

    ==== Event Viewer Messages From Past Week ========

    6/6/2009 8:08:43 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
    5/31/2009 9:52:49 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avg8wd service.
    5/31/2009 1:41:22 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer DENNIS-HENDERSO that believes that it is the master browser for the domain on transport NetBT_Tcpip_{83E2F9DE-2FF9-4E5D-84BF-E1. The master browser is stopping or an election is being forced.
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd sptd
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7001] - The Windows Media Player Network Sharing Service service depends on the UPnP Device Host service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7000] - The Universal WDM TV Tuner service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7000] - The SAA7135 TV Card service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified.
    5/30/2009 11:38:29 PM, Error: Service Control Manager [7000] - The AEGIS Protocol (IEEE 802.1x) v3.1.6.0 service failed to start due to the following error: The system cannot find the file specified.
    5/30/2009 11:32:44 PM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom0.
    5/30/2009 11:31:36 PM, Error: Microsoft-Windows-Kernel-Processor-Power [6] - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.
    5/30/2009 11:31:18 PM, Error: sptd [4] - Driver detected an internal error in its data structures for .

    ==== End Of File ===========================


    DDS (Ver_09-05-14.01) - NTFSx86
    Run by Justin Henderson at 20:34:52.85 on Sat 06/06/2009
    Internet Explorer: 8.0.6001.18702
    Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1527.898 [GMT -7:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Windows\System32\snmp.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\AutoSizer\AutoSizer.exe
    C:\Users\Justin Henderson\AppData\Local\Google\Update\GoogleUpdate.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\Justin Henderson\Desktop\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uSearch Bar = Preserve
    uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mStart Page = hxxp://www.cox.net
    uInternet Settings,ProxyOverride = *.local
    BHO: {00000000-6cb0-410c-8c3d-8fa8d2011d0a} - DownloadRedirect Class
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [AutoSizer] "c:\program files\autosizer\AutoSizer.exe"
    uRun: [Google Update] "c:\users\justin henderson\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [PeerGuardian] c:\program files\peerguardian2\pg2.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
    mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
    mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
    StartupFolder: c:\users\justin~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
    uPolicies-explorer: NoViewOnDrive = 0 (0x0)
    uPolicies-explorer: HideRunAsVerb = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\partygaming\partypoker\RunApp.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
    DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1239532918143&h=7cb9c575117baf78e6cc365dec55b55f/&filename=jinstall-6u13-windows-i586-jc.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    AppInit_DLLs: avgrsstx.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\justin~1\appdata\roaming\mozilla\firefox\profiles\o53cq62b.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
    FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\justin henderson\appdata\local\google\update\1.2.145.5\npGoogleOneClick8.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: content.max.tokenizing.time - 200000
    FF - user.js: content.notify.interval - 100000
    FF - user.js: content.switch.threshold - 650000
    FF - user.js: nglayout.initialpaint.delay - 300
    c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.urlbar.matchOnWordBoundary", true);
    c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.safebrowsing.malware.reportURL", "http://www.stopbadware.org/reports/container?source=Firefox&version=3.0b5&reportname=");
    c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.places.importBookmarksHTML", true);
    c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.places.createdSmartBookmarks", false);

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-10 325896]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-10 108552]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-2-29 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-2-29 55024]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-10 298776]
    R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
    R3 WPC300N;Linksys Wireless Notebook Adapter WPC300N Driver;c:\windows\system32\drivers\WPC300N.SYS [2009-5-21 691192]
    S2 713xTVCard;SAA7135 TV Card;c:\windows\system32\drivers\SAA713x.sys [2008-9-2 277504]
    S2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2008-9-2 23680]
    S3 3xHybrid;SAA713x TV Card Service;c:\windows\system32\drivers\3xHybrid.sys [2007-7-6 906368]
    S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
    S3 nwusbmdm;Novatel Wireless Merlin CDMA EV-DO Modem Driver;c:\windows\system32\drivers\nwusbmdm.sys [2005-5-3 63360]
    S3 nwusbser;Novatel Wireless Merlin CDMA EV-DO Status Port;c:\windows\system32\drivers\nwusbser.sys [2005-5-3 63360]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-3-24 7808]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
    S3 WCG200BVistaI386;Linksys WCG200 Wireless-G Cable Gateway(B);c:\windows\system32\drivers\WCG200BVistaI386.sys [2006-12-22 15872]

    =============== Created Last 30 ================

    2009-06-06 02:00--d-----c:\users\justin~1\appdata\roaming\DonationCoder
    2009-06-06 01:58--d-----c:\programdata\DonationCoder
    2009-06-06 01:58--d-----c:\program files\ScreenshotCaptor
    2009-06-06 01:58--d-----c:\progra~2\DonationCoder
    2009-06-06 00:40--d-h---C:\BJPrinter
    2009-05-21 01:1634,304a-------c:\windows\DrvTool64.exe
    2009-05-21 01:1632,768a-------c:\windows\DrvTool.exe
    2009-05-21 01:16520a-------c:\windows\Hardware.ID
    2009-05-21 01:16825,336a-------c:\windows\bcmwl664.sys
    2009-05-21 01:16691,192a-------c:\windows\system32\drivers\WPC300N.SYS
    2009-05-21 01:16691,192a-------c:\windows\bcmwl6.sys
    2009-05-21 01:16113,756a-------c:\windows\Lsbcmnds.inf
    2009-05-21 01:1611,166a-------c:\windows\bcm43xx64.cat
    2009-05-21 01:1611,166a-------c:\windows\bcm43xx.cat
    2009-05-21 01:1627,072--------c:\windows\system32\drivers\CBPSp50.sys
    2009-05-21 01:163,262--------c:\windows\Linksys.ico
    2009-05-21 01:13139,264a-------c:\windows\UIButton.dll
    2009-05-21 01:13126,976a-------c:\windows\UIListCtrl.dll
    2009-05-21 01:1394,208a-------c:\windows\UITabCtrl.dll
    2009-05-21 01:1320,480a-------c:\windows\RegActiveX.exe
    2009-05-21 01:131,700,352a-------c:\windows\GdiPlus.dll
    2009-05-21 01:10--d-----c:\program files\Torrent Harvester
    2009-05-14 16:370a-------c:\windows\system32\tviresource.val
    2009-05-12 16:02--d-----c:\windows\TweakVI

    ==================== Find3M ====================

    2009-06-06 02:171,660a-------c:\windows\bthservsdp.dat
    2009-05-26 13:2040,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
    2009-05-26 13:1919,096a-------c:\windows\system32\drivers\mbam.sys
    2009-05-21 01:1851,200a-------c:\windows\inf\infpub.dat
    2009-05-21 01:18143,360a-------c:\windows\inf\infstrng.dat
    2009-05-21 01:1886,016a-------c:\windows\inf\infstor.dat
    2009-05-04 09:1211,952a-------c:\windows\system32\avgrsstx.dll
    2009-05-04 09:12325,896a-------c:\windows\system32\drivers\avgldx86.sys
    2009-05-04 09:12108,552a-------c:\windows\system32\drivers\avgtdix.sys
    2009-04-17 09:440a---h---c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
    2009-04-12 03:41410,984a-------c:\windows\system32\deploytk.dll
    2009-03-16 20:3840,960a-------c:\windows\apppatch\apihex86.dll
    2009-03-16 20:3813,824a-------c:\windows\system32\apilogen.dll
    2009-03-16 20:3824,064a-------c:\windows\system32\amxread.dll
    2008-09-03 23:19174a--sh---c:\program files\desktop.ini
    2008-09-03 22:58665,600a-------c:\windows\inf\drvindex.dat
    2006-11-02 05:39287,440a-------c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 05:39287,440a-------c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 05:3930,674a-------c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 05:3930,674a-------c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 02:20287,440a-------c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 02:20287,440a-------c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 02:2030,674a-------c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 02:2030,674a-------c:\windows\inf\perflib\0000\perfc.dat
    2005-05-22 20:28152a-------c:\users\justin~1\appdata\roaming\wklnhst.dat

    ============= FINISH: 20:36:14.87 ===============


    [attachment deleted by admin]It makes it easier on me with logs posted directly in the reply.

    Your Java is out of date.

    Older versions have vulnerabilities that malicious sites can use to infect your system.

    First install the new Sun Java Runtime Environment

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close all browser windows before beginning the install.

    Remove the old version(s)

    Download JavaRa
    • Unzip the file and open the JavaRa.exe
    • Click Remove Older Versions
    • JavaRa will search for and remove any outdated version of Java and remove any that are found.
    • Click Additional Tasks
    • Place a check next to Remove Useless JRE Files and click Go
    • Exit JavaRa
    • Delete the JavaRa files from the Desktop
    .
    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the BOX for Java Quick Starter. Click OK and restart your computer.

    ----------

    I see no indication of a malware issue here.

    Try posting in the Windows forum for more suggestions.Quote from: evilfantasy on June 07, 2009, 06:58:36 AM
    It makes it easier on me with logs posted directly in the reply.

    Sorry about that I will remove older Java. I am surprised Secunia didn't pick up on that one. I was also wondering why you recommend disabling SUPERantispyware at startup. Is it because its the freeware version and is no help to my computer unless I do a scan myself? If that is so, heck, I might as well buy the darn thing for $20 bucks. I tried to win it on your blog. Nice blog BTW. Very useful information. Sorry for wasting your time. I will now go post my problem in the windows forum and see if someone can help me get these extra files off my computer and free up my CPU. I think I might have screwed up my cache or something. I dunno. I know that vista always takes up all my free memory and puts it to use so no worries there, but I still know that something is up. Thanks for all your help.Quote
    Is it because its the freeware version and is no help to my computer unless I do a scan myself?

    Exactly.

    Good luck with the other issues and thanks for the compliments!
    3116.

    Solve : Can't install or delete programs?

    Answer»

    I ran the bitdefender on line scan and saved the file. Went to the file dropper site paid the monthly fee and then rebooted to get out of safe mode. The computer did not start up right. I was given the option to repair or go to a restore point. Tried the repair option but didn't work and had to restore from a previous point. So I've lost all the programs I installed and of course the files and logs. Back to square one. I am going to start in the morning, I've had enough for one day. I really appreciate all the help you have given me, just bare with me I'll get back to this point again.
    ThanksQuote

    Went to the file dropper site paid the monthly fee

    What? It's a free service with a paid option for more space. Anything I suggest will always be 100% free.

    Did you get the file uploaded to FileDropper so I can see it? I really need to get some names and LOCATIONS of the malware to know what to do next. Do you remember if anything was called Virut or Sality?Maybe I read it wrong but File dropper wouldn't LET me proceed with out making a payment of some kind. The cheapest option was .99 a month so I went with that. Not that much and I can drop it at any time.
    I had saved the file from Bitdefender on my desk top so it was lost when I rebooted. I do remember it was a Trojan virus but don't remember the name. There was a total of two. Can I proceed to the Bitdefender on line scan again without going through all the other programs as before?

    You are right, I went back and found that you can upload 2 G free, more than that cost extra. Sorry, my mistake Yes try BitDefender again and post the results.I finally got combo fix downloaded and tried to run the program. Got a message saying "comodo antivirus and comodo defense +" is running and needs to be shut down first. I have no idea where this is at, it never showed up in uninstall manager or in programs list. Now we have to find a way to shut them down. Is Comodo what you use for your antivirus or is it Avast?

    Just continue on with ComboFix. It should still run.I run Avast. The comodo shouldn't be there, it is from one I used and didn't like it and deleted it, I thought.
    I will continue on with the Combo fixComboFix 09-06-05.09 - William Michels 06/06/2009 23:07.1 - NTFSx86 NETWORK
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1484 [GMT -4:00]
    Running from: c:\users\William Michels\Desktop\ComboFix.exe
    AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
    FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
    SP: COMODO Defense+ *enabled* (Updated) {043803A4-4F86-4ef7-AFC5-F6E02A79969B}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\cluster 119497.PIF
    c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
    D:\Desktop.ini

    .
    ((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
    .

    2009-06-07 03:15 . 2009-06-07 03:15--------d-----w-c:\users\William Michels\AppData\Local\temp
    2009-06-06 20:27 . 2009-06-07 03:11--------d---a-w-\Qoobox
    2009-06-06 19:19 . 2009-06-06 19:19--------d-----w-c:\users\William Michels\AppData\Local\COMODO
    2009-06-06 19:19 . 2009-06-06 19:19--------d-----w-c:\users\WILLIA~1\AppData\Local\COMODO
    2009-06-06 17:16 . 2009-05-26 17:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-06 17:16 . 2009-05-26 17:1919096----a-w-c:\windows\system32\drivers\mbam.sys
    2009-06-06 15:40 . 2009-02-05 20:07114768----a-w-c:\windows\system32\drivers\aswSP.sys
    2009-06-06 15:40 . 2009-02-05 20:0720560----a-w-c:\windows\system32\drivers\aswFsBlk.sys
    2009-06-06 15:40 . 2009-02-05 20:0651376----a-w-c:\windows\system32\drivers\aswTdi.sys
    2009-06-06 15:40 . 2009-02-05 20:0623152----a-w-c:\windows\system32\drivers\aswRdr.sys
    2009-06-06 15:40 . 2009-02-05 20:0497480----a-w-c:\windows\system32\AvastSS.scr
    2009-06-06 15:40 . 2009-02-05 20:111256296----a-w-c:\windows\system32\aswBoot.exe
    2009-06-06 15:40 . 2009-02-05 20:0651792----a-w-c:\windows\system32\drivers\aswMonFlt.sys
    2009-06-06 02:42 . 2009-06-07 02:59117760----a-w-c:\users\William Michels\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-06-06 02:15 . 2009-06-06 02:15--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-06-06 02:09 . 2009-06-06 02:13--------d-----w-c:\program files\CCleaner
    2009-06-05 22:50 . 2009-06-06 18:57--------d-----w-c:\windows\BDOSCAN8
    2009-06-04 21:36 . 2009-06-06 15:30680----a-w-c:\users\William Michels\AppData\Local\d3d9caps.dat
    2009-06-04 21:36 . 2009-06-06 15:30680----a-w-c:\users\WILLIA~1\AppData\Local\d3d9caps.dat
    2009-06-04 21:32 . 2009-06-04 21:32--------d-----w-c:\users\William Michels\AppData\Roaming\Malwarebytes
    2009-06-04 21:32 . 2009-06-04 21:32--------d-----w-c:\users\WILLIA~1\AppData\Roaming\Malwarebytes
    2009-06-04 21:32 . 2009-06-06 17:18--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2009-06-04 21:32 . 2009-06-04 21:32--------d-----w-c:\progra~2\Malwarebytes
    2009-06-04 17:35 . 2009-06-04 17:35--------d-----w-c:\progra~2\SUPERAntiSpyware.com
    2009-06-04 17:31 . 2009-06-06 02:36--------d-----w-c:\program files\SUPERAntiSpyware
    2009-06-04 17:31 . 2009-06-04 17:31--------d-----w-c:\users\William Michels\AppData\Roaming\SUPERAntiSpyware.com
    2009-06-04 17:31 . 2009-06-04 17:31--------d-----w-c:\users\WILLIA~1\AppData\Roaming\SUPERAntiSpyware.com
    2009-06-03 01:33 . 2009-06-03 01:33--------d-----w-c:\program files\Alwil Software
    2009-05-31 23:31 . 2009-06-01 00:33--------d-----w-c:\program files\SpywareBlaster
    2009-05-28 21:20 . 2009-05-30 23:58--------d-----w-c:\users\William Michels\AppData\Roaming\System Tweaker
    2009-05-28 21:20 . 2009-05-30 23:58--------d-----w-c:\users\WILLIA~1\AppData\Roaming\System Tweaker
    2009-05-27 19:29 . 2009-06-06 04:53--------d-----w-c:\users\William Michels\{2be83168-6029-4d46-b0f6-10bbc66433b5}
    2009-05-27 19:07 . 2009-06-07 02:49408464----a-w-c:\windows\system32\drivers\sfi.dat
    2009-05-27 16:25 . 2009-05-27 19:2828704----a-w-c:\windows\system32\drivers\cmdhlp.sys
    2009-05-27 16:25 . 2009-05-27 19:28168208----a-w-c:\windows\system32\guard32.dll
    2009-05-27 16:25 . 2009-05-27 19:28130080----a-w-c:\windows\system32\drivers\cmdguard.sys
    2009-05-24 23:26 . 2009-06-06 04:52--------d-----w-c:\program files\tinySpell
    2009-05-24 23:26 . 2009-05-24 23:26--------d-----w-c:\users\William Michels\AppData\Roaming\tinySpell
    2009-05-24 23:26 . 2009-05-24 23:26--------d-----w-c:\users\WILLIA~1\AppData\Roaming\tinySpell
    2009-05-10 22:04 . 2009-05-10 22:0410769104----a-w-c:\users\William Michels\AppData\Roaming\Nikon\Message Center\DOWNLOAD_LOG\13213\S-P2____-176WU-NSAEN.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-07 03:03 . 2008-02-15 22:372325553152--sha-w-\pagefile.sys
    2009-06-06 15:27 . 2008-08-15 02:27--------d-----w-c:\program files\Uniblue
    2009-06-06 04:53 . 2009-04-22 21:51--------d-----w-c:\users\William Michels\AppData\Roaming\uTorrent
    2009-06-06 04:53 . 2009-04-22 21:51--------d-----w-c:\users\WILLIA~1\AppData\Roaming\uTorrent
    2009-06-06 04:52 . 2008-11-20 19:31--------d-----w-c:\program files\searchandwintoolbar
    2009-06-06 04:52 . 2008-09-04 23:41--------d-----w-c:\program files\LimeWire
    2009-06-06 04:52 . 2008-02-02 02:58--------d-----w-c:\program files\PC-Doctor 5 for Windows
    2009-06-06 04:52 . 2008-02-02 02:47--------d---a-w-c:\program files\Common Files\LightScribe
    2009-06-06 04:52 . 2008-02-02 02:47--------d-----w-c:\program files\Common Files\SureThing Shared
    2009-06-06 04:52 . 2009-05-07 22:21--------d-----w-c:\program files\TouchStoneSoftware
    2009-06-02 03:10 . 2008-08-23 19:49--------d-----w-c:\program files\Coupons
    2009-05-31 19:53 . 2008-09-05 23:3820---h--w-c:\progra~2\PKP_DLec.DAT
    2009-05-31 19:53 . 2008-09-05 23:2820---h--w-c:\progra~2\PKP_DLds.DAT
    2009-05-30 20:40 . 2008-08-14 01:53--------d-----w-c:\program files\google
    2009-05-30 19:55 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\users\William Michels\AppData\Roaming\Comodo
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\users\WILLIA~1\AppData\Roaming\Comodo
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\progra~2\comodo
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\program files\COMODO
    2009-05-29 21:48 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(61)
    2009-05-29 00:05 . 2008-09-04 23:41--------d-----w-c:\users\William Michels\AppData\Roaming\LimeWire
    2009-05-29 00:05 . 2008-09-04 23:41--------d-----w-c:\users\WILLIA~1\AppData\Roaming\LimeWire
    2009-05-28 21:17 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(62)
    2009-05-28 20:31 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(54)
    2009-05-17 15:26 . 2009-04-01 16:5168640----a-w-c:\windows\system32\drivers\inspect.sys
    2009-05-14 14:45 . 2008-02-02 02:54--------d-----w-c:\progra~2\Microsoft Help
    2009-05-14 14:41 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
    2009-05-09 23:18 . 2008-08-23 18:41--------d-----w-c:\users\William Michels\AppData\Roaming\GoodSync
    2009-05-09 23:18 . 2008-08-23 18:41--------d-----w-c:\users\WILLIA~1\AppData\Roaming\GoodSync
    2009-05-07 22:46 . 2009-04-11 03:35--------d-----w-c:\users\William Michels\AppData\Roaming\Azureus
    2009-05-07 22:46 . 2009-04-11 03:35--------d-----w-c:\users\WILLIA~1\AppData\Roaming\Azureus
    2009-05-07 18:13 . 2009-05-07 18:13--------d-----w-c:\progra~2\Azureus
    2009-04-26 15:08 . 2009-03-21 17:41541696----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdater.exe
    2009-04-23 23:49 . 2008-12-10 05:00350----a-w-c:\users\William Michels\AppData\Roaming\wklnhst.dat
    2009-04-23 23:49 . 2008-12-10 05:00350----a-w-c:\users\WILLIA~1\AppData\Roaming\wklnhst.dat
    2009-04-22 21:52 . 2009-04-22 21:52--------d-----w-c:\program files\uTorrent
    2009-04-11 03:39 . 2009-04-11 03:35--------d-----w-c:\program files\Vuze
    2009-04-02 03:56 . 2009-03-21 17:4179872----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
    2009-04-01 16:57 . 2009-04-01 16:57249592----a-w-c:\windows\system32\cssdll32.dll
    2009-03-21 17:41 . 2009-03-21 17:41349184----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
    2009-03-17 03:38 . 2009-04-17 00:4213824----a-w-c:\windows\system32\apilogen.dll
    2009-03-17 03:38 . 2009-04-17 00:4224064----a-w-c:\windows\system32\amxread.dll
    2009-03-09 18:51 . 2009-03-09 18:5110134----a-r-c:\users\William Michels\AppData\Roaming\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
    2009-03-09 09:19 . 2008-12-06 16:07410984----a-w-c:\windows\system32\deploytk.dll
    2008-09-04 18:15 . 2008-09-04 18:1522--sha-w-c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-15 39408]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "SansaDispatch"="c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-02 79872]
    "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-12 160592]
    "tinySpell"="c:\program files\tinySpell\tinyspell.exe" [2008-03-26 200704]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
    "OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [2007-02-08 73728]
    "Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]

    c:\users\William Michels\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-8-22 157000]

    c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
    NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-9-5 118784]

    c:\users\WILLIA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
    Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-8-22 157000]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 16:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4280910030-2114780719-3168784256-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{A4199458-5782-4B3E-8E51-C8E56A91E286}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{4C0A85EA-D703-46FB-AB37-357A1813E6BC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{B9030142-4060-4EE9-B4F8-0C73A6835873}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{57A41350-B9F7-42AB-9FC5-DE393A284472}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{D26B0CD2-729F-4B50-9CBE-3762030EF607}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{5DE4593B-9552-4936-A64F-55757A067408}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{BC1D0FF5-4079-459E-81B6-CB7C1EDA7EF6}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{31C95077-9A24-41A8-A42F-25CF4B8FEB82}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "TCP Query User{FD3048A1-CE40-4EF4-9CC2-05561BC6DD03}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{5128A22C-DC98-4B20-A29A-275D996B414F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "{463A1A22-E433-4394-8209-CB30B84EDAAA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
    "{2DFE46E2-93D8-47E2-BAFE-552A2C64F8F1}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
    "{CCD2AB17-D386-4349-B092-1CD31CB63173}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{467D2113-BD2A-4402-95EA-0217AEFCDA9D}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{C3CDCAA3-B3C7-4A15-9205-88E312385017}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{FAD5518F-43BD-4EE5-BDE0-B1C3035638EA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{0B06C9F2-B837-4B77-9077-CC481F3461AD}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "TCP Query User{BC0EF3F1-0E26-4568-88A0-2424648FC647}c:\\program files\\laplink\\pcsync\\sfthost.exe"= UDP:c:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "UDP Query User{25326B8B-07FA-41EA-971A-F4B9C292E1C4}c:\\program files\\laplink\\pcsync\\sfthost.exe"= TCP:c:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "{B58F19EE-652E-4A6C-B426-BD2AA1980B3C}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EC1E1CE4-7B8F-4D7B-8CF8-767D4C80D898}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "TCP Query User{7E8BD5A2-4812-434B-9740-EC75B68C3336}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
    "UDP Query User{4C1EA7AC-F5FF-4CBF-8009-68AA163EC9A4}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [5/27/2009 12:25 PM 28704]
    S1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [6/6/2009 11:40 AM 114768]
    S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [5/27/2009 12:25 PM 130080]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
    S2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [6/6/2009 11:40 AM 20560]
    S2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/6/2009 11:40 AM 51792]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - ECACHE
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-HP Software Update - c:\program files\Hp\HP Software Update\HPWuSchd2.exe
    SafeBoot-procexp90.Sys


    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    IE: FILL Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-06 23:15
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    SansaDispatch = c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe??E??h?`??type???P?

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @DENIED: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Completion time: 2009-06-07 23:17
    ComboFix-quarantined-files.txt 2009-06-07 03:17

    Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
    Post-Run: 224,851,353,600 bytes free

    236--- E O F ---2009-06-06 04:38

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    Driver::
    cmdHlp
    cmdGuard

    File::
    c:\windows\System32\drivers\cmdhlp.sys
    c:\windows\System32\drivers\cmdguard.sys

    Folder::
    c:\users\William Michels\AppData\Local\COMODO
    c:\users\WILLIA~1\AppData\Local\COMODO

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]


    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    ----------

    Now look in C:\Program Files for the Comodo folder and delete the entire folder.

    Next go to this post and follow the instructions for running the removal tool to get rid of the rest of Comodo.

    ----------

    Download Registry Search by Bobbi Flekman
    (see the link titled RegSearch Download Link)
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter comodo in the top area of the form and then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Add the contents of the Notepad file to your next reply.
    I have got to the part where I go to the post for running the removal tool for Comodo and I clicked on the link for non registered user and found the zip file, BUT it will not let me download it. I don't get the hand indicating there is anything there to download. What am I doing wrong?Here ya go.

    [attachment deleted by admin]I still can't delete the Comodo file from Program Files




    ComboFix 09-06-05.09 - William Michels 06/07/2009 12:03.1 - NTFSx86 NETWORK
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1484 [GMT -4:00]
    Running from: c:\users\William Michels\Desktop\ComboFix.exe
    Command switches used :: c:\users\William Michels\Desktop\CFScript.txt
    AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
    FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
    SP: COMODO Defense+ *enabled* (Updated) {043803A4-4F86-4ef7-AFC5-F6E02A79969B}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    FILE ::
    "c:\windows\System32\drivers\cmdguard.sys"
    "c:\windows\System32\drivers\cmdhlp.sys"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\users\WILLIA~1\AppData\Local\COMODO
    c:\users\WILLIA~1\AppData\Local\COMODO\.tmp\ctx0.tmp
    c:\users\WILLIA~1\AppData\Local\COMODO\.tmp\ctx1.tmp
    c:\users\William Michels\AppData\Local\COMODO\.tmp\ctx0.tmp
    c:\users\William Michels\AppData\Local\COMODO\.tmp\ctx1.tmp
    c:\windows\System32\drivers\cmdguard.sys
    c:\windows\System32\drivers\cmdhlp.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_CMDGUARD
    -------\Legacy_CMDHLP
    -------\Service_cmdGuard
    -------\Service_cmdHlp


    ((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
    .

    2009-06-07 16:10 . 2009-06-07 16:10--------d-sh--w-\$RECYCLE.BIN
    2009-06-07 16:10 . 2009-06-07 16:102011750400--sha-w-\hiberfil.sys
    2009-06-07 16:09 . 2009-06-07 16:10--------d-----w-c:\users\William Michels\AppData\Local\temp
    2009-06-07 16:09 . 2009-06-07 16:09--------d-----w-C:\temp
    2009-06-07 16:09 . 2009-06-07 16:09--------d-----w-\temp
    2009-06-07 16:01 . 2009-06-07 16:10--------d-s---w-\ComboFix
    2009-06-06 20:27 . 2009-06-07 16:03--------d---a-w-\Qoobox
    2009-06-06 17:16 . 2009-05-26 17:2040160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-06 17:16 . 2009-05-26 17:1919096----a-w-c:\windows\system32\drivers\mbam.sys
    2009-06-06 15:40 . 2009-02-05 20:07114768----a-w-c:\windows\system32\drivers\aswSP.sys
    2009-06-06 15:40 . 2009-02-05 20:0720560----a-w-c:\windows\system32\drivers\aswFsBlk.sys
    2009-06-06 15:40 . 2009-02-05 20:0651376----a-w-c:\windows\system32\drivers\aswTdi.sys
    2009-06-06 15:40 . 2009-02-05 20:0623152----a-w-c:\windows\system32\drivers\aswRdr.sys
    2009-06-06 15:40 . 2009-02-05 20:0497480----a-w-c:\windows\system32\AvastSS.scr
    2009-06-06 15:40 . 2009-02-05 20:111256296----a-w-c:\windows\system32\aswBoot.exe
    2009-06-06 15:40 . 2009-02-05 20:0651792----a-w-c:\windows\system32\drivers\aswMonFlt.sys
    2009-06-06 02:42 . 2009-06-07 15:35117760----a-w-c:\users\William Michels\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-06-06 02:15 . 2009-06-06 02:15--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-06-06 02:09 . 2009-06-06 02:13--------d-----w-c:\program files\CCleaner
    2009-06-05 22:50 . 2009-06-06 18:57--------d-----w-c:\windows\BDOSCAN8
    2009-06-04 21:36 . 2009-06-06 15:30680----a-w-c:\users\William Michels\AppData\Local\d3d9caps.dat
    2009-06-04 21:32 . 2009-06-04 21:32--------d-----w-c:\users\William Michels\AppData\Roaming\Malwarebytes
    2009-06-04 21:32 . 2009-06-06 17:18--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2009-06-04 21:32 . 2009-06-04 21:32--------d-----w-c:\progra~2\Malwarebytes
    2009-06-04 17:35 . 2009-06-04 17:35--------d-----w-c:\progra~2\SUPERAntiSpyware.com
    2009-06-04 17:31 . 2009-06-06 02:36--------d-----w-c:\program files\SUPERAntiSpyware
    2009-06-04 17:31 . 2009-06-04 17:31--------d-----w-c:\users\William Michels\AppData\Roaming\SUPERAntiSpyware.com
    2009-06-03 01:33 . 2009-06-03 01:33--------d-----w-c:\program files\Alwil Software
    2009-05-31 23:31 . 2009-06-01 00:33--------d-----w-c:\program files\SpywareBlaster
    2009-05-28 21:20 . 2009-05-30 23:58--------d-----w-c:\users\William Michels\AppData\Roaming\System Tweaker
    2009-05-27 19:29 . 2009-06-06 04:53--------d-----w-c:\users\William Michels\{2be83168-6029-4d46-b0f6-10bbc66433b5}
    2009-05-27 19:07 . 2009-06-07 15:54408464----a-w-c:\windows\system32\drivers\sfi.dat
    2009-05-27 16:25 . 2009-05-27 19:28168208----a-w-c:\windows\system32\guard32.dll
    2009-05-24 23:26 . 2009-06-06 04:52--------d-----w-c:\program files\tinySpell
    2009-05-24 23:26 . 2009-05-24 23:26--------d-----w-c:\users\William Michels\AppData\Roaming\tinySpell
    2009-05-10 22:04 . 2009-05-10 22:0410769104----a-w-c:\users\William Michels\AppData\Roaming\Nikon\Message Center\DOWNLOAD_LOG\13213\S-P2____-176WU-NSAEN.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-07 16:10 . 2008-02-15 22:372325553152--sha-w-\pagefile.sys
    2009-06-06 15:27 . 2008-08-15 02:27--------d-----w-c:\program files\Uniblue
    2009-06-06 04:53 . 2009-04-22 21:51--------d-----w-c:\users\William Michels\AppData\Roaming\uTorrent
    2009-06-06 04:52 . 2008-11-20 19:31--------d-----w-c:\program files\searchandwintoolbar
    2009-06-06 04:52 . 2008-09-04 23:41--------d-----w-c:\program files\LimeWire
    2009-06-06 04:52 . 2008-02-02 02:58--------d-----w-c:\program files\PC-Doctor 5 for Windows
    2009-06-06 04:52 . 2008-02-02 02:47--------d---a-w-c:\program files\Common Files\LightScribe
    2009-06-06 04:52 . 2008-02-02 02:47--------d-----w-c:\program files\Common Files\SureThing Shared
    2009-06-06 04:52 . 2009-05-07 22:21--------d-----w-c:\program files\TouchStoneSoftware
    2009-06-02 03:10 . 2008-08-23 19:49--------d-----w-c:\program files\Coupons
    2009-05-31 19:53 . 2008-09-05 23:3820---h--w-c:\progra~2\PKP_DLec.DAT
    2009-05-31 19:53 . 2008-09-05 23:2820---h--w-c:\progra~2\PKP_DLds.DAT
    2009-05-30 20:40 . 2008-08-14 01:53--------d-----w-c:\program files\google
    2009-05-30 19:55 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\users\William Michels\AppData\Roaming\Comodo
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\progra~2\comodo
    2009-05-29 23:42 . 2009-04-01 16:51--------d-----w-c:\program files\COMODO
    2009-05-29 21:48 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(61)
    2009-05-29 00:05 . 2008-09-04 23:41--------d-----w-c:\users\William Michels\AppData\Roaming\LimeWire
    2009-05-28 21:17 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(62)
    2009-05-28 20:31 . 2008-08-31 16:58--------d-----w-c:\progra~2\Avg8(54)
    2009-05-17 15:26 . 2009-04-01 16:5168640----a-w-c:\windows\system32\drivers\inspect.sys
    2009-05-14 14:45 . 2008-02-02 02:54--------d-----w-c:\progra~2\Microsoft Help
    2009-05-14 14:41 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
    2009-05-09 23:18 . 2008-08-23 18:41--------d-----w-c:\users\William Michels\AppData\Roaming\GoodSync
    2009-05-07 22:46 . 2009-04-11 03:35--------d-----w-c:\users\William Michels\AppData\Roaming\Azureus
    2009-05-07 18:13 . 2009-05-07 18:13--------d-----w-c:\progra~2\Azureus
    2009-04-26 15:08 . 2009-03-21 17:41541696----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdater.exe
    2009-04-23 23:49 . 2008-12-10 05:00350----a-w-c:\users\William Michels\AppData\Roaming\wklnhst.dat
    2009-04-22 21:52 . 2009-04-22 21:52--------d-----w-c:\program files\uTorrent
    2009-04-11 03:39 . 2009-04-11 03:35--------d-----w-c:\program files\Vuze
    2009-04-02 03:56 . 2009-03-21 17:4179872----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
    2009-04-01 16:57 . 2009-04-01 16:57249592----a-w-c:\windows\system32\cssdll32.dll
    2009-03-21 17:41 . 2009-03-21 17:41349184----a-w-c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
    2009-03-17 03:38 . 2009-04-17 00:4213824----a-w-c:\windows\system32\apilogen.dll
    2009-03-17 03:38 . 2009-04-17 00:4224064----a-w-c:\windows\system32\amxread.dll
    2009-03-09 18:51 . 2009-03-09 18:5110134----a-r-c:\users\William Michels\AppData\Roaming\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
    2008-09-04 18:15 . 2008-09-04 18:1522--sha-w-c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-15 39408]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "SansaDispatch"="c:\users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-02 79872]
    "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-12 160592]
    "tinySpell"="c:\program files\tinySpell\tinyspell.exe" [2008-03-26 200704]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
    "OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [2007-02-08 73728]
    "Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]

    c:\users\William Michels\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-8-22 157000]

    c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
    NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-9-5 118784]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 16:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4280910030-2114780719-3168784256-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{A4199458-5782-4B3E-8E51-C8E56A91E286}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{4C0A85EA-D703-46FB-AB37-357A1813E6BC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{B9030142-4060-4EE9-B4F8-0C73A6835873}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{57A41350-B9F7-42AB-9FC5-DE393A284472}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{D26B0CD2-729F-4B50-9CBE-3762030EF607}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{5DE4593B-9552-4936-A64F-55757A067408}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{BC1D0FF5-4079-459E-81B6-CB7C1EDA7EF6}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{31C95077-9A24-41A8-A42F-25CF4B8FEB82}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "TCP Query User{FD3048A1-CE40-4EF4-9CC2-05561BC6DD03}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{5128A22C-DC98-4B20-A29A-275D996B414F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "{463A1A22-E433-4394-8209-CB30B84EDAAA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
    "{2DFE46E2-93D8-47E2-BAFE-552A2C64F8F1}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
    "{CCD2AB17-D386-4349-B092-1CD31CB63173}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{467D2113-BD2A-4402-95EA-0217AEFCDA9D}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{C3CDCAA3-B3C7-4A15-9205-88E312385017}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{FAD5518F-43BD-4EE5-BDE0-B1C3035638EA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{0B06C9F2-B837-4B77-9077-CC481F3461AD}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "TCP Query User{BC0EF3F1-0E26-4568-88A0-2424648FC647}c:\\program files\\laplink\\pcsync\\sfthost.exe"= UDP:c:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "UDP Query User{25326B8B-07FA-41EA-971A-F4B9C292E1C4}c:\\program files\\laplink\\pcsync\\sfthost.exe"= TCP:c:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "{B58F19EE-652E-4A6C-B426-BD2AA1980B3C}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EC1E1CE4-7B8F-4D7B-8CF8-767D4C80D898}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "TCP Query User{7E8BD5A2-4812-434B-9740-EC75B68C3336}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
    "UDP Query User{4C1EA7AC-F5FF-4CBF-8009-68AA163EC9A4}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [6/6/2009 11:40 AM 114768]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
    R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [6/6/2009 11:40 AM 20560]
    R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/6/2009 11:40 AM 51792]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-07 12:10
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\nvvsvc.exe
    c:\windows\System32\audiodg.exe
    c:\windows\System32\rundll32.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\windows\System32\drivers\XAudio.exe
    c:\windows\System32\WUDFHost.exe
    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
    c:\program files\Alwil Software\Avast4\ashWebSv.exe
    c:\windows\System32\rundll32.exe
    c:\program files\Alwil Software\Avast4\ashDisp.exe
    c:\program files\Webshots\Webshots.scr
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\ehome\ehmsas.exe
    c:\windows\servicing\TrustedInstaller.exe
    c:\windows\System32\wbem\WMIADAP.exe
    .
    **************************************************************************
    .
    Completion time: 2009-06-07 12:14 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-06-07 16:14
    ComboFix2.txt 2009-06-07 03:17

    Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
    Post-Run: 222,641,451,008 bytes free

    246--- E O F ---2009-06-06 04:38




    Windows Registry Editor Version 5.00

    ; Registry Search 2.0 by Bobbi Flekman © 2005
    ; Version: 2.0.6.0

    ; Results at 6/7/2009 1:45:29 PM for strings:
    ; 'comodo'
    ; Strings excluded from search:
    ; (None)
    ; Search in:
    ; Registry Keys Registry Values Registry Data
    ; HKEY_LOCAL_MACHINE HKEY_USERS


    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Comodo Antivirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CavShell.CntMenu]
    @="Comodo Antivirus Context Menu Class"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CavShell.CntMenu.1]
    @="Comodo Antivirus Context Menu Class"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4255A182-CAD9-4214-A19B-7BA7FB633BBD}]
    @="Comodo AntiVirus"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4255A182-CAD9-4214-A19B-7BA7FB633BBD}\InprocServer32]
    @="C:\\Program Files\\COMODO\\COMODO Internet Security\\cavshell.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Comodo Antivirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\file\ShellEx\ContextMenuHandlers\Comodo Antivirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Comodo Antivirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{96D27592-5FAA-4B65-AE65-C41AA290ABCD}\1.0]
    @="Comodo Antivirus Shell Menu"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{96D27592-5FAA-4B65-AE65-C41AA290ABCD}\1.0\0\win64]
    @="C:\\Program Files\\COMODO\\COMODO Internet Security\\cavshell.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{4255A182-CAD9-4214-A19B-7BA7FB633BBD}"="Comodo Antivirus"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]
    "LocDescription"="@oem48.inf,%inspect_desc%;COMODO Internet Security Firewall Driver"
    "Description"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]
    "HelpText"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]
    "LocDescription"="@oem48.inf,%inspect_desc%;COMODO Internet Security Firewall Driver"
    "Description"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]
    "HelpText"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]
    "LocDescription"="@oem48.inf,%inspect_desc%;COMODO Internet Security Firewall Driver"
    "Description"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]
    "HelpText"="COMODO Internet Security Firewall Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"="COMODO Internet Security Firewall Driver"

    [HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup]

    [HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup\COMODO Internet Security]

    [HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup\COMODO Internet Security\CisMainDialog]

    [HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\\Users\\William Michels\\Desktop\\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe"="COMODO Internet Security Installer"
    "C:\\Program Files\\COMODO\\COMODO Internet Security\\cfpconfg.exe"="COMODO Internet Security"
    "C:\\Program Files\\COMODO\\COMODO Internet Security\\cavscan.exe"="COMODO Internet Security"

    [HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
    "C:\\Users\\William Michels\\Desktop\\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe"="COMODO Internet Security Installer"
    "C:\\Program Files\\COMODO\\COMODO Internet Security\\cfpconfg.exe"="COMODO Internet Security"
    "C:\\Program Files\\COMODO\\COMODO Internet Security\\cavscan.exe"="COMODO Internet Security"

    ; End Of The Log...
    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    File::
    C:\Users\William Michels\Desktop\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe

    Folder::
    C:\Program Files\COMODO

    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Comodo Antivirus]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CavShell.CntMenu]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CavShell.CntMenu.1]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4255A182-CAD9-4214-A19B-7BA7FB633BBD}]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4255A182-CAD9-4214-A19B-7BA7FB633BBD}\InprocServer32]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Comodo Antivirus]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\file\ShellEx\ContextMenuHandlers\Comodo Antivirus]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Comodo Antivirus]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{96D27592-5FAA-4B65-AE65-C41AA290ABCD}\1.0]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{96D27592-5FAA-4B65-AE65-C41AA290ABCD}\1.0\0\win64]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{4255A182-CAD9-4214-A19B-7BA7FB633BBD}"="Comodo Antivirus"

    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]

    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"=-

    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]

    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"=-

    [-HKEY_LOCAL_MACHINE\SYSTEM\Software\Comodo]

    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}]

    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{208D67BB-EF7E-4183-8341-580548FB2E4D}\Ndi]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INSPECT\0000]
    "DeviceDesc"=-

    [-HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup]

    [-HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup\COMODO Internet Security]

    [-HKEY_USERS\S-1-5-21-4280910030-2114780719-3168784256-1000\Software\ComodoGroup\COMODO Internet Security\CisMainDialog]


    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    ----------

    Go to Start > Run and type Notepad.exe then click OK.

    Copy and paste the following text within the code box into the new Notepad file.

    Code: [Select]@ECHO OFF
    net stop winmgmt
    cd /d %windir%\system32\wbem
    ren repository repository.old
    net start winmgmt
    exit
    In Notepad select File and Save as
    Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files.

    Next double click fixservice.bat to run it.
    A black box should open and close after a short time, this is normal.
    Do not continue until the black box has closed
    Delete fixservice.bat from the Desktop.

    ----------

    Also let me know how the computer is running now.Computer is running much faster, but still have a couple more issues. I haven't mentioned it but everytime I have to reboot or shut down I get a message, "Configuring updates" It will stay there for hours if I let it but I have been doing a hard shut down. I have went to Windows update and there are some updates that are trying to download, when I hit Install, the screen freezes and have to go to task manager to shut down Windows update screen. They won't install and I can't make them go away.
    Also there is a program that I deleted about the time all these problems started that keeps trying to initialize but the program is not there anymore. It trys to start on every startup. As of now this is all I can find wrong. Program is called "tiny spell"

    Here is the Combofix from the last run:

    ComboFix 09-06-05.09 - William Michels 06/07/2009 14:54:52.1 - NTFSx86 NETWORK
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.1486 [GMT -4:00]
    Running from: C:\Users\William Michels\Desktop\ComboFix.exe
    Command switches used :: C:\Users\William Michels\Desktop\CFScript7.txt
    AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
    FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
    SP: COMODO Defense+ *enabled* (Updated) {043803A4-4F86-4ef7-AFC5-F6E02A79969B}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    FILE ::
    "C:\Users\William Michels\Desktop\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\COMODO
    C:\Program Files\COMODO\COMODO Internet Security\cavscan.dll
    C:\Program Files\COMODO\COMODO Internet Security\cavscan.exe
    C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll
    C:\Program Files\COMODO\COMODO Internet Security\cfp.chinese.chm
    C:\Program Files\COMODO\COMODO Internet Security\cfp.chm
    C:\Program Files\COMODO\COMODO Internet Security\cfp.dll
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.russian.chm
    C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.dll
    C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.dll
    C:\Program Files\COMODO\COMODO Internet Security\cfplogvw.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.dll
    C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfpver.dat
    C:\Program Files\COMODO\COMODO Internet Security\cisinfo.ini
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Program Files\COMODO\COMODO Internet Security\COMODO - Antivirus Security.cfg
    C:\Program Files\COMODO\COMODO Internet Security\COMODO - Firewall Security.cfg
    C:\Program Files\COMODO\COMODO Internet Security\COMODO - Internet Security.cfg
    C:\Program Files\COMODO\COMODO Internet Security\COMODO - Proactive Security.cfg
    C:\Program Files\COMODO\COMODO Internet Security\crashrep.exe
    C:\Program Files\COMODO\COMODO Internet Security\database\pending.hse
    C:\Program Files\COMODO\COMODO Internet Security\database\pending.nme
    C:\Program Files\COMODO\COMODO Internet Security\database\safe.hse
    C:\Program Files\COMODO\COMODO Internet Security\database\safe.nme
    C:\Program Files\COMODO\COMODO Internet Security\database\vendor.nme
    C:\Program Files\COMODO\COMODO Internet Security\EULA.txt
    C:\Program Files\COMODO\COMODO Internet Security\framework.dll
    C:\Program Files\COMODO\COMODO Internet Security\incompatsw.ini
    C:\Program Files\COMODO\COMODO Internet Security\inspect.cat
    C:\Program Files\COMODO\COMODO Internet Security\inspect.inf
    C:\Program Files\COMODO\COMODO Internet Security\inspect.sys
    C:\Program Files\COMODO\COMODO Internet Security\LPSSetup.exe
    C:\Program Files\COMODO\COMODO Internet Security\registration.txt
    C:\Program Files\COMODO\COMODO Internet Security\s1.tmp
    C:\Program Files\COMODO\COMODO Internet Security\s2.tmp
    C:\Program Files\COMODO\COMODO Internet Security\scanners\bases.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\common.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\dosmz.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\first.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\gunpack.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\heur.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\mach32.dll
    C:\Program Files\COMODO\COMODO Internet Security\scanners\mem.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\pe32.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\pkann.dll
    C:\Program Files\COMODO\COMODO Internet Security\scanners\unarch.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\unpack.cav
    C:\Program Files\COMODO\COMODO Internet Security\scanners\white.cav
    C:\Program Files\COMODO\COMODO Internet Security\Themes\cfp.theme
    C:\Program Files\COMODO\COMODO Internet Security\tlicense.txt
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.arabic.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.brazilian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.Chinese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.chinesetraditional.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.czech.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.danish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.dutch.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.english.lang.template
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.estonian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.finnish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.french.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.german.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.italian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.japanese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.polish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.portuguese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.romanian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.russian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.slovak.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cavscan.swedish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.arabic.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.brazilian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.Chinese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.chinesetraditional.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.czech.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.danish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.dutch.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.english.lang.template
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.estonian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.finnish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.french.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.german.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.italian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.japanese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.polish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.portuguese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.romanian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.russian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.slovak.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfp.swedish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.arabic.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.brazilian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.Chinese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.chinesetraditional.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.czech.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.danish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.dutch.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.english.lang.template
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.estonian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.finnish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.french.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.german.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.italian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.japanese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.polish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.portuguese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.romanian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.russian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.slovak.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpconfg.swedish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.arabic.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.brazilian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.Chinese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.chinesetraditional.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.czech.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.danish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.dutch.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.english.lang.template
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.estonian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.finnish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.french.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.german.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.italian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.japanese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.polish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.portuguese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.romanian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.russian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.slovak.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfplogvw.swedish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.arabic.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.brazilian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.Chinese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.chinesetraditional.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.czech.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.danish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.dutch.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.english.lang.template
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.estonian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.finnish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.french.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.german.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.italian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.japanese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.polish.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.portuguese.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.romanian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.russian.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.slovak.lang
    C:\Program Files\COMODO\COMODO Internet Security\Translations\cfpupdat.swedish.lang

    .
    ((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
    .

    2009-06-07 19:02:41 . 2009-06-07 19:02:410d-sh--w-\$RECYCLE.BIN
    2009-06-07 19:01:57 . 2009-06-07 19:01:572009694208--sha-w-\hiberfil.sys
    2009-06-07 19:00:38 . 2009-06-07 19:02:470d-----w-C:\Users\William Michels\AppData\Local\temp
    2009-06-07 19:00:38 . 2009-06-07 19:00:380d-----w-C:\temp
    2009-06-07 19:00:38 . 2009-06-07 19:00:380d-----w-\temp
    2009-06-07 18:53:09 . 2009-06-07 19:02:480d-s---w-\ComboFix
    2009-06-07 16:28:25 . 2009-06-07 16:28:250d-----w-C:\Users\William Michels\AppData\Local\COMODO
    2009-06-06 20:27:25 . 2009-06-07 18:54:330d---a-w-\Qoobox
    2009-06-06 17:16:29 . 2009-05-26 17:20:0840160----a-w-C:\Windows\system32\drivers\mbamswissarmy.sys
    2009-06-06 17:16:28 . 2009-05-26 17:19:5619096----a-w-C:\Windows\system32\drivers\mbam.sys
    2009-06-06 15:40:39 . 2009-02-05 20:07:23114768----a-w-C:\Windows\system32\drivers\aswSP.sys
    2009-06-06 15:40:39 . 2009-02-05 20:07:1220560----a-w-C:\Windows\system32\drivers\aswFsBlk.sys
    2009-06-06 15:40:39 . 2009-02-05 20:06:2051376----a-w-C:\Windows\system32\drivers\aswTdi.sys
    2009-06-06 15:40:39 . 2009-02-05 20:06:1023152----a-w-C:\Windows\system32\drivers\aswRdr.sys
    2009-06-06 15:40:39 . 2009-02-05 20:04:4597480----a-w-C:\Windows\system32\AvastSS.scr
    2009-06-06 15:40:30 . 2009-02-05 20:11:351256296----a-w-C:\Windows\system32\aswBoot.exe
    2009-06-06 15:40:30 . 2009-02-05 20:06:5951792----a-w-C:\Windows\system32\drivers\aswMonFlt.sys
    2009-06-06 02:42:32 . 2009-06-07 16:42:01117760----a-w-C:\Users\William Michels\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-06-06 02:15:51 . 2009-06-06 02:15:510d-----w-C:\Program Files\Common Files\Wise Installation Wizard
    2009-06-06 02:09:11 . 2009-06-06 02:13:120d-----w-C:\Program Files\CCleaner
    2009-06-05 22:50:18 . 2009-06-06 18:57:440d-----w-C:\Windows\BDOSCAN8
    2009-06-04 21:36:13 . 2009-06-06 15:30:58680----a-w-C:\Users\William Michels\AppData\Local\d3d9caps.dat
    2009-06-04 21:32:08 . 2009-06-04 21:32:080d-----w-C:\Users\William Michels\AppData\Roaming\Malwarebytes
    2009-06-04 21:32:03 . 2009-06-06 17:18:320d-----w-C:\Program Files\Malwarebytes' Anti-Malware
    2009-06-04 21:32:03 . 2009-06-04 21:32:030d-----w-C:\PROGRA~2\Malwarebytes
    2009-06-04 17:35:40 . 2009-06-04 17:35:400d-----w-C:\PROGRA~2\SUPERAntiSpyware.com
    2009-06-04 17:31:43 . 2009-06-06 02:36:370d-----w-C:\Program Files\SUPERAntiSpyware
    2009-06-04 17:31:43 . 2009-06-04 17:31:430d-----w-C:\Users\William Michels\AppData\Roaming\SUPERAntiSpyware.com
    2009-06-03 01:33:08 . 2009-06-03 01:33:080d-----w-C:\Program Files\Alwil Software
    2009-05-31 23:31:04 . 2009-06-01 00:33:500d-----w-C:\Program Files\SpywareBlaster
    2009-05-28 21:20:35 . 2009-05-30 23:58:080d-----w-C:\Users\William Michels\AppData\Roaming\System Tweaker
    2009-05-27 19:29:15 . 2009-06-06 04:53:300d-----w-C:\Users\William Michels\{2be83168-6029-4d46-b0f6-10bbc66433b5}
    2009-05-27 19:07:57 . 2009-06-07 15:54:17408464----a-w-C:\Windows\system32\drivers\sfi.dat
    2009-05-27 16:25:05 . 2009-05-27 19:28:34168208----a-w-C:\Windows\system32\guard32.dll
    2009-05-24 23:26:22 . 2009-06-06 04:52:270d-----w-C:\Program Files\tinySpell
    2009-05-24 23:26:22 . 2009-05-24 23:26:490d-----w-C:\Users\William Michels\AppData\Roaming\tinySpell
    2009-05-10 22:04:53 . 2009-05-10 22:04:5310769104----a-w-C:\Users\William Michels\AppData\Roaming\Nikon\Message Center\DOWNLOAD_LOG\13213\S-P2____-176WU-NSAEN.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-07 19:01:55 . 2008-02-15 22:37:352325553152--sha-w-\pagefile.sys
    2009-06-06 15:27:19 . 2008-08-15 02:27:490d-----w-C:\Program Files\Uniblue
    2009-06-06 04:53:27 . 2009-04-22 21:51:520d-----w-C:\Users\William Michels\AppData\Roaming\uTorrent
    2009-06-06 04:52:27 . 2008-11-20 19:31:490d-----w-C:\Program Files\searchandwintoolbar
    2009-06-06 04:52:26 . 2008-09-04 23:41:300d-----w-C:\Program Files\LimeWire
    2009-06-06 04:52:26 . 2008-02-02 02:58:220d-----w-C:\Program Files\PC-Doctor 5 for Windows
    2009-06-06 04:52:18 . 2008-02-02 02:47:260d---a-w-C:\Program Files\Common Files\LightScribe
    2009-06-06 04:52:18 . 2008-02-02 02:47:180d-----w-C:\Program Files\Common Files\SureThing Shared
    2009-06-06 04:52:08 . 2009-05-07 22:21:480d-----w-C:\Program Files\TouchStoneSoftware
    2009-06-02 03:10:55 . 2008-08-23 19:49:040d-----w-C:\Program Files\Coupons
    2009-05-31 19:53:05 . 2008-09-05 23:38:3620---h--w-C:\PROGRA~2\PKP_DLec.DAT
    2009-05-31 19:53:05 . 2008-09-05 23:28:4320---h--w-C:\PROGRA~2\PKP_DLds.DAT
    2009-05-30 20:40:50 . 2008-08-14 01:53:270d-----w-C:\Program Files\google
    2009-05-30 19:55:43 . 2008-08-31 16:58:330d-----w-C:\PROGRA~2\Avg8
    2009-05-29 23:42:41 . 2009-04-01 16:51:520d-----w-C:\Users\William Michels\AppData\Roaming\Comodo
    2009-05-29 23:42:41 . 2009-04-01 16:51:490d-----w-C:\PROGRA~2\comodo
    2009-05-29 21:48:33 . 2008-08-31 16:58:330d-----w-C:\PROGRA~2\Avg8(61)
    2009-05-29 00:05:41 . 2008-09-04 23:41:440d-----w-C:\Users\William Michels\AppData\Roaming\LimeWire
    2009-05-28 21:17:45 . 2008-08-31 16:58:330d-----w-C:\PROGRA~2\Avg8(62)
    2009-05-28 20:31:18 . 2008-08-31 16:58:330d-----w-C:\PROGRA~2\Avg8(54)
    2009-05-17 15:26:21 . 2009-04-01 16:51:4968640----a-w-C:\Windows\system32\drivers\inspect.sys
    2009-05-14 14:45:51 . 2008-02-02 02:54:310d-----w-C:\PROGRA~2\Microsoft Help
    2009-05-14 14:41:57 . 2006-11-02 11:18:330d-----w-C:\Program Files\Windows Mail
    2009-05-09 23:18:25 . 2008-08-23 18:41:260d-----w-C:\Users\William Michels\AppData\Roaming\GoodSync
    2009-05-07 22:46:37 . 2009-04-11 03:35:450d-----w-C:\Users\William Michels\AppData\Roaming\Azureus
    2009-05-07 18:13:57 . 2009-05-07 18:13:570d-----w-C:\PROGRA~2\Azureus
    2009-04-26 15:08:55 . 2009-03-21 17:41:14541696----a-w-C:\Users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdater.exe
    2009-04-23 23:49:40 . 2008-12-10 05:00:34350----a-w-C:\Users\William Michels\AppData\Roaming\wklnhst.dat
    2009-04-22 21:52:31 . 2009-04-22 21:52:310d-----w-C:\Program Files\uTorrent
    2009-04-11 03:39:41 . 2009-04-11 03:35:090d-----w-C:\Program Files\Vuze
    2009-04-02 03:56:11 . 2009-03-21 17:41:1479872----a-w-C:\Users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
    2009-04-01 16:57:56 . 2009-04-01 16:57:56249592----a-w-C:\Windows\system32\cssdll32.dll
    2009-03-21 17:41:15 . 2009-03-21 17:41:15349184----a-w-C:\Users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
    2009-03-17 03:38:46 . 2009-04-17 00:42:2713824----a-w-C:\Windows\system32\apilogen.dll
    2009-03-17 03:38:44 . 2009-04-17 00:42:2724064----a-w-C:\Windows\system32\amxread.dll
    2008-09-04 18:15:54 . 2008-09-04 18:15:5422--sha-w-C:\Windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((( [emailprotected]_16.10.53 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-02-02 03:17:43 . 2009-06-07 16:43:1547880 C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 13:05:11 . 2009-06-07 16:43:1671032 C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-08-13 21:13:17 . 2009-06-07 15:36:1616384 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-08-13 21:13:17 . 2009-06-07 16:42:5216384 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-08-13 21:13:17 . 2009-06-07 15:36:1632768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-08-13 21:13:17 . 2009-06-07 16:42:5232768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-08-13 21:13:17 . 2009-06-07 15:36:1616384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-08-13 21:13:17 . 2009-06-07 16:42:5216384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-08-13 23:01:39 . 2009-06-07 16:43:169870 C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4280910030-2114780719-3168784256-1000_UserData.bin
    - 2006-11-02 10:33:01 . 2009-06-07 15:42:24595446 C:\Windows\System32\perfh009.dat
    + 2006-11-02 10:33:01 . 2009-06-07 16:48:58595446 C:\Windows\System32\perfh009.dat
    - 2006-11-02 10:33:01 . 2009-06-07 15:42:24101144 C:\Windows\System32\perfc009.dat
    + 2006-11-02 10:33:01 . 2009-06-07 16:48:58101144 C:\Windows\System32\perfc009.dat
    - 2006-11-02 10:22:39 . 2009-06-07 15:38:026553600 C:\Windows\System32\SMI\Store\Machine\schema.dat
    + 2006-11-02 10:22:39 . 2009-06-07 16:44:426553600 C:\Windows\System32\SMI\Store\Machine\schema.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C8ED-EA2EFAD2ED61}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 12:35:14 801904]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 07:33:09 125952]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-15 05:15:24 39408]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 07:33:39 202240]
    "SansaDispatch"="C:\Users\William Michels\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-02 03:56:11 79872]
    "RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-04-12 11:56:35 160592]
    "tinySpell"="C:\Program Files\tinySpell\tinyspell.exe" [2008-03-26 18:09:38 200704]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 14:05:52 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 13:42:24 65536]
    "OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 10:59:00 118784]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-23 02:49:00 13539872]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-23 02:49:00 92704]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 11:00:48 33648]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 06:04:34 39792]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-03-09 09:19:17 148888]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 20:08:45 81000]
    "RtHDVCpl"="RtHDVCpl.exe" - C:\WINDOWS\RtHDVCpl.exe [2008-01-15 16:26:18 4874240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "PCDrProfiler"="C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" [2007-02-08 22:27:12 73728]
    "Launcher"="C:\Windows\SMINST\launcher.exe" [2007-03-07 19:09:52 44168]

    C:\Users\William Michels\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2008-8-22 157000]

    C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
    NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2008-9-5 118784]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 14:13:36 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 16:05:34356352----a-w-C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4280910030-2114780719-3168784256-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{A4199458-5782-4B3E-8E51-C8E56A91E286}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{4C0A85EA-D703-46FB-AB37-357A1813E6BC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{B9030142-4060-4EE9-B4F8-0C73A6835873}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{57A41350-B9F7-42AB-9FC5-DE393A284472}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{D26B0CD2-729F-4B50-9CBE-3762030EF607}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{5DE4593B-9552-4936-A64F-55757A067408}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{BC1D0FF5-4079-459E-81B6-CB7C1EDA7EF6}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{31C95077-9A24-41A8-A42F-25CF4B8FEB82}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "TCP Query User{FD3048A1-CE40-4EF4-9CC2-05561BC6DD03}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{5128A22C-DC98-4B20-A29A-275D996B414F}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
    "{463A1A22-E433-4394-8209-CB30B84EDAAA}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{2DFE46E2-93D8-47E2-BAFE-552A2C64F8F1}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{CCD2AB17-D386-4349-B092-1CD31CB63173}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{467D2113-BD2A-4402-95EA-0217AEFCDA9D}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{C3CDCAA3-B3C7-4A15-9205-88E312385017}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{FAD5518F-43BD-4EE5-BDE0-B1C3035638EA}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{0B06C9F2-B837-4B77-9077-CC481F3461AD}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "TCP Query User{BC0EF3F1-0E26-4568-88A0-2424648FC647}C:\\program files\\laplink\\pcsync\\sfthost.exe"= UDP:C:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "UDP Query User{25326B8B-07FA-41EA-971A-F4B9C292E1C4}C:\\program files\\laplink\\pcsync\\sfthost.exe"= TCP:C:\program files\laplink\pcsync\sfthost.exe:PCsync Host Module
    "{B58F19EE-652E-4A6C-B426-BD2AA1980B3C}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EC1E1CE4-7B8F-4D7B-8CF8-767D4C80D898}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "TCP Query User{7E8BD5A2-4812-434B-9740-EC75B68C3336}C:\\program files\\vuze\\azureus.exe"= UDP:C:\program files\vuze\azureus.exe:Azureus
    "UDP Query User{4C1EA7AC-F5FF-4CBF-8009-68AA163EC9A4}C:\\program files\\vuze\\azureus.exe"= TCP:C:\program files\vuze\azureus.exe:Azureus

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [6/6/2009 11:40:39 AM 114768]
    R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05:54 AM 9968]
    R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05:52 AM 72944]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\System32\drivers\aswFsBlk.sys [6/6/2009 11:40:39 AM 20560]
    R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\drivers\aswMonFlt.sys [6/6/2009 11:40:30 AM 51792]
    R3 SASENUM;SASENUM;C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05:56 AM 7408]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    IE: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    IE: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    IE: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    .


    Try reinstalling tiny spell and then uninstall it through Add or Remove Programs (programs and features)

    Shut down IE.

    Open it up by right clicking the IE icon and choose 'Run as Administrator' and then try the Windows Updates.

    Let me know...
    3117.

    Solve : Had a rundll error, was infected, cleaned, attached HJT, still no IE?

    Answer»

    Scan with Panda ActiveScan 2.0

    This scanner requires Internet Explorer

    • Once you are on the Panda site click the Scan your PC now button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select EITHER Home User or Company
    • Select the appropriate Yes or No to receiving marketing information
    • Click the Free Online Scan button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    .
    Post the contents of the ActiveScan report in your next reply.Ran the Panda scan and attached the log

    [attachment deleted by admin]I forgot to mention that Panda says that it can disinfect it for me, but I have not clicked the box yet.You have to buy Panda for it to disinfect and that isn't necessary.

    * Download Qoofix to your Desktop or any other convient location
    * Unzip the files from Qoofix.zip to a convenient location such as C:\Qoofix.
    * Navigate to the folder you unzipped the files to and double click on the file named Qoofix.exe.
    * Finally, select Begin Removal and the removal process will commence. A reboot may be necessary if an infection is found.

    ----------

    Locate and delete this file:

    c:\windows\system32\csuninstall.exe

    ----------

    Download OTMoveIt3 by OldTimer OTMoveIt3.exe and place it on your desktop. (unless you already have it installed)

    1. Double click OTMoveIt3.exe to launch it.
    Vista users right click and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
    5. Once complete exit out of OTMoveIt3

    ----------

    Set a New Restore Point to PREVENT possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.I can not get past step one - Qoofix: http://majorgeeks.com/download.php?det=5175 (there is nothing on this page to download - at least nothing appears on my screen).Try here: http://www.besttechie.net/forums/index.php?showtopic=9051This java issue keeps coming back to haunt me . . . secunia also requires java to WORK (keep in mind I have the latest version of it, but it doesn't work).

    I see that there are two "important" windows updates for me to download:

    Windows Vista:
    Important: Microsoft .NET Framework 3.5 Service Pack1 and .NET Framework 3.5 Family Update
    Optional: Group Policy Preference Client Side Extensions for Windows Vista
    Optional: Windows PowerShell 1.0 for Windows Vista

    Office Live Add-in
    Optional: Office LIve add-in

    SQL Server 2005:
    Important: Microsoft SQL Server 2005 Express Edition Service Pack 3

    When I attempt to perform these updates I get an error message (screen shot attached). I attempted to research the error codes. They tell me to be sure that the firewall will allow microsoft access etc... and turn off the antivirus software (well I did and they still will not download). For some reason I feel that this is the reason JAVA doesn't work - and therefore I cannot run the additional software programs you've recommended.

    Also, I am pretty maxed out on my hard drive and I am wondering if that is also playing a role in this. I have about 3 Gigs free.

    Again, I really appreciate your patience with me and your help.

    [attachment deleted by admin]Anything that is Important or critical are just the.

    Optional is optional...finally got Java to enable PROPERLY so I ran the Kscan . . . file attached - as it was on your oringinal list of things to do (nothing detected). Still no luck in downloading those windows updates. Will try some things this afternoon.

    Thanks for all of your help,
    Crispin

    [attachment deleted by admin]Close all browser windows. Right click IE and choose 'Run as Administrator' and then get the updates.What is K Scan evil fantasy is it an online scanner?KASPERSKY Lab Online Scanner

    http://www.kaspersky.com/virusscannerQuote from: evilfantasy on April 06, 2009, 07:27:59 AM
    Close all browser windows. Right click IE and choose 'Run as Administrator' and then get the updates.

    I did exactly that, but still no beans . . . I am perplexed. I feel great that my original issue has been solved, but I don't know what to think regarding the lack of ability to perform "windows updates". Should a start a new thread?

    evilfantasy you have been a great help, my wife and I thank you!I am not sure why that wouldn't work. Ah by the way I'm using Kaspersky anti virus 2009 right now and this anti virus for me is the best. Well 2nd for me is NOD 32. Well it's good that you have already fixed the problem. Remember the last tip that i gave you that was just said to me by my friend he is a computer technician. Well it's good you have solved your problem.
    3118.

    Solve : .exe Bad image warnings(logs attached as requested)?

    Answer»

    I have attached the logs. My problem is:

    EVERYTIME I open a program I see the same WARNING. I will use firefox as an example.
    It says:

    firefox.exe- Bad Image
    The application of DLL C:\WINDOWS\systems32\rigezide.dll is not a valid windows image. Please check this against your installation diskette.

    This happens all the TIME. Is there anyway to get rid of this? I have a dell inspiron 1100 and run xp

    Thank you

    [ATTACHMENT deleted by ADMIN]problem was solved by another site using hijackthis and otmover! thankscan you provide the link so we may learn

    3119.

    Solve : Another W32.silly.fdc, Logs posted?

    Answer»

    The only other 3rd party program I have on this computer, particularity, is EndItAll. (Not counting the programs for these scans)

    Also, I am also experiencing these "transparent"(The same thing daffodil had.) files, here is a list of what they are.

    desktop.ini
    desktop.ini (Yes, there are 2 of them.)
    Folder.jpg
    AlbumArtSmall.jpg
    AlbumArt_(Random characters, numbers, and letters)Large
    AlbumArt_(Random characters, numbers, and letters)Small

    (On a side note, about those files, all except the desktop.ini files, have a picture, with the words Pat Banter, and a picture of her behind it... I'm under the assumption I got a ********* torrent, is this correct?)

    Haven't so much as CLICKED them, but by the names, they seem harmless, are they safe to trash? Or do they serve some kind of purpose?

    I started the other one (with daffodil) Soooo... Here are my logs from the SUPERAntiSpyware:


    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/06/2009 at 03:52 PM

    Application Version : 4.26.1000

    Core Rules Database Version : 3830
    Trace Rules Database Version: 1786

    Scan type : Complete Scan
    Total Scan Time : 00:58:03

    Memory items scanned : 288
    Memory threats detected : 0
    Registry items scanned : 6851
    Registry threats detected : 2
    File items scanned : 148212
    File threats detected : 24

    Adware.Tracking Cookie
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][5].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt

    Trojan.DNS-Changer (Hi-Jacked DNS)
    HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{225C21AF-2FD1-4017-97F3-FFB266B81B98}#NAMESERVER
    HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{225C21AF-2FD1-4017-97F3-FFB266B81B98}#NAMESERVER



    Malware Bytes results:

    Malwarebytes' Anti-Malware 1.35
    Database version: 1945
    Windows 6.0.6001 Service Pack 1

    4/6/2009 6:02:47 PM
    mbam-log-2009-04-06 (18-02-46).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 225856
    Time elapsed: 1 hour(s), 59 minute(s), 39 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 4
    Folders Infected: 2
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayMe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMe (Trojan.DNSChanger) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Users\Doris\AppData\Local\codecsetup8678.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMe\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.


    HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:11:12 PM, on 4/6/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Ideazon\ZEngine\Zboard.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - MRI_DISABLED - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\Windows\System32\TwcToolbarBho.dll
    O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\Windows\System32\TwcToolbarIe7.dll
    O4 - HKLM\..\RUN: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O15 - Trusted Zone: *.moove.com
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)
    O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
    O23 - Service: AUTOMATIC LiveUpdate Scheduler - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9661 bytes





    Ok... So how exactly do I remove this crap? Ok, THATS all 3 logs... What am I suppose to do now? They keep saying the removed them, but they keep showing up. Ok, I also notice that where the worm was, it now keeps showing as 3 empty registry keys to my scanners (Advanced SystemCare) When I click repair, it says problems fixed, but I scan again right after, and they are still there...

    So is the worm gone, or are there more steps I need to take?Stop using Advanced SystemCare before your computer becomes damaged. These tools are dangerous especially when there is already a problem.

    Right click HijackThis and choose 'Run as Administrator'

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    • O2 - BHO: (no name) - MRI_DISABLED - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O4 - HKUS\S-1-5-19\..\RunOnce: [] (User \'LOCAL SERVICE\')
    • O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    • O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    • O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    • O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixOk, here is my combofix log.... So is it safe to delete all these transparent folders? Or even log on important sites, I.E. my online bank account? Sorry, most of my knowledge is in building computers, not removing worms, trojans, whatever have you...


    ComboFix 09-04-04.01 - Doris 2009-04-07 15:23:26.1 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3061.2023 [GMT -4:00]
    Running from: c:\users\Doris\Desktop\ComboFix.exe
    AV: Norton Internet Security *On-access scanning disabled* (Updated)
    FW: Norton Internet Security *enabled*
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\AutoRun.inf
    c:\windows\system32\KBL.LOG
    c:\windows\system32\x64

    .
    ((((((((((((((((((((((((( Files Created from 2009-03-07 to 2009-04-07 )))))))))))))))))))))))))))))))
    .

    2009-04-07 09:56 . 2009-04-07 09:56118--a------c:\windows\System32\MRT.INI
    2009-04-06 23:44 . 2009-04-06 23:53d--------c:\users\Doris\AppData\Roaming\IObit
    2009-04-06 23:44 . 2009-04-07 10:00d--------c:\program files\IObit
    2009-04-06 23:43 . 2009-04-06 23:43d--------c:\program files\CCleaner
    2009-04-06 18:19 . 2009-04-06 18:18410,984--a------c:\windows\System32\deploytk.dll
    2009-04-06 18:10 . 2009-04-06 18:10d--------c:\program files\Trend Micro
    2009-04-06 16:00 . 2009-04-06 16:00d--------c:\users\Doris\AppData\Roaming\Malwarebytes
    2009-04-06 16:00 . 2009-04-06 16:00d--------c:\users\All Users\Malwarebytes
    2009-04-06 16:00 . 2009-04-06 16:00d--------c:\programdata\Malwarebytes
    2009-04-06 16:00 . 2009-04-06 18:02d--------c:\program files\Malwarebytes' Anti-Malware
    2009-04-06 16:00 . 2009-03-26 16:4938,496--a------c:\windows\System32\drivers\mbamswissarmy.sys
    2009-04-06 16:00 . 2009-03-26 16:4915,504--a------c:\windows\System32\drivers\mbam.sys
    2009-04-06 14:44 . 2009-04-06 14:44d--------c:\users\Doris\AppData\Roaming\SUPERAntiSpyware.com
    2009-04-06 14:44 . 2009-04-06 14:44d--------c:\users\All Users\SUPERAntiSpyware.com
    2009-04-06 14:44 . 2009-04-06 14:44d--------c:\programdata\SUPERAntiSpyware.com
    2009-04-06 14:44 . 2009-04-06 14:44d--------c:\program files\SUPERAntiSpyware
    2009-04-05 09:52 . 2009-04-05 09:52d--------c:\users\Doris\AppData\Roaming\Darkfall
    2009-04-05 09:26 . 2008-07-12 08:183,851,784--a------c:\windows\System32\D3DX9_39.dll
    2009-04-05 09:26 . 2008-05-30 14:113,850,760--a------c:\windows\System32\D3DX9_38.dll
    2009-04-05 09:26 . 2008-03-05 15:563,786,760--a------c:\windows\System32\D3DX9_37.dll
    2009-04-05 09:26 . 2007-10-12 15:143,734,536--a------c:\windows\System32\d3dx9_36.dll
    2009-04-05 09:26 . 2007-07-19 18:143,727,720--a------c:\windows\System32\d3dx9_35.dll
    2009-04-05 09:26 . 2007-05-16 16:453,497,832--a------c:\windows\System32\d3dx9_34.dll
    2009-04-05 09:26 . 2007-03-12 16:423,495,784--a------c:\windows\System32\d3dx9_33.dll
    2009-04-05 09:26 . 2006-11-29 13:063,426,072--a------c:\windows\System32\d3dx9_32.dll
    2009-04-05 09:26 . 2006-09-28 16:052,414,360--a------c:\windows\System32\d3dx9_31.dll
    2009-04-05 09:25 . 2009-04-05 09:51d--------c:\program files\Darkfall
    2009-03-30 14:46 . 2008-10-31 13:2553,248--a------c:\windows\nswatchdog.exe
    2009-03-26 21:01 . 2009-03-26 21:01d--------c:\program files\The Weather Channel Toolbar
    2009-03-26 21:01 . 2008-07-22 13:31327,680--a------c:\windows\System32\TwcToolbarIe7.dll
    2009-03-26 21:01 . 2008-07-22 13:2498,304--a------c:\windows\System32\TwcToolbarBho.dll
    2009-03-26 21:01 . 2007-12-03 12:3625,600--a------c:\windows\System32\TwcToolInstDll.dll
    2009-03-26 21:00 . 2009-03-26 21:00d--------c:\program files\The Weather Channel FW
    2009-03-26 18:27 . 2009-03-26 18:27d--------c:\users\Doris\AppData\Roaming\AVS4YOU
    2009-03-26 18:27 . 2009-03-26 18:27d--------c:\users\All Users\AVS4YOU
    2009-03-26 18:27 . 2009-03-26 18:27d--------c:\programdata\AVS4YOU
    2009-03-26 18:25 . 2009-04-05 18:39d--------c:\program files\Common Files\AVSMedia
    2009-03-26 18:25 . 2009-04-05 18:39d--------c:\program files\AVS4YOU
    2009-03-26 18:25 . 2002-01-05 14:40487,424--a------c:\windows\System32\msvcp70.dll
    2009-03-26 18:25 . 2003-05-21 12:5024,576--a------c:\windows\System32\msxml3a.dll
    2009-03-23 14:45 . 2009-04-07 09:48d--------c:\users\Doris\Tracing
    2009-03-23 14:44 . 2009-03-23 14:44d--------c:\program files\Windows Live SkyDrive
    2009-03-23 14:44 . 2009-03-23 14:44d--------c:\program files\Microsoft
    2009-03-23 14:41 . 2009-03-23 14:41d--------c:\program files\Common Files\Windows Live
    2009-03-14 16:35 . 2009-03-14 16:36d--------c:\program files\EndItAll
    2009-03-14 04:19 . 2009-03-14 04:19d--------c:\program files\Movie Maker 2.6
    2009-03-14 03:35 . 2009-03-14 03:40d--------c:\users\Doris\AppData\Roaming\vlc
    2009-03-14 03:35 . 2009-03-14 03:35d--------c:\program files\VideoLAN
    2009-03-14 03:27 . 2009-03-14 16:25d--------c:\program files\Winamp
    2009-03-14 02:22 . 2009-03-14 02:22d--------c:\users\Doris\AppData\Roaming\Xilisoft Corporation
    2009-03-14 02:20 . 2009-03-14 02:20d--------c:\program files\Xilisoft
    2009-03-14 02:10 . 2009-03-14 16:25d--------c:\program files\WM Converter
    2009-03-14 01:58 . 2009-03-14 03:27d--------c:\program files\Common Files\PX Storage Engine
    2009-03-14 01:57 . 2009-03-27 09:27d--------c:\program files\DivX
    2009-03-14 01:37 . 2009-03-15 01:32d-a------c:\users\All Users\TEMP
    2009-03-14 01:37 . 2009-03-15 01:32d-a------c:\programdata\TEMP
    2009-03-14 01:37 . 2009-03-15 01:32d--------C:\Fraps
    2009-03-11 03:43 . 2002-01-05 13:48974,848---------c:\windows\System32\mfc70.dll
    2009-03-11 03:43 . 2002-01-05 12:37344,064---------c:\windows\System32\msvcr70.dll
    2009-03-11 03:43 . 2003-07-24 10:24237,568--a------c:\windows\System32\demoover.exe
    2009-03-11 03:43 . 2004-05-29 17:5291,072---------c:\windows\System32\RoseCo2.dll
    2009-03-11 03:43 . 2004-05-29 17:5382,896---------c:\windows\System32\KickCom2.dll
    2009-03-11 03:42 . 2009-03-11 04:36d--------C:\moove
    2009-03-11 03:42 . 2001-10-12 15:443,310---------c:\windows\System32\advanced.ico
    2009-03-11 03:42 . 1998-04-24 00:001,078---------c:\windows\System32\rosewaste.ico
    2009-03-11 03:22 . 2009-03-14 16:28d--------c:\program files\Kaneva
    2009-03-10 13:17 . 2008-12-15 23:298,147,456--a------c:\windows\System32\wmploc.DLL
    2009-03-10 13:17 . 2008-12-16 01:317,680--a------c:\windows\System32\spwmp.dll
    2009-03-10 13:17 . 2008-12-16 01:314,096--a------c:\windows\System32\msdxm.ocx
    2009-03-10 13:17 . 2008-12-16 01:314,096--a------c:\windows\System32\dxmasf.dll
    2009-03-10 13:16 . 2009-02-08 23:102,033,152--a------c:\windows\System32\win32k.sys
    2009-03-10 13:16 . 2008-11-27 00:43268,288--a------c:\windows\System32\schannel.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-07 16:58---------d-----wc:\programdata\Symantec
    2009-04-07 02:55---------d--h--wc:\program files\InstallShield Installation Information
    2009-04-07 02:40---------d-----wc:\program files\Microsoft Games
    2009-04-07 02:34---------d-----wc:\users\Doris\AppData\Roaming\uTorrent
    2009-04-06 22:18---------d-----wc:\program files\Java
    2009-04-06 18:43---------d-----wc:\program files\Common Files\Wise Installation Wizard
    2009-04-05 22:12---------d-----wc:\program files\Common Files\Symantec Shared
    2009-03-27 22:45---------d-----wc:\users\Doris\AppData\Roaming\HP
    2009-03-23 18:43---------d-----wc:\program files\Windows Live
    2009-03-14 20:30---------d-----wc:\program files\Yahoo!
    2009-03-14 20:22---------d-----wc:\program files\Warcraft III
    2009-03-11 21:19---------d-----wc:\program files\Maxis
    2009-03-11 07:44---------d-----wc:\program files\Windows Mail
    2009-03-04 10:29---------d-----wc:\programdata\Yahoo!
    2009-03-04 10:26---------d-----wc:\users\Doris\AppData\Roaming\Yahoo!
    2009-02-28 04:03---------d-----wc:\users\Doris\AppData\Roaming\Ideazon
    2009-02-28 04:01---------d-----wc:\program files\Ideazon
    2009-02-20 01:48---------d-----wc:\program files\7-Zip
    2009-02-19 17:3196,560----a-wc:\windows\system32\drivers\symfw.sys
    2009-02-19 17:319,844----a-wc:\windows\system32\drivers\SymRedir.cat
    2009-02-19 17:3141,008----a-wc:\windows\system32\drivers\symndisv.sys
    2009-02-19 17:3138,576----a-wc:\windows\system32\drivers\symids.sys
    2009-02-19 17:3124,112----a-wc:\windows\system32\drivers\SymIMV.sys
    2009-02-19 17:3122,320----a-wc:\windows\system32\drivers\symredrv.sys
    2009-02-19 17:31184,496----a-wc:\windows\system32\drivers\symtdi.sys
    2009-02-19 17:3113,616----a-wc:\windows\system32\drivers\symdns.sys
    2009-02-19 17:311,611----a-wc:\windows\system32\drivers\SymRedir.inf
    2009-02-10 20:56---------d-----wc:\users\Doris\AppData\Roaming\GetRightToGo
    2009-02-06 22:5249,504----a-wc:\windows\System32\sirenacm.dll
    2009-01-15 06:11827,392----a-wc:\windows\System32\wininet.dll
    2008-01-21 02:43174--sha-wc:\program files\desktop.ini
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
    "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
    "DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-10-25 212992]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 202032]
    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
    "Zboard"="c:\program files\Ideazon\ZEngine\Zboard.exe" [2008-11-12 57344]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-06 148888]
    "MRT"="c:\windows\system32\MRT.exe" [2009-02-25 24768960]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.l3codecp"= l3codecp.acm

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2007-05-11 07:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
    --a------ 2007-10-03 19:15 480560 c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
    --a------ 2007-10-03 18:44 178712 c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UacDisableNotify"=dword:00000001
    "InternetSettingsDisableNotify"=dword:00000001
    "AutoUpdateDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-256968735-640673003-351684455-1004]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{0C53955B-DA7B-4D19-BA7F-C3CB861DD127}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{FD04AC5D-80BB-4236-B929-5FE0F9062AA1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{7B754820-430B-45BC-94F4-41B6E1FE1C31}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{5DAE2496-F342-4EDC-AD0D-57C4F2FBD791}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{5506AB42-C949-428E-9933-843D58434240}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{70BBC0E6-A428-4B94-AED1-03C6FC39BEF7}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{B1DD21E3-600D-4A50-BFC1-46449F6C36B9}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{03510A4F-F70C-41A5-BCBC-ACE4311F5B29}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{E8474A6C-2929-473E-BC70-2CAF59DF1323}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{9D3EAB25-7FE2-4059-99AD-705B409E0582}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{7AC37F4F-38B2-467D-9B36-5928C8AE0322}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{0E2AE14D-5586-4934-BDB9-A8F70E2B55B8}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
    "{45FABCFD-6E9B-4EB4-93F1-895F353A67BC}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
    "{B440AFF3-8EE0-4D1A-9DFB-61E0B55D8BD5}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
    "{ED3E1680-003B-426D-9408-CDF644F7D019}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
    "{836450E8-5137-45BF-9A16-2CF8F78ACF9E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
    "{DD3C3DCF-01F9-44F9-BFD5-F880336DFBBC}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
    "{94B91045-FA70-47D5-BA2E-73CAAE9B3DBA}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
    "{879FFDE0-AD61-4957-9273-00A29424AC84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
    "{8FC23F4B-A223-47CE-AAF6-80D1ECCA86E3}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
    "{388F61DD-611C-41AD-A683-ADA389F202DA}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
    "{B7058F4F-EF2A-4A66-AD3C-F12AF8F61AD7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
    "{C6D9C9BC-4D8E-4BC4-A497-318C91E8718C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
    "{43037F55-683A-4730-953C-52E5C9AE903A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
    "{DFCD453A-013C-4E44-B814-DF8A13DBECF8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
    "{11D47BC6-927C-446B-B95B-2F12BB5DCD83}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
    "{949E98F9-9D71-4F4D-B614-A612C3ED49CA}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
    "{FBE336B9-2DA9-4BAA-AF38-7B5367D4F205}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
    "{3E387DF5-D4AE-4BCC-8E41-79DC113F3C48}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
    "{29AB88E1-4A3C-4469-82EA-3BA6912D4DD7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
    "{4AFE900C-BF8C-47C0-96F1-FDC0B170FAB6}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
    "{2B3A7DE9-42B4-486A-A869-D629014218F7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
    "{7959871D-B519-44FD-A2A9-38B50744F7B8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
    "{C838A574-C47C-4072-BB8D-F0182151F6D2}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
    "{A90D1241-56BC-46CE-A8FE-855A3AB04C28}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
    "{B61A6346-323D-455F-9CE9-8488A575F881}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{1E017D30-5307-4F81-B074-70CAFA94D7DC}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "{9F636F78-1F18-4E1E-B7B5-12219041BFE1}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{65B23307-6F92-41CD-A629-AE686E1D5AEB}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)
    "DoNotAllowExceptions"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090331.003\IDSvix86.sys [2009-04-02 272432]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-03-23 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-03-23 72944]
    R2 atashost;WebEx Service Host for Support Center;c:\windows\System32\atashost.exe [2008-09-09 20376]
    R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2007-08-25 149352]
    R3 Alpham1;Ideazon ZBoard USB Human Interface Device;c:\windows\System32\drivers\Alpham1.sys [2007-07-23 42624]
    R3 Alpham2;Ideazon ZBoard MM USB Human Interface Device;c:\windows\System32\drivers\Alpham2.sys [2007-03-20 18432]
    R3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2007-05-29 23888]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-01 101936]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
    R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2009-02-19 41008]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - COMHOST

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-07 c:\windows\Tasks\AWC Startup.job
    - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-02-22 14:45]

    2009-04-07 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Doris.job
    - c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 20:19]

    2009-04-07 c:\windows\Tasks\SmartDefrag.job
    - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 18:15]

    2009-04-07 c:\windows\Tasks\SmartDefrag.job
    - c:\program files\IObit\IObit SmartDefrag\ [2009-04-06 23:44]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    Trusted Zone: moove.com
    FF - ProfilePath - c:\users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\ea13htpd.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.perfectworld.com
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npkanevapatch.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-07 15:27:33
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-04-07 15:31:00
    ComboFix-quarantined-files.txt 2009-04-07 19:30:54

    Pre-Run: 106,823,573,504 bytes free
    Post-Run: 106,879,004,672 bytes free

    285--- E O F ---2009-04-07 13:56:33
      Quote from: psychotic on April 07, 2009, 01:37:50 PM
      So is it safe to delete all these transparent folders? Or even log on important sites, I.E. my online bank account? Sorry, most of my knowledge is in building computers, not removing worms, trojans, whatever have you

      Let me know how everything is after this next step.

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Are the icons still there and if so which ones?


      They are all still there (The notpad file you see, is just the instructions I was to print.)

      • Close all programs so that you are at your desktop.
      • Open the Control Panel menu and click Folder Options.
      • After the new window appears select the View tab.
      • Make sure there is NO checkmark in the checkbox labeled Display the contents of system folders.
      • Under the Hidden files and folders section select the radio button labeled Do not show hidden files and folders.
      • Place a checkmark in the checkbox labeled Hide file extensions for known file types.
      • Place a checkmark from the checkbox labeled Hide protected operating system files.
      • Press the Apply button and then the OK button and exit My Computer.
      • Now your computer is configured to hide all hidden files and folders which is the default and should always be this way unless needed for MAINTENANCE or removing malware.
      .
      ----------

      Now delete any hidden (transparent) files/folders left on the desktop.

      Download CCleaner Slim and save it to your Desktop.
      When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
      Follow the prompts to install the program.
      Complete the installation then:

      • Double-click the CCleaner shortcut on the desktop to start the program.
      • Click on the Options block on the left, then choose Cookies.
        • Under Cookies to Delete, highlight any cookies you would like to retain permanently
        • Click the right arrow > to move them to the Cookies to Keep window.
        .
      • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
      • Click Cleaner on the left then Run Cleaner on the right to run the program.
      • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
      • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
      • Exit CCleaner after it has completed its process.
      .
      Note CCleaner is a 100% free tool. I suggest keeping it and running it regularly to keep your computer running smooth.

      ----------

      We have not done a full virus scan yet so we should do so now.

      Use the Kaspersky Lab Online Scanner

      In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

      • Click on SCAN NOW
      • Click Accept.
      • The program will then begin downloading the latest definition files.
      • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
      • The scan will take a while, so be patient and let it finish.
      When the scan is done, in the Scan is complete window, any infection is displayed.
      There is no option to clean/disinfect, however, we need to analyze the information on the report.

      To obtain the report:
      Click on: Save Report As
      • Next, in the Save as prompt, Save in area, select: Desktop.
      • In the File name area use KScan, or something similar.
      • In Save as type: click the drop arrow and select: Text file [*.txt]
      • Then, click: Save


      Copy and paste the Kaspersky Online Scanner Report in your next reply.

      Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

      If needed, this animation will guide you through the process.The Hidden files, are fully hidden now, didn't have to delete any of them, started the scan an hour ago, its at 18%, will post it as soon as its done.

      Thanks for your help thus far, by the way.Uhhh.... heres the log..., lol, 0 problems... So am I clean?

      No malware has been detected. The scan area is clean.Looks good.

      Final steps.

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok, thanks again, glad I found a place that won't charge me an arm and a leg for this


      Take careYour welcome.

      Safe surfing...
      3120.

      Solve : .exe bad image warnings?

      Answer»

      Hello EVERYONE. Everytime I open a program I see the same warning. I will use firefox as an example.
      It says:

      firefox.exe- BAD Image
      The application of DLL C:\WINDOWS\systems32\rigezide.dll is not a valid windows image. PLEASE check this against your installation diskette.

      This happens all the time. Is there anyway to get rid of this? I have a dell inspiron 1100 and run xp
      Mbam, SPYBOT, adaware pick up nothing so I don't know if its infected.

      Thank you

      3121.

      Solve : browser keeps redirecting me and can't install windows update...?

      Answer»

      Hi. running Vista with IE 8 and yahoo canada and didn't know if I can follow the same steps as the sticky TOPIC..

      Only redirects when I do a search not when I enter one of my favorite...

      Ran my Mcafee full scan and nothing

      Windows update won't install saying error code 80240016

      any help appreatiated...

      Tried changing browser to firefox but wouldn't work right and tried INSTALLING Spyboy and it wouldn't install, tried google etc and still the same....Save some time, run all the scans and post the logs.....help will arrive.Thank you for the reply Karnac. So I should follow the steps in the sticky message about Malware Removal Guide even having Vista? Thanks
      Absolutely........follow the directions in order, post the logs, and a specialist will assist you.Hi. Well I am following the malware removel steps and when I click on the download the free Superantispyware it loads for a second then it goes into "internet cannot DISPLAY the PAGE" Just continue with what you can and post you logs for Evil Fantasy.try dling it in SAFE mode... hope i can say this?

      3122.

      Solve : Blaster email spying?

      Answer»

      Has ANYONE ever used this to keep track of emails etc,, for kids and spouses?Thanks,,Do you mean eBlaster http://www.eblaster.com Sounds like a lot of MONEY and a very distinct invasion of a person's privacy.That would be the one,and yes it is an invasion of privacy but for keeping kids safe,and a spouse honest thats what you have to do,,,Quote from: illini3023 on April 06, 2009, 03:43:31 PM

      That would be the one,and yes it is an invasion of privacy but for keeping kids safe,and a spouse honest thats what you have to do,,,

      I'm not going to tell you that's wrong and right but I and many of us here disagree. For kids it's education and parenting. Not spying. That only destroys trust. If they are breaking the rules then they loose computer privileges and other things they like. You know, discipline?

      Won't COMMENT on your spouse but I think you already know that if you can't trust someone, spouse, best friend or whoever, then it will never work out. I remember a KEYLOGGER meant for "security"...
      Keylogger is to security as George W. Bush is to smart.

      I can't remember what those are called...but this is basically the same thing. The eBlaster will probably send a copy of all their email addresses to advertising companies. I advise not using it for both privacy and security issues.huge waste of money too. may as well attach a security limpet to their head or something.Quote from: BC_Programmer on April 07, 2009, 04:47:17 PM
      huge waste of money too. may as well attach a security limpet to their head or something.

      I can't belive someone would actually be stupid ENOUGH to pay so their private emails sent to large corporations, just so they can make better ads.
      3123.

      Solve : Is this dangerous??

      Answer»

      My AVG resident virus shield has given me this notice: Resident shield alert; Threat name: runtime packed nspack detected on open.
      This came up in a CD that I bought for our kids, a story book type thing. Is this really dangerous? Can I defang it in any way? Do I have to THROW the CD away or can it be fixed? I've got a whining kid on my hands here so if you can help me figure out if I really have to throw the thing out, I'd appreciate it.

      Note: I went to the AVG site and they didn't recognize the virus when I searched in their encyclopedia. Also, there was no "HEAL" BUTTON on the dialogue box. Only "remove threat as power user" but I don't know what that means.

      What should I do?
      Thanks
      Dr.D.Try UNINSTALLING that thing first and see what happens NEXT. Thanks KingPincer but I hadn't installed it yet. As soon as I clicked on the icon for my DVD drive, I got the security warning. I took things no farther. I'd just like to know what kind of virus this is, can I fix it, or do I have to throw the CD away. We were on vacation and bought this as a souvenir for our kids, so we can't take it back. I hate to throw away the money and disappoint the kids, unless of course this is necessary for the safety of our computer.

      anyone else know anything about this virus or what I can do in this situation? Thank you.

      In peace
      Dr. D.Is the CD that you bought a fake or original cause you said that once you click the CD a alert just pops out. For me this is a spy ware cause once you installed this thing it installs something to your computer that you don't know making the performance of your computer not that good.

      3124.

      Solve : Virus emails?

      Answer»

      I have a couple of VIRUS emails that are saved in my email account.. would anybody like to have them? In the sense email to them? I would just like to know what they are? Norton stopped me from opening them. It would be cool if SOMEONE COULD tell me what they were. If not no MATTER...Does not Norton report to you what kinds of viruses it found?

      Yeah there trojan's but I thought there were PEOPLE who can pull these programmes apart.. there from a couple of years ago.to pull them apart you would have to open them , get ride of them , harry

      3125.

      Solve : no name file in system tray?

      Answer»

      hi again. i've got another issue i can't fix on my own... any help is always appreciated.

      yesterday i noticed a blank space in the ICONS on my SYSTEM tray:



      upon further investigation, it turns out to be a file with no name... can't right-click it, can't determine where it's located to rename it, open it, or delete it.



      i also have since gotten an error when trying to open My Documents that there is not enough memory because too many programs were running, yet my memory was nowhere near max'd and i could open other programs which REQUIRE much more memory, like MS Word or game applications. no idea if these are related, but they appeared at the same time, so it's definitely an odd coincidence, right?

      anyway, the logs are attached below. thanks again.

      [attachment deleted by admin]I'm not sure but it could be this:

      C:\DOCUME~1\ZACHAR~1.DEL\LOCALS~1\Temp\Temporary Directory 1 for lcdsirreal267.zip\LCDSirReal.exe

      Which is your driver for Logitech G15 keyboard with LCD display. It's running from a temporary folder so might not have installed correctly.that would be odd if it was, i've been using this app for years.

      ...but now that i OPENED that file, it also contains an error log for that app that has four entries, all from yesterday. a quick check of the Task Manager showed 2 processes running for it as well, so perhaps that is the issue?

      i didn't mention this before because i thought it had been fixed, but my Search option for Windows wasn't working a couple days ago either. after much time spent with the MS tech yesterday he got it working, but now it's dysfunctional again. correction: it will let me search for documents, but not files & folders.

      edit: alright, deleted that file and now i'm getting the "not enough memory" error again when i hit the My Documents link, but i can go to my folders just fine manually. also, the no-name file is still showing on my system tray. alright, i stumbled upon another process which didn't look familiar, so i killed it and the entire taskbar flashed... then the no-name file disappeared. i also got my ability to use the Search Windows link and My Documents back instantly. wish i could remember exactly what the process was (dwesrnd.exe, or something similar) so i could post it here, but if it comes back i'll pay more attention to it so that you can have all the info i have.

      thanks for pointing out that extra LCDSirReal file... if i have any more problems i'll come back with new logs.

      appreciate the help.

      edit: forgot to mention that i restarted the PC and it didn't return

      3126.

      Solve : Mountain of problems?

      Answer»

      Sorry gunbrown but with Virut it is a no win battle. There are a few lines in a HJT log that I LOOK for that point to Virut. Unfortunately your log has not one but multiple which means that the infection has gotten very well rooted into the entire system.

      Here are a few.

      Quote

      O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Katt\reader_s.exe (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')

      Your thread title "Mountain of PROBLEMS" is more accurate than you might have realized...

      Dr Web CureIt is your best bet. Run that now. Then again tomorrow.

      Quote from: BC_Programmer on April 02, 2009, 01:24:29 PM
      I'm speshul?

      aww shucks.


      Also let's recognize macDad for being the first person to give the proper link; NONE of this "oh and do <this>" and "don't forget to <this>". It's just going in circles.

      Yea macDad is one of our members who "get's it."

      BC I'm sure you could/can read these logs just as well or better than I do. I'm just waiting for you to pick up a thread and follow it through to the end There is also this.

      O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

      You need to uninstall anything that says NORTON, Symantec or Live Update. Two antivirus will only cause you problems.

      Run this tool to ensure all of Norton is gone. Norton Removal Tool (SymNRT)Quote from: BC_Programmer on April 02, 2009, 01:24:29 PM
      I'm speshul?

      aww shucks.


      Also let's recognize macDad for being the first person to give the proper link; none of this "oh and do <this>" and "don't forget to <this>". It's just going in circles.

      Thanks BC and Evil, just wanted to direct them to the right place.

      My knowledge of viruses, malware is pretty vague...but to get them on track is at least something that i can help with. I'm speshul?

      aww shucks.

      Yes, You Are and You Know it,
      Evil's a heck of a Guy too....................Well i'm not an expert or anything but i think i may have gotten rid of the virut but there are still on or two other trojans that keep popping up each time upon boot up. i say this because neither avg or any of the virut removers detect ANYMORE virut infected files and they usually do. But as i had anticipated the system files are messed up and stuff so some programs won't work. i think i might be able to work them out individually but now that i have most of the control of the pc i'll just backup the files and reformat, only problem now is that my girlfriend lost the hp cd .

      Anyways thank you very much for your time and help. I'm only in here once every two years or so but i love what you guys do. maybe one day i'll grow up to be like you. Quote from: gunbrown on April 03, 2009, 11:01:21 AM
      thank you very much for your time and help. I'm only in here once every two years or so but i love what you guys do. maybe one day i'll grow up to be like you.


      Grow-up is what everybody I meet tells me to do. Well I Hope You never Do it's the Worst thingthat can happen You know That shouldnt need to be a requriement unless you want to take care of all of it yourself. I would try spybot and see if that wouldnt help, since its built to do this stuff.Virut prevents any App from running.Quote from: squall_01 on April 04, 2009, 05:36:57 PM
      That shouldnt need to be a requriement unless you want to take care of all of it yourself. I would try spybot and see if that wouldnt help, since its built to do this stuff.

      I'm not sure what u're talking about squall_01. Whats does spybot do?same as SuperAntiSpyware....its another Anti-Spyware ProgI see just a thought in case it gets rid of a lot of my junk....Not trying to put you down, just saying that its an Anti-Spyware Program.I understand no hard feelings or anything of that for that matter.
      3127.

      Solve : program name.exe - Bad Image Error (logs inside)?

      Answer»

      Hi, Can you please help with what I have to do to FIX this!!!

      Every program or file I open, I get a message saying;

      program name.exe - Bad Image
      The application or DLL C::\WINDOWS\system32\yalepefo.dll is not a valid Windows Image.

      Here ar my Logs;
      Hijackthis
      Quote

      Logfile of Trend MICRO HijackThis v2.0.2
      Scan saved at 19:51:38, on 06/04/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\PremierOpinion\pmropn.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMWDSrv.exe
      C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Spyware Terminator\sp_rsser.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\system32\RunDll32.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\AIM6\aim6.exe
      C:\WINDOWS\system32\wbem\unsecapp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      C:\Program Files\AIM6\aolsoftware.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
      O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O2 - BHO: (no name) - {b74ab59c-530d-4f7a-8918-e0d99af57269} - C:\WINDOWS\system32\yuhituka.dll (file missing)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
      O4 - HKLM\..\Run: [High DEFINITION Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
      O4 - HKLM\..\Run: [KMConfig] "C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe" KMConfig.exe
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
      O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
      O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
      O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190670149500
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190670135125
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?AuthParam=1239042671_5cd9b4621197155649b8cddd0a6f5909&GroupName=JSC&FilePath=/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab&File=jinstall-6u13-windows-i586-jc.cab&BHost=javadl.sun.com
      O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O20 - AppInit_DLLs: C:\WINDOWS\system32\yalepefo.dll,C:\WINDOWS\system32\vovamobe.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: PremierOpinion - C:\Program Files\PremierOpinion\pmls.dll
      O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMWDSrv.exe
      O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      --
      End of file - 10916 bytes

      mbam-log-2009-04-06 (19-23-26)
      Quote
      Malwarebytes' Anti-Malware 1.28
      Database version: 1250
      Windows 5.1.2600 Service Pack 3

      06/04/2009 19:23:26
      mbam-log-2009-04-06 (19-23-26).txt

      Scan TYPE: Full Scan (C:\|)
      Objects scanned: 161005
      Time elapsed: 28 minute(s), 58 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      REGISTRY Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)

      SUPERAntiSpyware Scan Log - 04-06-2009 - 18-32-22
      Quote
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/06/2009 at 06:32 PM

      Application Version : 4.26.1000

      Core Rules Database Version : 3829
      Trace Rules Database Version: 1785

      Scan type : Complete Scan
      Total Scan Time : 00:42:44

      Memory items scanned : 536
      Memory threats detected : 0
      Registry items scanned : 6480
      Registry threats detected : 0
      File items scanned : 107393
      File threats detected : 21

      Adware.Tracking Cookie
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Main User\Cookies\[emailprotected][2].txt
      3128.

      Solve : My NOrton expired today should I renew it or get something else??

      Answer»

      Quote

      outgoing traffic is only dangerous when you've already been compromised.
      Your computer may become infected but at least, the infections are not calling home with all your secret passwords and other sensitive information. Ahh, yes, that's a very good point; I was thinking of "danger level" more ALONG the LINES of probability to infect, not wether said traffic could contain sensitive data, which is far worse.Quote
      outgoing traffic is only dangerous when you've already been compromised.
      Whoever said that should retract it. How about:
      Mass breeding rattlesnakes and releasing
      them in a schoolyard is not
      dangerous if you are MENTALLY ill.

      One of the biggest THINGS the media picked up was how LimeWrie was PROVIDING software tools to allow professional criminals get credit card information and make millions. Not dangerous? Your e-mail list is a liability, if not for you, for your contacts.
      Now don't argue about how easy is it was or not. It happened.heh, Like I say, I was thinking more along the lines of danger from getting infected- since that wouldn't matter if one was already infected. But obviously the outgoing traffic from a trojan could prompt the download of further infections and the upload of personal information.
      3129.

      Solve : Packed Generic.200 Norton can't remove?

      Answer»

      I can't get rid of this virus. Norton keeps alerting me that it's infected. I've ran combofix,Malwarebytes,Superantispyware. Those got rid of a lot of stuff. They now read CLEAN on a re scan. But Norton Still SAYS it's infected. I cleared out the system restore and rebooted and cleared the Quarantine of Norton out and it still says it's infected. Is there a remover program for Packed Generic.200?Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 2:54:34 PM, on 4/9/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
      C:\Program Files\PDF COMPLETE\pdfsvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\PDF Complete\pdfsty.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.bbsihq.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL (file missing)
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL (file missing)
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
      O4 - HKLM\..\Run: [SDMSSplash] "C:\Program Files\HP_SDMS\SDMSSplash\launcher.exe" "launchdir=C:\Program Files\HP_SDMS\SDMSSplash"
      O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://download.windowspdate.com
      O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (CITRIX ICA Client) - https://www.bbsihq.com/bbsi/citrix/icaweb.cab
      O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186077039437
      O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://chill.comcast.net/AspNet2.0/App/games/channel--110341560/lc--en/room--fd671a9d-6fbb-47c5-b9eb-870fa1fd2ce4/online/wedding_dash/en/WeddingDash.1.0.0.47.cab
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
      O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe

      --
      End of file - 6841 bytes

      3130.

      Solve : 2 iexplore.exe in task manager?

      Answer»

      Hello,
      When I fire up IE, it shows twice in my task manager. Below are the three scan reports you have ASKED for. Thanks.

      SUPERANTISPYWARE Scan Log

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 04/09/2009 at 01:55 PM

      Application Version : 4.26.1000

      Core Rules Database Version : 3836
      Trace Rules Database Version: 1792

      Scan type : Complete Scan
      Total Scan Time : 00:22:48

      Memory items scanned : 393
      Memory threats detected : 0
      Registry items scanned : 4037
      Registry threats detected : 0
      File items scanned : 3183
      File threats detected : 0



      Malwarebytes' Anti-Malware Log

      Database version: 1954
      Windows 5.1.2600 Service Pack 3

      09/04/2009 5:25:06 PM
      mbam-log-2009-04-09 (17-25-06).txt

      Scan type: Full Scan (C:\|)
      Objects scanned: 101582
      Time elapsed: 48 minute(s), 45 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


      Hijack This Log

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 5:30:21 PM, on 09/04/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Hotspot Shield\bin\openvpnas.exe
      C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Anti-Malware\mbamservice.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\AVG8\avgtray.exe
      C:\PROGRA~1\AVG8\avgwdsvc.exe
      C:\PROGRA~1\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG8\avgemc.exe
      C:\Program Files\AVG8\avgcsrvx.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\Dave\Local Settings\Temporary Internet Files\Content.IE5\L06CEEKQ\HiJackThis[1].exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG8\avgssie.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
      O4 - HKLM\..\Run: [CARPService] carpserv.exe
      O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Anti-Malware\mbamgui.exe" /starttray
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Window Washer\WashIdx.exe "Dave"
      O4 - HKUS\S-1-5-21-1417066420-2678003418-1157166300-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
      O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238818815717
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=29223
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG8\avgpp.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8\avgwdsvc.exe
      O23 - Service: Hotspot Shield Service (HotspotShieldService) - UNKNOWN owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
      O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Anti-Malware\mbamservice.exe
      O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
      O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Window Washer\WasherSvc.exe

      --
      End of file - 5392 bytes

      Also, im wondering if you could refer me to a good root kit seeker

      Thanks very much

      Cheers

      3131.

      Solve : computer virus/malware?

      Answer»

      Here are the latest logs. The CCleaner didn't find ANYTHING to delete.
      Malwarebytes' Anti-Malware 1.35
      Database version: 1904
      Windows 5.1.2600 Service Pack 3

      4/8/2009 7:25:33 PM
      mbam-log-2009-04-08 (19-25-33).txt

      Scan type: Full Scan (C:\|D:\|)
      OBJECTS scanned: 184054
      Time elapsed: 1 HOUR(s), 15 minute(s), 7 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 6:03:20 PM, on 4/8/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      D:\WINDOWS\System32\smss.exe
      D:\WINDOWS\system32\winlogon.exe
      D:\WINDOWS\system32\services.exe
      D:\WINDOWS\system32\lsass.exe
      D:\WINDOWS\system32\svchost.exe
      D:\WINDOWS\System32\svchost.exe
      D:\WINDOWS\system32\spoolsv.exe
      D:\WINDOWS\Explorer.EXE
      D:\Program Files\McAfee\Common Framework\FrameworkService.exe
      D:\Program Files\QuickTime\qttask.exe
      D:\Program Files\McAfee\Common Framework\udaterui.exe
      D:\Program Files\Messenger\msmsgs.exe
      D:\Program Files\OpenOffice.org 2.3\program\soffice.exe
      D:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
      D:\Program Files\McAfee\Common Framework\McTray.exe
      D:\WINDOWS\system32\wscntfy.exe
      D:\WINDOWS\system32\wuauclt.exe
      D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mmc.org/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - D:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [HPLJ Config] D:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\SetConfig.exe -c Direct -p DOT4_001 -pn "hp LaserJet 1320 PCL 6" -n 1 -l 1033 -sl 120000
      O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
      O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Windows UPDATE loader] C:\Windows\xpupdate.exe
      O4 - HKCU\..\Run: [TomTomHOME.exe] "D:\Documents and Settings\engineering\My Documents\TomTom HOME 2\HOMERunner.exe"
      O4 - HKCU\..\Run: [Weather] D:\Program Files\AWS\WeatherBug\Weather.exe 1
      O4 - Startup: OpenOffice.org 2.3.lnk = D:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
      O10 - UNKNOWN file in Winsock LSP: d:\windows\system32\nwprovau.dll
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
      O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - http://www.photodex.com/pxplay.cab
      O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
      O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - D:\Program Files\McAfee\Common Framework\FrameworkService.exe
      O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe

      --
      End of file - 4598 bytes

      What should I do next?
      hi earmic hows the pc going now , all looks ok

      but wait for an expert , harry

      3132.

      Solve : Search result issue?

      Answer»

      Hello Phil. Could you please run MBAM again and this time clean the infection. Then, let me know how your computer is running.SD
      Maybe I wasn't clear in my last post, MBAM did remove the infected file. I just ran it again and will attach the log, nothing found this time. That devldr.exe file has not re-appeared since I last deleted it. Everything seems to be working normally since my last post, including proper functioning of my search results. If you think there's anything else I should check, please let me know.
      Again, thank you very much for all your help.
      pk

      [Saving space, attachment deleted by admin]Hello phil. That's good news. Thanks for being so patient with me. Let's do some clean up. You can uninstall HJT but keep SAS and MBAM, if you wish. Update them and run them about once a week to keep the bugs out.

      * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
      * Now type Combofix /uninstall in the runbox
      * Make sure there's a space between Combofix and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.

      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my HOMEPAGE" and uncheck any HopSurf and/or Ask.com OPTIONS if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all CRITICAL updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your BROWSER. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

      Safe Surfing!

      3133.

      Solve : Keyboard screwed up on a XP SP3 OS?

      Answer»

      Has anyone had a problem with the keys on the right side only changing to different letters and numbers that don’t match what you type?? For instants the letters on the left of the keyboard QWERTYASDFGHZXCVBN123456 work fine but on the right side is all screwed up. U goes back space then up, I does nothing, O STEP forward one and stops, P -, J steps down one and stops, L nothing, ; +, M nothing, . nothing, 7 nothing, 8 goes up, 9 nothing, 0 *.
      Note if you press the Function key on the laptop while PRESSING the keys on the right side you get the right keys back.

      I have gone back in system restore and has worked in the past. It seems to be more of a conflict with windows automatic updates and not a virus as it has happened on my desktop or laptop with different virus scans in place, and has not come up as any virus. The next time you start up from a windows update this happens and corrupts the keyboard and of coarse you can’t log in.
      Any fix come to mind??? would an reinstall of the keyboard drivers be a fix?
      Sounds LIKE you have number lock turned on, Try Fn+F11 (may be something besides F11, look for the key with a picture that looks like a calculator)
      this is in the wrong topicQuote from: cruisin702 on January 03, 2010, 01:34:16 AM

      Sounds like you have number lock turned on, Try Fn+F11 (may be something besides F11, look for the key with a picture that looks like a calculator)


      ;DThanks, You where right!!! Pressed Fn and F8 and all ok now!
      3134.

      Solve : Super Anti-Spyware Log?

      Answer»

      This is the log I got after running the Super Anti-Spyware. What information/advice could you give me from this data?
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 06/24/2010 at 08:26 PM

      Application Version : 4.39.1002

      Core Rules Database Version : 5057
      Trace Rules Database Version: 2869

      Scan type : Quick Scan
      Total Scan Time : 00:45:10

      Memory items scanned : 548
      Memory threats detected : 0
      Registry items scanned : 1436
      Registry threats detected : 6
      File items scanned : 36820
      File threats detected : 1038

      Rogue.AntivirusSoft
      HKU\S-1-5-21-3615259314-1621620533-1473750240-1005\Software\avsoft

      Malware.Trace
      HKU\S-1-5-21-3615259314-1621620533-1473750240-1005\SOFTWARE\AVSUITE
      HKLM\SOFTWARE\AVSUITE
      HKLM\SOFTWARE\AVSOFT

      Disabled.SecurityCenterOption
      HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#ANTIVIRUSDISABLENOTIFY
      HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY

      Adware.Tracking Cookie
      2mdn.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      ads1.msn.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      b.ads1.msn.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      foodbycountry.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      googleads.g.doubleclick.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      hairstyle.seventeen.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      ia.media-imdb.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      interclick.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      m1.2mdn.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media.mtvnservices.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media.resulthost.org [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media.scanscout.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media.tattomedia.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media01.kyte.tv [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      media1.break.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      msnbcmedia.msn.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      objects.tremormedia.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      secure-us.imrworldwide.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      static.2mdn.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      udn.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      www.teennick.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      wwwstatic.megaporn.com [ C:\Documents and Settings\Bobby\Application Data\Macromedia\Flash Player\#SharedObjects\LDYR8X3P ]
      .specificmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .www.sexytheresas.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .www.sexytheresas.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .www.sexytheresas.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .xxxdessert.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .collective-media.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .collective-media.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .collective-media.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .e-2dj6wjl4amc5eko.stats.esomniture.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      adserving.autotrader.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.autoleadsystems.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adinterax.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adinterax.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .collective-media.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      mediamall.wireless.att.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      lawyers.findlaw.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .qnsr.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .interclick.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .game-advertising-online.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .smartadserver.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .doubleclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .smartadserver.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .smartadserver.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .xiti.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tacoda.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tacoda.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tacoda.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .at.atwola.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .atdmt.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ext-us.bestofmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .kontera.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .kontera.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .chitika.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .kontera.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .bs.serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .socialmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .realmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .casalemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .interclick.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .apmebf.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .websponsors.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .websponsors.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .fastclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .fastclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .247realmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .zedo.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .zedo.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .imrworldwide.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .imrworldwide.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .microsoftwindows.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ads.bridgetrack.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .questionmarket.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .revsci.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .network.realmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.teennick.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .overture.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .overture.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .teennick.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .viacom.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .viacom.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .mediaplex.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .mediaplex.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .jibjab.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-myspaceinc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-myspaceinc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ads.pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .burstnet.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .247realmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.burstbeacon.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .burstbeacon.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      stat.onestat.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      stat.onestat.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .pointroll.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .lucidmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .lucidmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .lucidmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .yieldmanager.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .zedo.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adbrite.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adbrite.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .invitemedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .edge.ru4.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .edge.ru4.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adserver.adtechus.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adtech.de [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .statcounter.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .intermundomedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .overture.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .kontera.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-myspaceinc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .atdmt.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .viacom.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .burstnet.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-nestleusainc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-nestleusainc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-nestleusainc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      sales.liveperson.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      sales.liveperson.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      statse.webtrendslive.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .healthgrades.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .fastclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .msnportal.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .bestbuy.122.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .statcounter.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .statcounter.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .azjmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .smartadserver.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-myspaceinc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .statcounter.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .timeinc.122.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      find.myrecipes.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .find.myrecipes.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      find.myrecipes.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .highbeam.122.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .valueclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      dc.tremormedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      data.coremetrics.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .newyorkandcompany.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .zedo.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .iacas.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trvlnet.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trvlnet.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trvlnet.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trvlnet.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trvlnet.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .perf.overture.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      eas.apm.emediate.eu [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-starbucks.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adlegend.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eyewonder.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .eyewonder.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adbrite.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      stat.onestat.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adecn.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .linksynergy.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .linksynergy.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .linksynergy.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      counter.hitslink.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .precisionintermedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .precisionintermedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .viacom.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .viacom.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      adserving.cpxinteractive.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      adserving.cpxinteractive.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .22squared.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cgm.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cgm.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertiseyourgame.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .advertiseyourgame.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cgm.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .realmedia.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cgm.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .videoegg.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      rotator.adjuggler.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      rotator.adjuggler.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .carfax.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ru4.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ru4.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ru4.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      server.iad.liveperson.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      cdn4.specificclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ehg-myspaceinc.hitbox.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .revsci.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .trafficmp.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .dmtracker.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .doubleclick.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      eas.apm.emediate.eu [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .acronymfinder.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .revsci.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .roiservice.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.ticketsnow.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ticketsnow.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .ticketsnow.db.advertising.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.ticketsnow.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .surveymonkey.122.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .livenation.122.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adbrite.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .adbrite.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .insightexpressai.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .revsci.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .revsci.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .atdmt.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .cb.adbureau.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .qnsr.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .qnsr.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .serving-sys.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      sales.liveperson.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      sales.liveperson.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .questionmarket.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.googleadservices.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      www.googleadservices.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      webstats.aetna.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      webstats.aetna.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .g2.112.2o7.net [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .interclick.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .media6degrees.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      .tribalfusion.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      ad.yieldmanager.com [ C:\Documents and Settings\Bobby\Application Data\Mozilla\Firefox\Profiles\prkymud8.default\cookies.sqlite ]
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected]tsitesurfer[1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected]*censored*.pornlivenews[1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][5].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected]*censored*-enlargement-planet[1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][5].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][10].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][11].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][4].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][5].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][6].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][7].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][8].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][9].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected]*censored*-enlargement-planet[2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][1].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][2].txt
      C:\Documents and Settings\Bobby\Cookies\[emailprotected][3].txt
      bannerfarm.ace.advertising.com [ C:\Documents and Settings\Cassie\Application Data\Macromedia\Flash Player\#SharedObjects\X8NFWEBN ]
      cdn4.specificclick.net [ C:\Documents and Settings\Cassie\Application Data\Macromedia\Flash Player\#SharedObjMalwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Database version: 4244

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18702

      6/26/2010 12:21:21 PM
      mbam-log-2010-06-26 (12-21-21).txt

      Scan type: Quick scan
      Objects scanned: 171196
      Time elapsed: 13 minute(s), 55 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 1
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully.

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\Documents and Settings\Bobby\Local Settings\Temp\e.exe (Trojan.Mufanom) -> Quarantined and deleted successfully.
      Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other TOOLS or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      Your computer is possibly infected. Would you like to run some more scans and post the logs here?

      Please download: HiJackThis to your Desktop.

      • Double Click the HijackThis icon, located on your Desktop.
      • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
      • Accept the license agreement.
      • Click the Open the Misc Tools section button.
      • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
      • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
      • Please post the log in your next reply.
      ==================================

      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

      ================================

      Please download ComboFix from BleepingComputer.com

      Alternate link: GeeksToGo.com

      Alternate link: Forospyware.com

      Rename ComboFix.exe to commy.exe before you save it to your Desktop
      • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools ]A guide to do this can be found here
      • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
      • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.
      • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


      Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


      • Click on Yes, to continue scanning for malware.
      • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 3:01:32 PM, on 6/27/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\WINDOWS\lpcl.exe
      C:\Program Files\Common Files\Motive\McciCMService.exe
      C:\Program Files\PC Tools Firewall Plus\FWService.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
      C:\WINDOWS\system32\hphmon03.exe
      C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
      C:\Program Files\Motive\AsstCommon\motmon.exe
      C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Microsoft Security Essentials\msseces.exe
      C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
      C:\Program Files\Common Files\Java\Java Update\jusched.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Digital Lifeline\bin\mpbtn.exe
      C:\Program Files\palmOne\Hotsync.exe
      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HPQ\SHARED\HPQWMI.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (filesize 62080 bytes, MD5 C11F6A1F61481E24BE3FDC06EA6F7D2A)
      O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL (filesize 1865544 bytes, MD5 9F7C6AADF6B57946D4C37C9C910EC3F4)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (filesize 41760 bytes, MD5 385BD69743EA92E76CDF07B3345A25D5)
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (filesize 79648 bytes, MD5 4E2BB6D2677B42AD04BE18A6E9817B68)
      O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL (filesize 1865544 bytes, MD5 9F7C6AADF6B57946D4C37C9C910EC3F4)
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeC:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exeC:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start (filesize 405504 bytes, MD5 24C588CD72DDD39F7808922F711A3DF8)
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exeC:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
      O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exeC:\WINDOWS\system32\hphmon03.exe
      O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exeC:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
      O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart (filesize 3739648 bytes, MD5 BCD9CBF0621F9A6767276A2E0BF1DD15)
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (filesize 63712 bytes, MD5 FC9E59FE8BC4FE05382CFF5C8FC59DE1)
      O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (filesize 213936 bytes, MD5 2BAD84B393AF47006D80BA2F03B18029)
      O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exeC:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exeC:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
      O4 - HKLM\..\Run: [MotiveMonitor] "C:\Program Files\Motive\AsstCommon\motmon.exe" (filesize 155648 bytes, MD5 5DBCACF3FC3E81524128D4BFBC9725D5)
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exec:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exeC:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" (filesize 45056 bytes, MD5 45C07E3EE85A318D2DC8C391E952182A)
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (filesize 344064 bytes, MD5 1FF662360032871AF5F5DB9812321097)
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (filesize 39792 bytes, MD5 8B9145D229D4E89D15ACB820D4A3A90F)
      O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN (filesize 2061816 bytes, MD5 C6FC3B54AD1FEE0FE4069AB51BF4C724)
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (filesize 417792 bytes, MD5 55D7A219AD8D0DB8980528944152A6FD)
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (filesize 141600 bytes, MD5 68A553BDFA855C4F1074696682FCDEB6)
      O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey (filesize 1093208 bytes, MD5 5DB28B77A1A75DDDFEED99FB9722C540)
      O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s (filesize 3168216 bytes, MD5 B4C1C657FCCCAF24EBF028CE68E6D086)
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" (filesize 248040 bytes, MD5 52DB6CDAC5BC7A1FC884E97C41C91213)
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
      O4 - Global Startup: Digital Lifeline.lnk = C:\Program Files\Digital Lifeline\bin\mpbtn.exe (filesize 172032 bytes, MD5 6564B07717189A921C428E7B62A90CDB)
      O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (filesize 471040 bytes, MD5 F8FB2CA91F25D3EAA2CAE2F0B55FEC54)
      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe (filesize 118784 bytes, MD5 8C920DFE944B0DCE788DB3CB0320B336)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (filesize 558080 bytes, MD5 AAC1D4EE39DF138C5D30AC5883E3B59F)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (filesize 558080 bytes, MD5 AAC1D4EE39DF138C5D30AC5883E3B59F)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)
      O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184988058187
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLLC:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exeC:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeC:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeC:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: lpcl - Warranty Corporation of America - C:\WINDOWS\lpcl.exeC:\WINDOWS\lpcl.exe
      O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exeC:\Program Files\Common Files\Motive\McciCMService.exe
      O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exeC:\Program Files\PC Tools Firewall Plus\FWService.exe
      O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exeC:\WINDOWS\system32\HPHipm09.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeC:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)
      O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exeC:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

      --
      End of file - 13819 bytes
      ComboFix 10-06-27.03 - Sandra 06/27/2010 15:25:34.1.1 - x86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.452 [GMT -5:00]
      Running from: c:\documents and settings\Sandra\My Documents\Downloads\commy.exe
      AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
      FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Bobby\Local Settings\Application Data\{060A2A6F-FF3B-49E3-B01B-7D2F74549326}
      c:\documents and settings\Bobby\Local Settings\Application Data\{060A2A6F-FF3B-49E3-B01B-7D2F74549326}\chrome.manifest
      c:\documents and settings\Bobby\Local Settings\Application Data\{060A2A6F-FF3B-49E3-B01B-7D2F74549326}\chrome\content\_cfg.js
      c:\documents and settings\Bobby\Local Settings\Application Data\{060A2A6F-FF3B-49E3-B01B-7D2F74549326}\chrome\content\overlay.xul
      c:\documents and settings\Bobby\Local Settings\Application Data\{060A2A6F-FF3B-49E3-B01B-7D2F74549326}\install.rdf
      c:\documents and settings\Sandra\Local Settings\Application Data\{C7BD1C5F-319E-495C-8B9B-EB010B705AA1}
      c:\documents and settings\Sandra\Local Settings\Application Data\{C7BD1C5F-319E-495C-8B9B-EB010B705AA1}\chrome.manifest
      c:\documents and settings\Sandra\Local Settings\Application Data\{C7BD1C5F-319E-495C-8B9B-EB010B705AA1}\chrome\content\_cfg.js
      c:\documents and settings\Sandra\Local Settings\Application Data\{C7BD1C5F-319E-495C-8B9B-EB010B705AA1}\chrome\content\overlay.xul
      c:\documents and settings\Sandra\Local Settings\Application Data\{C7BD1C5F-319E-495C-8B9B-EB010B705AA1}\install.rdf

      .
      ((((((((((((((((((((((((( Files Created from 2010-05-27 to 2010-06-27 )))))))))))))))))))))))))))))))
      .

      2010-06-27 19:58 . 2010-06-27 19:58--------d-----w-c:\program files\Trend Micro
      2010-06-27 03:19 . 2010-06-27 03:19503808----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcp71.dll
      2010-06-27 03:19 . 2010-06-27 03:19499712----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\jmc.dll
      2010-06-27 03:19 . 2010-06-27 03:19348160----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcr71.dll
      2010-06-27 03:19 . 2010-06-27 03:1961440----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-sse.dll
      2010-06-27 03:19 . 2010-06-27 03:1912800----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-d3d.dll
      2010-06-27 03:19 . 2010-06-27 03:18411368----a-w-c:\windows\system32\deployJava1.dll
      2010-06-26 16:48 . 2010-06-26 16:48--------d-----w-c:\documents and settings\Sandra\Application Data\Malwarebytes
      2010-06-26 16:47 . 2010-04-29 20:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
      2010-06-26 16:47 . 2010-06-26 16:47--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
      2010-06-26 16:43 . 2010-06-26 16:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware
      2010-06-26 16:43 . 2010-04-29 20:3920952----a-w-c:\windows\system32\drivers\mbam.sys
      2010-06-25 02:46 . 2010-05-21 19:14221568------w-c:\windows\system32\MpSigStub.exe
      2010-06-25 00:34 . 2010-06-25 00:3463488----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
      2010-06-25 00:34 . 2010-06-25 00:3452224----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
      2010-06-25 00:34 . 2010-06-25 00:34117760----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:33 . 2010-06-25 00:33--------d-----w-c:\program files\SUPERAntiSpyware
      2010-06-25 00:06 . 2010-06-25 00:07--------d-----w-c:\program files\CCleaner
      2010-06-24 23:55 . 2010-06-24 23:56--------d-----w-c:\documents and settings\Sandra\Application Data\PCToolsFirewallPlus
      2010-06-24 01:59 . 2010-06-24 01:59--------d-----w-c:\documents and settings\All Users\Application Data\RegSERVO
      2010-06-24 01:47 . 2009-11-23 18:5488040----a-w-c:\windows\system32\drivers\PCTAppEvent.sys
      2010-06-24 01:47 . 2009-11-09 16:20207792----a-w-c:\windows\system32\drivers\PCTCore.sys
      2010-06-24 01:47 . 2010-01-07 17:40233136----a-w-c:\windows\system32\drivers\pctgntdi.sys
      2010-06-24 01:47 . 2010-06-24 01:47--------d-----w-c:\program files\Common Files\PC Tools
      2010-06-24 01:47 . 2010-01-12 14:3470664----a-w-c:\windows\system32\drivers\pctNdis-PacketFilter.sys
      2010-06-24 01:47 . 2010-01-07 16:3558816----a-w-c:\windows\system32\drivers\pctNdis.sys
      2010-06-24 01:47 . 2010-01-07 16:3532680----a-w-c:\windows\system32\drivers\pctNdis-DNS.sys
      2010-06-24 01:47 . 2010-01-13 13:59115216----a-w-c:\windows\system32\drivers\pctplfw.sys
      2010-06-24 01:47 . 2010-06-24 23:57--------d-----w-c:\program files\PC Tools Firewall Plus
      2010-06-24 01:26 . 2010-06-24 01:26--------d-sh--w-c:\documents and settings\Administrator\IECompatCache
      2010-06-24 01:25 . 2010-06-24 01:25--------d-sh--w-c:\documents and settings\Administrator\PrivacIE
      2010-06-24 01:24 . 2010-06-24 01:2473424----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-06-22 04:55 . 2010-06-22 04:55--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
      2010-06-22 04:51 . 2010-06-22 04:52--------d-----w-c:\program files\Microsoft Security Essentials
      2010-06-22 04:47 . 2010-06-22 04:47--------d-----w-C:\76681267014789b6f130998a7b092a
      2010-06-22 04:46 . 2010-06-22 04:46--------d-----w-C:\6c46460cc4353a7a5f30ff2463
      2010-06-22 04:45 . 2010-06-22 04:45--------d-----w-C:\1e2df3c2d7506665fafd0372e8c7d1
      2010-06-22 04:35 . 2010-06-22 04:35--------d-----w-C:\cf0812036585e0f292cd8391f11a33ca
      2010-06-22 04:15 . 2010-06-22 04:15--------d-----w-C:\0497a1ce892cce9c6dfc0a02e6
      2010-06-22 03:38 . 2010-06-22 03:38--------d-sh--w-c:\documents and settings\Administrator\IETldCache
      2010-06-20 04:35 . 2010-06-22 02:390----a-w-c:\windows\Thizozido.bin
      2010-06-20 04:33 . 2010-06-24 05:36--------d-----w-c:\documents and settings\Bobby\Local Settings\Application Data\kuqoqmppe
      2010-06-18 01:47 . 2010-05-06 10:41743424-c----w-c:\windows\system32\dllcache\iedvtool.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-06-27 19:53 . 2008-12-14 21:12--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
      2010-06-27 03:19 . 2005-11-29 05:23--------d-----w-c:\program files\Common Files\Java
      2010-06-27 02:40 . 2005-11-29 05:23--------d-----w-c:\program files\Java
      2010-06-25 00:26 . 2009-08-28 20:48--------d-----w-c:\documents and settings\All Users\Application Data\ATTToolbar
      2010-06-22 04:49 . 2005-11-29 05:53--------d-----w-c:\program files\Common Files\Symantec Shared
      2010-06-22 04:45 . 2005-11-29 05:53--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
      2010-06-22 03:57 . 2008-12-14 21:07--------d-----w-c:\program files\Norton Security Scan
      2010-06-22 03:32 . 2005-11-29 05:53--------d-----w-c:\program files\Symantec
      2010-05-23 23:17 . 2010-05-23 23:17503808----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcp71.dll
      2010-05-23 23:17 . 2010-05-23 23:17499712----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\jmc.dll
      2010-05-23 23:17 . 2010-05-23 23:17348160----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcr71.dll
      2010-05-06 10:41 . 2004-08-10 12:00916480----a-w-c:\windows\system32\wininet.dll
      2010-05-02 05:22 . 2004-08-10 12:001851264----a-w-c:\windows\system32\win32k.sys
      2010-04-20 05:30 . 2004-08-10 12:00285696----a-w-c:\windows\system32\atmfd.dll
      2010-03-31 05:16 . 2010-03-31 05:1699176----a-w-c:\windows\system32\PresentationHostProxy.dll
      2010-03-31 05:10 . 2010-03-31 05:10295264----a-w-c:\windows\system32\PresentationHost.exe
      2006-07-20 02:28 . 2006-07-20 02:28251----a-w-c:\program files\wt3d.ini
      2007-06-21 23:38 . 2007-06-21 23:3830280----a-w-c:\program files\mozilla firefox\plugins\cgpcfg.dll
      2007-06-21 23:38 . 2007-06-21 23:3879432----a-w-c:\program files\mozilla firefox\plugins\CgpCore.dll
      2007-06-21 23:38 . 2007-06-21 23:3871240----a-w-c:\program files\mozilla firefox\plugins\confmgr.dll
      2007-06-21 23:38 . 2007-06-21 23:38140872----a-w-c:\program files\mozilla firefox\plugins\ctxmui.dll
      2007-06-21 23:39 . 2007-06-21 23:3938472----a-w-c:\program files\mozilla firefox\plugins\icafile.dll
      2007-06-21 23:39 . 2007-06-21 23:3946664----a-w-c:\program files\mozilla firefox\plugins\icalogon.dll
      2007-06-21 23:39 . 2007-06-21 23:3934376----a-w-c:\program files\mozilla firefox\plugins\logging.dll
      2007-06-21 23:39 . 2007-06-21 23:39685640----a-w-c:\program files\mozilla firefox\plugins\sslsdk_b.dll
      2007-06-21 23:40 . 2007-06-21 23:4030280----a-w-c:\program files\mozilla firefox\plugins\TcpPServ.dll
      2003-12-05 03:16 . 2006-03-20 05:3969632--sha-r-c:\windows\lnchshll.exe
      2003-12-05 17:41 . 2006-03-20 05:39368640--sha-r-c:\windows\lpcl.exe
      2003-12-05 03:16 . 2006-03-20 05:3949152--sha-r-c:\windows\ScrnInt.exe
      2004-08-10 12:00 . 2004-08-10 12:0094784--sh--w-c:\windows\twain.dll
      2008-04-14 00:12 . 2004-08-10 12:0050688--sh--w-c:\windows\twain_32.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_16.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_32.dll
      2008-04-14 00:11 . 2004-08-10 12:001028096--sha-w-c:\windows\system32\mfc42.dll
      2008-04-14 00:12 . 2004-08-10 12:0057344--sh--w-c:\windows\system32\msvcirt.dll
      2008-04-14 00:12 . 2004-08-10 12:00413696--sha-w-c:\windows\system32\msvcp60.dll
      2008-04-14 00:12 . 2004-08-10 12:00343040--sha-w-c:\windows\system32\msvcrt.dll
      2008-04-14 00:12 . 2004-08-10 12:00551936--sh--w-c:\windows\system32\oleaut32.dll
      2008-04-14 00:12 . 2004-08-10 12:0084992--sh--w-c:\windows\system32\olepro32.dll
      2008-04-14 00:12 . 2004-08-10 12:0011776--sh--w-c:\windows\system32\regsvr32.exe
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
      "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
      "eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2006-04-18 405504]
      "Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
      "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
      "HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
      "Motive SmartBridge"="c:\progra~1\SBCLIG~1\SMARTB~1\MotiveSB.exe" [2003-12-10 380928]
      "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
      "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
      "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
      "WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
      "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
      "MotiveMonitor"="c:\program files\Motive\AsstCommon\motmon.exe" [2003-10-10 155648]
      "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
      "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
      "CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
      "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-28 344064]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
      "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
      "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
      "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Digital Lifeline.lnk - c:\program files\Digital Lifeline\bin\mpbtn.exe [2006-3-20 172032]
      HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
      NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-3-19 118784]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
      @="Service"

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [6/23/2010 8:47 PM 233136]
      R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
      R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
      R2 lpcl;lpcl;c:\windows\lpcl.exe [3/20/2006 12:39 AM 368640]
      R2 pciinfo;HP Pci Information;\??\c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
      R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [6/23/2010 8:47 PM 88040]
      R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 6:12 PM 102400]
      R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 4:06 AM 231424]
      R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [6/23/2010 8:47 PM 70664]
      R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [6/23/2010 8:47 PM 58816]
      R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [6/23/2010 8:47 PM 115216]
      S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [10/25/2001 9:54 AM 18864]
      S3 Net6IM;Net6;c:\windows\system32\DRIVERS\CAG_im51.sys --> c:\windows\system32\DRIVERS\CAG_im51.sys [?]
      S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [7/6/2007 6:28 PM 31768]
      .
      Contents of the 'Scheduled Tasks' folder

      2010-06-10 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

      2010-06-27 c:\windows\Tasks\MP Scheduled Scan.job
      - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 23:02]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.att.net
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
      mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
      uInternet Settings,ProxyOverride =
      uInternet Settings,ProxyServer = http=127.0.0.1:5555
      uSearchAssistant = hxxp://www.google.com/ie
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      FF - ProfilePath - c:\documents and settings\Sandra\Application Data\Mozilla\Firefox\Profiles\v0znyxy7.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      FF - prefs.js: network.proxy.type - 4
      FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .
      - - - - ORPHANS REMOVED - - - -

      WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
      HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
      HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe



      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-06-27 15:31
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe??6?2?0?5??P? ???B????hLC?

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(800)
      c:\program files\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\system32\WININET.dll
      c:\windows\system32\Ati2evxx.dll
      .
      Completion time: 2010-06-27 15:35:12
      ComboFix-quarantined-files.txt 2010-06-27 20:35

      Pre-Run: 38,059,266,048 bytes free
      Post-Run: 38,712,512,512 bytes free

      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

      - - End Of File - - 931F704807B959E5A5B9C10B2FC04B8A
      Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

      Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

      Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

      Exit out of MessengerDisable then delete the two files that were put on the desktop.

      ===============================

      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

      ======================================

      Open HijackThis and select Do a system scan only

      Place a check MARK next to the following entries: (if there)

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (filesize 1695232 bytes, MD5 3E930C641079443D4DE036167A69CAA2)


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.

      ===============================

      Re-running ComboFix to remove infections:

      • Close any open browsers.
      • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Open notepad and copy/paste the text in the quotebox below into it:
        Quote
        KillAll::

        File::
        c:\windows\Thizozido.bin

        DirLook::
        c:\documents and settings\Bobby\Local Settings\Application Data\kuqoqmppe

        DDS::
        uInternet Settings,ProxyServer = http=127.0.0.1:5555

      • Save this as CFScript.txt, in the same location as ComboFix.exe



      • Referring to the picture above, drag CFScript into ComboFix.exe
      • When finished, it shall produce a log for you at C:\ComboFix.txt
      • Please post the contents of the log in your next reply.

      Results of screen317's Security Check version 0.99.4
      Windows XP Service Pack 3
      Internet Explorer 8
      ``````````````````````````````
      Antivirus/Firewall Check:

      Windows Firewall Disabled!
      PC Tools Firewall Plus 6.0
      Microsoft Security Essentials
      Antivirus up to date! (On Access scanning disabled!)
      ```````````````````````````````
      Anti-malware/Other Utilities Check:

      Malwarebytes' Anti-Malware
      HijackThis 2.0.2
      CCleaner
      Cleaner 5 EZ
      Java(TM) 6 Update 20
      Adobe Flash Player 10.0.32.18
      Adobe Reader 8.1.1
      Adobe Reader 8.1.2
      Adobe Reader 8.1.2 Security Update 1 (KB403742)
      Out of date Adobe Reader installed!
      ````````````````````````````````
      Process Check:
      objlist.exe by Laurent

      Windows Defender MSMpEng.exe
      Microsoft Security Essentials msseces.exe
      PC Tools Firewall Plus FWService.exe
      PC Tools Firewall Plus FirewallGUI.exe
      ````````````````````````````````
      DNS Vulnerability Check:

      GREAT! (Not vulnerable to DNS cache poisoning)

      ``````````End of Log````````````
      ComboFix 10-06-27.03 - Sandra 06/27/2010 22:19:07.2.1 - x86
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.519 [GMT -5:00]
      Running from: c:\documents and settings\Sandra\My Documents\Downloads\commy.exe
      AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
      FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
      .

      ((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
      .

      2010-06-28 02:52 . 2010-06-28 02:53--------d-----w-c:\documents and settings\Bobby\Application Data\PCToolsFirewallPlus
      2010-06-27 19:58 . 2010-06-27 19:58--------d-----w-c:\program files\Trend Micro
      2010-06-27 03:19 . 2010-06-27 03:19503808----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcp71.dll
      2010-06-27 03:19 . 2010-06-27 03:19499712----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\jmc.dll
      2010-06-27 03:19 . 2010-06-27 03:19348160----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcr71.dll
      2010-06-27 03:19 . 2010-06-27 03:1961440----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-sse.dll
      2010-06-27 03:19 . 2010-06-27 03:1912800----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-d3d.dll
      2010-06-27 03:19 . 2010-06-27 03:18411368----a-w-c:\windows\system32\deployJava1.dll
      2010-06-26 16:48 . 2010-06-26 16:48--------d-----w-c:\documents and settings\Sandra\Application Data\Malwarebytes
      2010-06-26 16:47 . 2010-04-29 20:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
      2010-06-26 16:47 . 2010-06-26 16:47--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
      2010-06-26 16:43 . 2010-06-26 16:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware
      2010-06-26 16:43 . 2010-04-29 20:3920952----a-w-c:\windows\system32\drivers\mbam.sys
      2010-06-25 02:46 . 2010-05-21 19:14221568------w-c:\windows\system32\MpSigStub.exe
      2010-06-25 00:34 . 2010-06-25 00:3463488----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
      2010-06-25 00:34 . 2010-06-25 00:3452224----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
      2010-06-25 00:34 . 2010-06-25 00:34117760----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:33 . 2010-06-25 00:33--------d-----w-c:\program files\SUPERAntiSpyware
      2010-06-25 00:06 . 2010-06-25 00:07--------d-----w-c:\program files\CCleaner
      2010-06-24 23:55 . 2010-06-24 23:56--------d-----w-c:\documents and settings\Sandra\Application Data\PCToolsFirewallPlus
      2010-06-24 01:59 . 2010-06-24 01:59--------d-----w-c:\documents and settings\All Users\Application Data\RegSERVO
      2010-06-24 01:47 . 2009-11-23 18:5488040----a-w-c:\windows\system32\drivers\PCTAppEvent.sys
      2010-06-24 01:47 . 2009-11-09 16:20207792----a-w-c:\windows\system32\drivers\PCTCore.sys
      2010-06-24 01:47 . 2010-01-07 17:40233136----a-w-c:\windows\system32\drivers\pctgntdi.sys
      2010-06-24 01:47 . 2010-06-24 01:47--------d-----w-c:\program files\Common Files\PC Tools
      2010-06-24 01:47 . 2010-01-12 14:3470664----a-w-c:\windows\system32\drivers\pctNdis-PacketFilter.sys
      2010-06-24 01:47 . 2010-01-07 16:3558816----a-w-c:\windows\system32\drivers\pctNdis.sys
      2010-06-24 01:47 . 2010-01-07 16:3532680----a-w-c:\windows\system32\drivers\pctNdis-DNS.sys
      2010-06-24 01:47 . 2010-01-13 13:59115216----a-w-c:\windows\system32\drivers\pctplfw.sys
      2010-06-24 01:47 . 2010-06-24 23:57--------d-----w-c:\program files\PC Tools Firewall Plus
      2010-06-24 01:26 . 2010-06-24 01:26--------d-sh--w-c:\documents and settings\Administrator\IECompatCache
      2010-06-24 01:25 . 2010-06-24 01:25--------d-sh--w-c:\documents and settings\Administrator\PrivacIE
      2010-06-24 01:24 . 2010-06-24 01:2473424----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-06-22 04:55 . 2010-06-22 04:55--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
      2010-06-22 04:51 . 2010-06-22 04:52--------d-----w-c:\program files\Microsoft Security Essentials
      2010-06-22 04:47 . 2010-06-22 04:47--------d-----w-C:\76681267014789b6f130998a7b092a
      2010-06-22 04:46 . 2010-06-22 04:46--------d-----w-C:\6c46460cc4353a7a5f30ff2463
      2010-06-22 04:45 . 2010-06-22 04:45--------d-----w-C:\1e2df3c2d7506665fafd0372e8c7d1
      2010-06-22 04:35 . 2010-06-22 04:35--------d-----w-C:\cf0812036585e0f292cd8391f11a33ca
      2010-06-22 04:15 . 2010-06-22 04:15--------d-----w-C:\0497a1ce892cce9c6dfc0a02e6
      2010-06-22 03:38 . 2010-06-22 03:38--------d-sh--w-c:\documents and settings\Administrator\IETldCache
      2010-06-20 04:35 . 2010-06-22 02:390----a-w-c:\windows\Thizozido.bin
      2010-06-20 04:33 . 2010-06-24 05:36--------d-----w-c:\documents and settings\Bobby\Local Settings\Application Data\kuqoqmppe
      2010-06-18 01:47 . 2010-05-06 10:41743424-c----w-c:\windows\system32\dllcache\iedvtool.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-06-28 03:01 . 2008-12-14 21:12--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
      2010-06-27 03:19 . 2005-11-29 05:23--------d-----w-c:\program files\Common Files\Java
      2010-06-27 02:40 . 2005-11-29 05:23--------d-----w-c:\program files\Java
      2010-06-25 00:26 . 2009-08-28 20:48--------d-----w-c:\documents and settings\All Users\Application Data\ATTToolbar
      2010-06-22 04:49 . 2005-11-29 05:53--------d-----w-c:\program files\Common Files\Symantec Shared
      2010-06-22 04:45 . 2005-11-29 05:53--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
      2010-06-22 03:57 . 2008-12-14 21:07--------d-----w-c:\program files\Norton Security Scan
      2010-06-22 03:32 . 2005-11-29 05:53--------d-----w-c:\program files\Symantec
      2010-05-23 23:17 . 2010-05-23 23:17503808----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcp71.dll
      2010-05-23 23:17 . 2010-05-23 23:17499712----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\jmc.dll
      2010-05-23 23:17 . 2010-05-23 23:17348160----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcr71.dll
      2010-05-06 10:41 . 2004-08-10 12:00916480----a-w-c:\windows\system32\wininet.dll
      2010-05-02 05:22 . 2004-08-10 12:001851264----a-w-c:\windows\system32\win32k.sys
      2010-04-20 05:30 . 2004-08-10 12:00285696----a-w-c:\windows\system32\atmfd.dll
      2010-03-31 05:16 . 2010-03-31 05:1699176----a-w-c:\windows\system32\PresentationHostProxy.dll
      2010-03-31 05:10 . 2010-03-31 05:10295264----a-w-c:\windows\system32\PresentationHost.exe
      2006-07-20 02:28 . 2006-07-20 02:28251----a-w-c:\program files\wt3d.ini
      2007-06-21 23:38 . 2007-06-21 23:3830280----a-w-c:\program files\mozilla firefox\plugins\cgpcfg.dll
      2007-06-21 23:38 . 2007-06-21 23:3879432----a-w-c:\program files\mozilla firefox\plugins\CgpCore.dll
      2007-06-21 23:38 . 2007-06-21 23:3871240----a-w-c:\program files\mozilla firefox\plugins\confmgr.dll
      2007-06-21 23:38 . 2007-06-21 23:38140872----a-w-c:\program files\mozilla firefox\plugins\ctxmui.dll
      2007-06-21 23:39 . 2007-06-21 23:3938472----a-w-c:\program files\mozilla firefox\plugins\icafile.dll
      2007-06-21 23:39 . 2007-06-21 23:3946664----a-w-c:\program files\mozilla firefox\plugins\icalogon.dll
      2007-06-21 23:39 . 2007-06-21 23:3934376----a-w-c:\program files\mozilla firefox\plugins\logging.dll
      2007-06-21 23:39 . 2007-06-21 23:39685640----a-w-c:\program files\mozilla firefox\plugins\sslsdk_b.dll
      2007-06-21 23:40 . 2007-06-21 23:4030280----a-w-c:\program files\mozilla firefox\plugins\TcpPServ.dll
      2003-12-05 03:16 . 2006-03-20 05:3969632--sha-r-c:\windows\lnchshll.exe
      2003-12-05 17:41 . 2006-03-20 05:39368640--sha-r-c:\windows\lpcl.exe
      2003-12-05 03:16 . 2006-03-20 05:3949152--sha-r-c:\windows\ScrnInt.exe
      2004-08-10 12:00 . 2004-08-10 12:0094784--sh--w-c:\windows\twain.dll
      2008-04-14 00:12 . 2004-08-10 12:0050688--sh--w-c:\windows\twain_32.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_16.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_32.dll
      2008-04-14 00:11 . 2004-08-10 12:001028096--sha-w-c:\windows\system32\mfc42.dll
      2008-04-14 00:12 . 2004-08-10 12:0057344--sh--w-c:\windows\system32\msvcirt.dll
      2008-04-14 00:12 . 2004-08-10 12:00413696--sha-w-c:\windows\system32\msvcp60.dll
      2008-04-14 00:12 . 2004-08-10 12:00551936--sh--w-c:\windows\system32\oleaut32.dll
      2008-04-14 00:12 . 2004-08-10 12:0011776--sh--w-c:\windows\system32\regsvr32.exe
      .

      ((((((((((((((((((((((((((((( [emailprotected]_20.32.02 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2010-06-28 02:54 . 2010-06-28 02:5416384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
      "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
      "eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2006-04-18 405504]
      "Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
      "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
      "HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
      "Motive SmartBridge"="c:\progra~1\SBCLIG~1\SMARTB~1\MotiveSB.exe" [2003-12-10 380928]
      "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
      "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
      "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
      "WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
      "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
      "MotiveMonitor"="c:\program files\Motive\AsstCommon\motmon.exe" [2003-10-10 155648]
      "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
      "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
      "CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
      "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-28 344064]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
      "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
      "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
      "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Digital Lifeline.lnk - c:\program files\Digital Lifeline\bin\mpbtn.exe [2006-3-20 172032]
      HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
      NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-3-19 118784]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
      @="Service"

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [6/23/2010 8:47 PM 233136]
      R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
      R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
      R2 lpcl;lpcl;c:\windows\lpcl.exe [3/20/2006 12:39 AM 368640]
      R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [6/23/2010 8:47 PM 88040]
      R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 6:12 PM 102400]
      R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 4:06 AM 231424]
      R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [6/23/2010 8:47 PM 70664]
      R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [6/23/2010 8:47 PM 58816]
      R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [6/23/2010 8:47 PM 115216]
      S2 pciinfo;HP Pci Information;\??\c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
      S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [10/25/2001 9:54 AM 18864]
      S3 Net6IM;Net6;c:\windows\system32\DRIVERS\CAG_im51.sys --> c:\windows\system32\DRIVERS\CAG_im51.sys [?]
      S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [7/6/2007 6:28 PM 31768]
      .
      Contents of the 'Scheduled Tasks' folder

      2010-06-10 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

      2010-06-28 c:\windows\Tasks\MP Scheduled Scan.job
      - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 23:02]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.att.net
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
      mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
      uInternet Settings,ProxyOverride =
      uSearchAssistant = hxxp://www.google.com/ie
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      FF - ProfilePath - c:\documents and settings\Sandra\Application Data\Mozilla\Firefox\Profiles\v0znyxy7.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      FF - prefs.js: network.proxy.type - 4
      FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-06-27 22:26
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe??6?2?0?5? ???B????hLC?

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(800)
      c:\program files\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\system32\WININET.dll
      c:\windows\system32\Ati2evxx.dll

      - - - - - - - > 'explorer.exe'(14508)
      c:\windows\system32\WININET.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      .
      Completion time: 2010-06-27 22:29:21
      ComboFix-quarantined-files.txt 2010-06-28 03:29
      ComboFix2.txt 2010-06-27 20:35

      Pre-Run: 38,784,167,936 bytes free
      Post-Run: 38,768,476,160 bytes free

      - - End Of File - - 034D137168A3027DEDD2556C3841487F
      Please download the newest version of Adobe Acrobat Reader from Adobe.com

      Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
      Go to the Control Panel and enter ADD or Remove Programs.
      Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

      Once old versions are gone, please install the newest version.

      =====================================

      Did you run the ComboFix script as instructed in Reply #5. If not, please do so and send me the log.I had to run the ComboFx in Safe Mode it was running a memory physical dump. Here is my log after running the ComboFix with the script.

      ComboFix 10-06-27.06 - Sandra 06/28/2010 22:12:58.5.1 - x86 NETWORK
      Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.756 [GMT -5:00]
      Running from: c:\documents and settings\Sandra\My Documents\Downloads\commy.exe
      Command switches used :: c:\documents and settings\Sandra\My Documents\Downloads\CFScript.txt
      AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
      FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

      FILE ::
      "c:\windows\Thizozido.bin"
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\windows\Thizozido.bin

      .
      ((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
      .

      2010-06-29 02:48 . 2010-06-29 02:48--------d-----w-c:\documents and settings\Default User\Local Settings\Application Data\Adobe
      2010-06-29 02:28 . 2010-06-29 02:2853632----a-w-c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
      2010-06-29 02:28 . 2010-06-29 02:28--------d-----w-c:\program files\Common Files\Adobe AIR
      2010-06-29 02:21 . 2010-06-29 03:11--------d-----w-c:\documents and settings\All Users\Application Data\NOS
      2010-06-29 00:35 . 2010-06-29 00:35--------d-----w-c:\documents and settings\Sandra\Local Settings\Application Data\PCHealth
      2010-06-28 02:52 . 2010-06-28 02:53--------d-----w-c:\documents and settings\Bobby\Application Data\PCToolsFirewallPlus
      2010-06-27 19:58 . 2010-06-27 19:58--------d-----w-c:\program files\Trend Micro
      2010-06-27 03:19 . 2010-06-27 03:19503808----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcp71.dll
      2010-06-27 03:19 . 2010-06-27 03:19499712----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\jmc.dll
      2010-06-27 03:19 . 2010-06-27 03:19348160----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-20f215ac-n\msvcr71.dll
      2010-06-27 03:19 . 2010-06-27 03:1961440----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-sse.dll
      2010-06-27 03:19 . 2010-06-27 03:1912800----a-w-c:\documents and settings\Sandra\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-186516e0-n\decora-d3d.dll
      2010-06-27 03:19 . 2010-06-27 03:18411368----a-w-c:\windows\system32\deployJava1.dll
      2010-06-26 16:48 . 2010-06-26 16:48--------d-----w-c:\documents and settings\Sandra\Application Data\Malwarebytes
      2010-06-26 16:47 . 2010-04-29 20:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
      2010-06-26 16:47 . 2010-06-26 16:47--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
      2010-06-26 16:43 . 2010-06-26 16:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware
      2010-06-26 16:43 . 2010-04-29 20:3920952----a-w-c:\windows\system32\drivers\mbam.sys
      2010-06-25 02:46 . 2010-05-21 19:14221568------w-c:\windows\system32\MpSigStub.exe
      2010-06-25 00:34 . 2010-06-25 00:3463488----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
      2010-06-25 00:34 . 2010-06-25 00:3452224----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
      2010-06-25 00:34 . 2010-06-25 00:34117760----a-w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\Sandra\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:34 . 2010-06-25 00:34--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
      2010-06-25 00:33 . 2010-06-25 00:33--------d-----w-c:\program files\SUPERAntiSpyware
      2010-06-25 00:06 . 2010-06-25 00:07--------d-----w-c:\program files\CCleaner
      2010-06-24 23:55 . 2010-06-24 23:56--------d-----w-c:\documents and settings\Sandra\Application Data\PCToolsFirewallPlus
      2010-06-24 01:59 . 2010-06-24 01:59--------d-----w-c:\documents and settings\All Users\Application Data\RegSERVO
      2010-06-24 01:47 . 2009-11-23 18:5488040----a-w-c:\windows\system32\drivers\PCTAppEvent.sys
      2010-06-24 01:47 . 2009-11-09 16:20207792----a-w-c:\windows\system32\drivers\PCTCore.sys
      2010-06-24 01:47 . 2010-01-07 17:40233136----a-w-c:\windows\system32\drivers\pctgntdi.sys
      2010-06-24 01:47 . 2010-06-24 01:47--------d-----w-c:\program files\Common Files\PC Tools
      2010-06-24 01:47 . 2010-01-12 14:3470664----a-w-c:\windows\system32\drivers\pctNdis-PacketFilter.sys
      2010-06-24 01:47 . 2010-01-07 16:3558816----a-w-c:\windows\system32\drivers\pctNdis.sys
      2010-06-24 01:47 . 2010-01-07 16:3532680----a-w-c:\windows\system32\drivers\pctNdis-DNS.sys
      2010-06-24 01:47 . 2010-01-13 13:59115216----a-w-c:\windows\system32\drivers\pctplfw.sys
      2010-06-24 01:47 . 2010-06-24 23:57--------d-----w-c:\program files\PC Tools Firewall Plus
      2010-06-24 01:26 . 2010-06-24 01:26--------d-sh--w-c:\documents and settings\Administrator\IECompatCache
      2010-06-24 01:25 . 2010-06-24 01:25--------d-sh--w-c:\documents and settings\Administrator\PrivacIE
      2010-06-24 01:24 . 2010-06-24 01:2473424----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-06-22 04:55 . 2010-06-22 04:55--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
      2010-06-22 04:51 . 2010-06-22 04:52--------d-----w-c:\program files\Microsoft Security Essentials
      2010-06-22 04:47 . 2010-06-22 04:47--------d-----w-C:\76681267014789b6f130998a7b092a
      2010-06-22 04:46 . 2010-06-22 04:46--------d-----w-C:\6c46460cc4353a7a5f30ff2463
      2010-06-22 04:45 . 2010-06-22 04:45--------d-----w-C:\1e2df3c2d7506665fafd0372e8c7d1
      2010-06-22 04:35 . 2010-06-22 04:35--------d-----w-C:\cf0812036585e0f292cd8391f11a33ca
      2010-06-22 04:15 . 2010-06-22 04:15--------d-----w-C:\0497a1ce892cce9c6dfc0a02e6
      2010-06-22 03:38 . 2010-06-22 03:38--------d-sh--w-c:\documents and settings\Administrator\IETldCache
      2010-06-20 04:33 . 2010-06-24 05:36--------d-----w-c:\documents and settings\Bobby\Local Settings\Application Data\kuqoqmppe
      2010-06-18 01:47 . 2010-05-06 10:41743424-c----w-c:\windows\system32\dllcache\iedvtool.dll

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-06-29 03:22 . 2008-12-14 21:12--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
      2010-06-29 02:47 . 2006-03-09 03:55--------d-----w-c:\program files\Common Files\Adobe
      2010-06-28 04:48 . 2009-08-28 20:48--------d-----w-c:\documents and settings\All Users\Application Data\ATTToolbar
      2010-06-27 03:19 . 2005-11-29 05:23--------d-----w-c:\program files\Common Files\Java
      2010-06-27 02:40 . 2005-11-29 05:23--------d-----w-c:\program files\Java
      2010-06-22 04:49 . 2005-11-29 05:53--------d-----w-c:\program files\Common Files\Symantec Shared
      2010-06-22 04:45 . 2005-11-29 05:53--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
      2010-06-22 03:57 . 2008-12-14 21:07--------d-----w-c:\program files\Norton Security Scan
      2010-06-22 03:32 . 2005-11-29 05:53--------d-----w-c:\program files\Symantec
      2010-05-23 23:17 . 2010-05-23 23:17503808----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcp71.dll
      2010-05-23 23:17 . 2010-05-23 23:17499712----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\jmc.dll
      2010-05-23 23:17 . 2010-05-23 23:17348160----a-w-c:\documents and settings\Bobby\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-18e85dce-n\msvcr71.dll
      2010-05-06 10:41 . 2004-08-10 12:00916480----a-w-c:\windows\system32\wininet.dll
      2010-05-02 05:22 . 2004-08-10 12:001851264----a-w-c:\windows\system32\win32k.sys
      2010-04-20 05:30 . 2004-08-10 12:00285696----a-w-c:\windows\system32\atmfd.dll
      2010-03-31 05:16 . 2010-03-31 05:1699176----a-w-c:\windows\system32\PresentationHostProxy.dll
      2010-03-31 05:10 . 2010-03-31 05:10295264----a-w-c:\windows\system32\PresentationHost.exe
      2006-07-20 02:28 . 2006-07-20 02:28251----a-w-c:\program files\wt3d.ini
      2007-06-21 23:38 . 2007-06-21 23:3830280----a-w-c:\program files\mozilla firefox\plugins\cgpcfg.dll
      2007-06-21 23:38 . 2007-06-21 23:3879432----a-w-c:\program files\mozilla firefox\plugins\CgpCore.dll
      2007-06-21 23:38 . 2007-06-21 23:3871240----a-w-c:\program files\mozilla firefox\plugins\confmgr.dll
      2007-06-21 23:38 . 2007-06-21 23:38140872----a-w-c:\program files\mozilla firefox\plugins\ctxmui.dll
      2007-06-21 23:39 . 2007-06-21 23:3938472----a-w-c:\program files\mozilla firefox\plugins\icafile.dll
      2007-06-21 23:39 . 2007-06-21 23:3946664----a-w-c:\program files\mozilla firefox\plugins\icalogon.dll
      2007-06-21 23:39 . 2007-06-21 23:3934376----a-w-c:\program files\mozilla firefox\plugins\logging.dll
      2007-06-21 23:39 . 2007-06-21 23:39685640----a-w-c:\program files\mozilla firefox\plugins\sslsdk_b.dll
      2007-06-21 23:40 . 2007-06-21 23:4030280----a-w-c:\program files\mozilla firefox\plugins\TcpPServ.dll
      2003-12-05 03:16 . 2006-03-20 05:3969632--sha-r-c:\windows\lnchshll.exe
      2003-12-05 17:41 . 2006-03-20 05:39368640--sha-r-c:\windows\lpcl.exe
      2003-12-05 03:16 . 2006-03-20 05:3949152--sha-r-c:\windows\ScrnInt.exe
      2004-08-10 12:00 . 2004-08-10 12:0094784--sh--w-c:\windows\twain.dll
      2008-04-14 00:12 . 2004-08-10 12:0050688--sh--w-c:\windows\twain_32.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_16.dll
      2004-08-20 05:26 . 2004-08-20 05:261216--sh--w-c:\windows\Twunk_32.dll
      2008-04-14 00:11 . 2004-08-10 12:001028096--sha-w-c:\windows\system32\mfc42.dll
      2008-04-14 00:12 . 2004-08-10 12:0057344--sh--w-c:\windows\system32\msvcirt.dll
      2008-04-14 00:12 . 2004-08-10 12:00413696--sha-w-c:\windows\system32\msvcp60.dll
      2008-04-14 00:12 . 2004-08-10 12:00551936--sh--w-c:\windows\system32\oleaut32.dll
      2008-04-14 00:12 . 2004-08-10 12:0011776--sh--w-c:\windows\system32\regsvr32.exe
      .

      (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      ---- Directory of c:\documents and settings\Bobby\Local Settings\Application Data\kuqoqmppe ----



      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
      "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
      "eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2006-04-18 405504]
      "Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
      "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
      "HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
      "Motive SmartBridge"="c:\progra~1\SBCLIG~1\SMARTB~1\MotiveSB.exe" [2003-12-10 380928]
      "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
      "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
      "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
      "WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
      "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
      "MotiveMonitor"="c:\program files\Motive\AsstCommon\motmon.exe" [2003-10-10 155648]
      "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
      "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
      "CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
      "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-28 344064]
      "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
      "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
      "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-12 3168216]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Digital Lifeline.lnk - c:\program files\Digital Lifeline\bin\mpbtn.exe [2006-3-20 172032]
      HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
      NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-3-19 118784]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
      @="Service"

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [6/23/2010 8:47 PM 233136]
      R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
      R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
      R2 lpcl;lpcl;c:\windows\lpcl.exe [3/20/2006 12:39 AM 368640]
      R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [6/23/2010 8:47 PM 88040]
      R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 6:12 PM 102400]
      R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 4:06 AM 231424]
      R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [6/23/2010 8:47 PM 70664]
      R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [6/23/2010 8:47 PM 58816]
      R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [6/23/2010 8:47 PM 115216]
      S2 pciinfo;HP Pci Information;\??\c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Sandra\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
      S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [10/25/2001 9:54 AM 18864]
      S3 Net6IM;Net6;c:\windows\system32\DRIVERS\CAG_im51.sys --> c:\windows\system32\DRIVERS\CAG_im51.sys [?]
      S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [7/6/2007 6:28 PM 31768]
      .
      Contents of the 'Scheduled Tasks' folder

      2010-06-10 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

      2010-06-29 c:\windows\Tasks\MP Scheduled Scan.job
      - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 23:02]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.att.net
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
      mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
      uInternet Settings,ProxyOverride =
      uSearchAssistant = hxxp://www.google.com/ie
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      FF - ProfilePath - c:\documents and settings\Sandra\Application Data\Mozilla\Firefox\Profiles\v0znyxy7.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
      FF - prefs.js: network.proxy.type - 4
      FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 10);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-06-28 22:22
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe???n??|??? ???B????hLC?

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(1124)
      c:\program files\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\system32\WININET.dll
      c:\windows\system32\Ati2evxx.dll

      - - - - - - - > 'explorer.exe'(4264)
      c:\windows\system32\WININET.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\windows\system32\Ati2evxx.exe
      c:\program files\Microsoft Security Essentials\MsMpEng.exe
      c:\windows\system32\Ati2evxx.exe
      c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\windows\eHome\ehRecvr.exe
      c:\windows\eHome\ehSched.exe
      c:\program files\Java\jre6\bin\jqs.exe
      c:\program files\Common Files\LightScribe\LSSrvc.exe
      c:\program files\Common Files\Motive\McciCMService.exe
      c:\program files\PC Tools Firewall Plus\FWService.exe
      c:\windows\system32\HPZipm12.exe
      c:\windows\ehome\mcrdsvc.exe
      c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
      c:\progra~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
      c:\windows\system32\dllhost.exe
      c:\windows\system32\wscntfy.exe
      c:\program files\iPod\bin\iPodService.exe
      c:\windows\eHome\ehmsas.exe
      c:\program files\HPQ\SHARED\HPQWMI.exe
      .
      **************************************************************************
      .
      Completion time: 2010-06-28 22:29:42 - machine was rebooted
      ComboFix-quarantined-files.txt 2010-06-29 03:29
      ComboFix2.txt 2010-06-28 03:29
      ComboFix3.txt 2010-06-27 20:35

      Pre-Run: 37,172,535,296 bytes free
      Post-Run: 37,158,219,776 bytes free

      - - End Of File - - FE582E01464266889D9389BD4DA18118
      What issues were you having with your computer? Are they still occuring?I believe that it is working ok. I need to check the applications and other user accounts to make sure. Thank you soo much for your help in resolving these issues. Please run one more scan for me and if it comes up negative, we'll so some clean-up.

      I'd like us to scan your machine with ESET OnlineScan

      •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

      I ran the ESET Online scanner with both the Remove Found Threats and Scan Archives checked and no threats were found.

      Looks like its working well. Thanks again for all your help.Ok. That sound good. Let's do some clean-up

      * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
      * Now type commy /uninstall in the runbox
      * Make sure there's a space between commy and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.

      ============================

      Download OTC by OldTimer and save it to your desktop.

      1. Double-click OTC to run it.
      2. Click the CleanUp! button.
      3. Select Yes when the "Begin cleanup Process?" prompt appears.
      4. If you are prompted to Reboot during the cleanup, select Yes
      5. OTC should delete itself once it finishes, if not delete it yourself.

      =============================

      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

      =================================

      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!

      3135.

      Solve : In need of DESPERATE help...almost giving up, please!!!! Help!!?

      Answer» Something has happened to my internet, it just wont work..I have tried everything from system restoring to 4 months ago, doing countless virus scans and it just wont work.
      It happened about 3 weeks ago when I did a virus scan with avast and I had about 15 viruses, I got rid of them but then my internet didn't work. I did a diagnostic and this is what it said:

      WinSock Diagnostic
      WinSock status

      info Error attmpting to validate the Winsock base providers: 2
      error Not all base service provider entries could be found in the winsock catalog. A reset is needed.
      info Redirecting user to support call



      Network Adapter Diagnostic
      Network location detection

      info Using home Internet connection
      Network adapter identification

      info Network connection: Name=Local Area Connection, Device=Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC, MediaType=LAN, SubMediaType=LAN
      info Network connection: Name=1394 Connection 2, Device=1394 Net Adapter, MediaType=LAN, SubMediaType=1394
      info Ethernet connection selected
      Network adapter status

      info Network connection status: Connected



      HTTP, HTTPS, FTP Diagnostic
      HTTP, HTTPS, FTP connectivity

      warn FTP (Passive): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved
      warn HTTP: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved
      warn HTTPS: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved
      warn FTP (Active): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved
      warn HTTPS: Error 12007 connecting to www.passport.net: The server name or address could not be resolved
      warn HTTP: Error 12007 connecting to www.hotmail.com: The server name or address could not be resolved
      error Could not make an HTTP connection.
      error Could not make an HTTPS connection.
      error Could not make an FTP connection


      It says im connected but it wont load, I have tried winsockfix and everything but it wont work..I even tried google chrome but that didn't work too...please help me I beg u!

      Please download RenewMyDNS by DragonMaster Jay.
      • Save it to your Desktop.
      • Right-click on the file and select Extract All...
      • Choose a location to save extracted files and keep pressing Next until Finish.
      • Double-click RenewMyDNS folder, then double-click RenewMyDNS.bat to start the program.
      • Follow the prompts, and when finished it will launch a log.
      • Post that log in your next reply.
      • After posting the log, delete the folder RenewMyDNS.
      Thanks for the reply, here is the log:

      RenewMyDNS by DragonMaster Jay
      DNS Diagnostics and refresher
      Version 0.1.4 - November 2009

      Microsoft Windows XP [Version 5.1.2600]


      (((((((((((((((((((( Network and DNS Information ))))))))))))))))))))




      Windows IP Configuration



      An internal error occurred: The request is not supported.



      Please contact Microsoft Product Support Services for further help.



      Additional information: Unable to query host name.


      (((((((((((((((((((( DNS-Fake Request Testing and Flush ))))))))))))))))))))

      ... Requests made were successful


      Windows IP Configuration



      An internal error occurred: The request is not supported.



      Please contact Microsoft Product Support Services for further help.



      Additional information: Unable to query host name.



      (((((((((((((((((((( Speed-test - Ping ))))))))))))))))))))
      Ping request could not find host yahoo.com. Please check the name and try again.

      Ping request could not find host geekpolice.net. Please check the name and try again.

      Ping request could not find host facebook.com. Please check the name and try again.

      Ping request could not find host microsoft.com. Please check the name and try again.


      ********************
      EOF

      Thanks again.Please visit this webpage for a tutorial on downloading and running ComboFix:

      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      See the area: Using ComboFix, and when done, post the log back here.Thanks 4 reply:

      ComboFix 10-06-14.01 - Tom_2 06/15/2010 21:00:13.1.2 - x86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2012.1391 [GMT 1:00]
      Running from: E:\ComboFix.exe
      AV: avast! Antivirus *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
      AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
      * Created a new restore point
      * Resident AV is active


      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .

      ((((((((((((((((((((((((((((((((((((((( Other DELETIONS )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Autorun.inf
      c:\documents and settings\Tom_2\Application Data\logs.dat
      c:\documents and settings\Tom_2\Application Data\SQLite3.dll
      c:\documents and settings\Tom_2\Local Settings\Temporary Internet Files\3Ho2Cejp.jpg
      c:\documents and settings\Tom_2\Local Settings\Temporary Internet Files\l4P2Ikk5.jpg
      c:\documents and settings\Tom_2\Local Settings\Temporary Internet Files\P3v3Y0e.jpg
      c:\documents and settings\Tom_2\Local Settings\Temporary Internet Files\Yt1n17En.jpg
      c:\program files\Cheat Engine\dbk32.sys
      c:\program files\Internet Explorer\IEXPLORER.EXE
      c:\windows\system32\Winlogon

      .
      ((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))
      .

      2010-06-11 18:47 . 2010-06-12 12:12--------d-----w-c:\documents and settings\Tom_2\Local Settings\Application Data\Google
      2010-06-11 18:42 . 2010-06-11 18:42--------d-----w-c:\windows\system32\Registry Patrol
      2010-06-11 18:35 . 2010-06-11 18:42--------d-----w-C:\ERDNT
      2010-06-06 17:09 . 2010-06-11 18:42--------d-----w-c:\program files\Registry Patrol
      2010-05-27 17:23 . 2010-04-14 16:3119024----a-w-c:\windows\system32\drivers\aswFsBlk.sys
      2010-05-27 17:23 . 2010-04-14 16:35162768----a-w-c:\windows\system32\drivers\aswSP.sys
      2010-05-27 17:23 . 2010-04-14 16:3123376----a-w-c:\windows\system32\drivers\aswRdr.sys
      2010-05-27 17:23 . 2010-04-14 16:3546672----a-w-c:\windows\system32\drivers\aswTdi.sys
      2010-05-27 17:23 . 2010-04-14 16:31100432----a-w-c:\windows\system32\drivers\aswmon2.sys
      2010-05-27 17:23 . 2010-04-14 16:3194800----a-w-c:\windows\system32\drivers\aswmon.sys
      2010-05-27 17:23 . 2010-04-14 16:3028880----a-w-c:\windows\system32\drivers\aavmker4.sys
      2010-05-27 17:21 . 2010-04-14 16:4738848----a-w-c:\windows\system32\avastSS.scr
      2010-05-27 17:21 . 2010-04-14 16:47153184----a-w-c:\windows\system32\aswBoot.exe
      2010-05-27 14:56 . 2010-05-27 14:56--------d-sh--w-c:\documents and settings\LocalService\IETldCache
      2010-05-27 06:34 . 2010-05-27 06:34--------d-sh--w-c:\documents and settings\Administrator.TOM-2C5350163A3.000\PrivacIE
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\DF
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.yanillescapeclientv3_file_store_32
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.sabsabionline474
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.sabsabi_store_32
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.pc_store_32
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.fub_file_store_32
      2010-05-25 18:21 . 2010-05-25 18:21--------d-----w-C:\.file_store_32
      2010-05-25 16:42 . 2010-05-25 18:21--------d-s---w-c:\documents and settings\Administrator.TOM-2C5350163A3
      2010-05-25 06:46 . 2010-05-25 17:55--------d-----w-c:\documents and settings\Administrator\Application Data\Orbit
      2010-05-25 06:45 . 2010-05-25 06:45--------d-----w-c:\documents and settings\Administrator\PrivacIE
      2010-05-25 06:44 . 2010-05-25 06:4414264----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-05-25 06:41 . 2010-05-25 06:41--------d-----w-c:\documents and settings\Administrator\IETldCache
      2010-05-25 06:40 . 2010-05-25 18:21--------d-----w-c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
      2010-05-25 06:40 . 2010-05-25 18:21--------d-s---w-c:\documents and settings\Administrator
      2010-05-23 19:31 . 2010-05-25 17:57--------d-----w-C:\cache525
      2010-05-23 16:12 . 2010-05-25 18:21--------d-----w-c:\documents and settings\All Users\Application Data\DivX

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-06-15 20:04 . 2010-01-25 19:46--------d-----w-c:\program files\Cheat Engine
      2010-06-13 13:24 . 2010-01-08 20:341324----a-w-c:\windows\system32\d3d9caps.dat
      2010-06-11 18:42 . 2010-04-19 17:14--------d-----w-c:\documents and settings\All Users\Application Data\Alwil Software
      2010-05-26 21:36 . 2009-11-29 20:34--------d-----w-c:\documents and settings\Tom_2\Application Data\Orbit
      2010-05-26 21:19 . 2009-12-09 19:2742----a-w-c:\documents and settings\Tom_2\jagex_runescape_preferences.dat
      2010-05-26 21:11 . 2009-12-09 19:2881----a-w-c:\documents and settings\Tom_2\jagex_runescape_preferences2.dat
      2010-05-03 12:43 . 2009-11-29 20:34--------d-----w-c:\program files\Orbitdownloader
      2010-05-03 00:27 . 2010-05-03 00:27--------d-----w-c:\program files\Simple Shutdown Timer
      2010-04-30 07:13 . 2010-04-30 07:13--------d-----w-c:\program files\Shutdown Timer
      2010-04-27 18:32 . 2010-03-21 14:01--------d-----w-c:\documents and settings\Tom_2\Application Data\godzHell
      2010-04-27 18:32 . 2010-04-27 18:3217----a-w-c:\documents and settings\Tom_2\Application Data\godzHell\jag2png.bat
      2010-04-26 14:57 . 2005-11-06 00:49--------d-sh--r-c:\documents and settings\Tom_2\Application Data\systemm
      2010-04-20 06:30 . 2010-01-15 18:26--------d-----w-c:\program files\Alwil Software
      2010-04-02 10:46 . 2010-04-02 10:46503808----a-w-c:\documents and settings\Tom_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46949b87-n\msvcp71.dll
      2010-04-02 10:46 . 2010-04-02 10:46499712----a-w-c:\documents and settings\Tom_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46949b87-n\jmc.dll
      2010-04-02 10:46 . 2010-04-02 10:46348160----a-w-c:\documents and settings\Tom_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46949b87-n\msvcr71.dll
      2010-04-02 10:46 . 2010-04-02 10:4661440----a-w-c:\documents and settings\Tom_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-37a14481-n\decora-sse.dll
      2010-04-02 10:46 . 2010-04-02 10:4612800----a-w-c:\documents and settings\Tom_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-37a14481-n\decora-d3d.dll
      2010-03-24 17:15 . 2010-03-24 17:150----a-w-c:\documents and settings\Tom_2\jagex__preferences3.dat
      2010-03-21 15:56 . 2010-03-21 15:5617----a-w-c:\documents and settings\Tom_2\Application Data\pkClient\jag2png.bat
      2005-07-12 16:37 . 2010-01-09 16:46293376--sha-r-c:\windows\system32\winsnc\plugin.dat
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
      "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
      "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-17 81920]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-01-02 417792]
      "RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner.exe" [2009-08-22 2781184]
      "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
      "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
      "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
      "c:\\Program Files\\Steam\\steamapps\\sirtom125\\garrysmod\\hl2.exe"=
      "c:\\Program Files\\ijji\\ijji REACTOR\\REACTOR.exe"=
      "c:\\WINDOWS\\Downloaded Program Files\\ijjiOptimizer.exe"=
      "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

      R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5/27/2010 6:23 PM 162768]
      R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/27/2010 6:23 PM 19024]
      S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
      S3 rak;rak;c:\windows\system32\rakion.sys [1/4/2010 6:37 PM 60928]
      S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys --> c:\windows\system32\DRIVERS\wg111v2.sys [?]
      S3 XDva289;XDva289;\??\c:\windows\system32\XDva289.sys --> c:\windows\system32\XDva289.sys [?]
      .
      .
      ------- Supplementary Scan -------
      .
      uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/
      .
      - - - - ORPHANS REMOVED - - - -

      Toolbar-Locked - (no file)
      HKCU-Run-winsnc - c:\windows\system32\winsnc\winsnc.bat
      HKLM-Run-nwiz - nwiz.exe
      HKLM-Explorer_Run-update - c:\windows\systemm\update.exe
      ActiveSetup-{0L4KN5M7-637R-M2Y3-RPX7-15WEYS2DU8AL} - c:\windows\systemm\update.exe
      AddRemove-BoxRune 525 Client V2 - c:\documents and settings\Tom_2\Desktop\BoxRune Client V2\Uninstal.exe
      AddRemove-BoxRune 562 - c:\documents and settings\Tom_2\Desktop\BoxRune 562 Client\Uninstal.exe
      AddRemove-UnityWebPlayer - c:\documents and settings\Tom_2\Local Settings\Application Data\Unity\WebPlayer\UNINSTALL.exe



      **************************************************************************
      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files:

      **************************************************************************

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
      "ImagePath"="c:\windows\system32\GameMon.des -service"
      .
      Completion time: 2010-06-15 21:05:58
      ComboFix-quarantined-files.txt 2010-06-15 20:05

      Pre-Run: 58,685,923,328 bytes free
      Post-Run: 58,717,700,096 bytes free

      - - END Of File - - F8BC8389153462DDE52E7094D82FCA1C
      GMER

      Note about this tool:
      • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
      • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
      • No matter what is in the log, please post all the information/contents of the log.
      Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

      Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

      Double-click gmer.exe. The program will begin to run.

      **Caution**
      These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless ADVISED!

      If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
      • Click NO
      • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
      • Now click the Scan button.
      Once the scan is complete, you may receive another notice about rootkit activity.
      • Click OK.
      • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
      • Save it where you can easily find it, such as your desktop.
      Post the contents of GMER.txt in your next reply.Thanks -

      GMER 1.0.15.15281 - http://www.gmer.net
      Rootkit quick scan 2010-06-19 20:02:36
      Windows 5.1.2600 Service Pack 3
      Running: gmer.exe; Driver: C:\DOCUME~1\Tom_2\LOCALS~1\Temp\kgnorfod.sys


      ---- System - GMER 1.0.15 ----

      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB74C550A]
      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB74C532E]
      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB74C5468]
      Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB6135347]
      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
      Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

      ---- Devices - GMER 1.0.15 ----

      Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

      AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
      AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
      AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
      AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
      AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

      ---- EOF - GMER 1.0.15 ----
      Please download MySystem-Search from here: Download mirror 2
      • Save the file to your Desktop.
      • Double-click on mss.exe
      • Allow it to run, and follow the prompts.
      • Once done, it will launch a log.
      • Post it in your next reply. Also, find a log in the same location called HOSTS.txt. Open it and copy and paste that information in your next reply.
      Note: the logs are long. Please use more than one post, if necessary.MySystem-Search

      Run on 06/20/2010 at 13:08:45

      MSS v1.4


      Basic System Information



      CD Emulation Drivers running?



      Peer-to-Peer applications?



      File associations

      .exe=exefile
      .scr=scrfile
      .pif=piffile
      .com=ComFile
      .bat=batfile
      .cmd=cmdfile
      .log=txtfile
      .txt=txtfile
      .reg=regfile
      .sys=sysfile
      .dll=dllfile


      Running processes



      Hidden objects

      PATH: C:\windows

      $hf_mig$
      $MSI31Uninstall_KB893803v2$
      $NtServicePackUninstall$
      $NtUninstallKB888111WXPSP2$
      $NtUninstallKB898461$
      $NtUninstallKB923561$
      $NtUninstallKB929399$
      $NtUninstallKB939683$
      $NtUninstallKB941569$
      $NtUninstallKB946648$
      $NtUninstallKB950762$
      $NtUninstallKB950974$
      $NtUninstallKB951066$
      $NtUninstallKB951376-v2$
      $NtUninstallKB951748$
      $NtUninstallKB951978$
      $NtUninstallKB952004$
      $NtUninstallKB952069_WM9$
      $NtUninstallKB952287$
      $NtUninstallKB952954$
      $NtUninstallKB954154_WM11$
      $NtUninstallKB954155_WM9$
      $NtUninstallKB955069$
      $NtUninstallKB955759$
      $NtUninstallKB956572$
      $NtUninstallKB956744$
      $NtUninstallKB956802$
      $NtUninstallKB956803$
      $NtUninstallKB956844$
      $NtUninstallKB957097$
      $NtUninstallKB958644$
      $NtUninstallKB958687$
      $NtUninstallKB958869$
      $NtUninstallKB959426$
      $NtUninstallKB960225$
      $NtUninstallKB960803$
      $NtUninstallKB960859$
      $NtUninstallKB961118$
      $NtUninstallKB961371-v2$
      $NtUninstallKB961501$
      $NtUninstallKB967715$
      $NtUninstallKB968389$
      $NtUninstallKB968816_WM9$
      $NtUninstallKB969059$
      $NtUninstallKB969947$
      $NtUninstallKB970238$
      $NtUninstallKB970430$
      $NtUninstallKB971468$
      $NtUninstallKB971486$
      $NtUninstallKB971557$
      $NtUninstallKB971633$
      $NtUninstallKB971657$
      $NtUninstallKB971737$
      $NtUninstallKB972270$
      $NtUninstallKB973354$
      $NtUninstallKB973507$
      $NtUninstallKB973525$
      $NtUninstallKB973540_WM9$
      $NtUninstallKB973687$
      $NtUninstallKB973815$
      $NtUninstallKB973869$
      $NtUninstallKB973904$
      $NtUninstallKB974112$
      $NtUninstallKB974318$
      $NtUninstallKB974392$
      $NtUninstallKB974455$
      $NtUninstallKB974571$
      $NtUninstallKB975025$
      $NtUninstallKB975467$
      $NtUninstallKB975560$
      $NtUninstallKB975561$
      $NtUninstallKB975713$
      $NtUninstallKB976098-v2$
      $NtUninstallKB977165$
      $NtUninstallKB977816$
      $NtUninstallKB977914$
      $NtUninstallKB978037$
      $NtUninstallKB978251$
      $NtUninstallKB978262$
      $NtUninstallKB978338$
      $NtUninstallKB978542$
      $NtUninstallKB978601$
      $NtUninstallKB978706$
      $NtUninstallKB979306$
      $NtUninstallKB979309$
      $NtUninstallKB979683$
      $NtUninstallKB980232$
      $NtUninstallMSCompPackV1$
      $NtUninstallWMFDist11$
      $NtUninstallwmp11$
      $NtUninstallWudf01000$
      ie8
      inf
      Installer
      msdownld.tmp
      sys32
      systemm
      WindowsShell.Manifest
      winnt.bmp
      winnt256.bmp


      PATH: C:\windows\system32

      cdplayer.exe.manifest
      dllcache
      logonui.exe.manifest
      Microsoft_MH2KU1
      ncpa.cpl.manifest
      nwc.cpl.manifest
      sapi.cpl.manifest
      WindowsLogon.manifest
      winsnc
      wuaucpl.cpl.manifest


      PATH: C:\windows\system32\drivers



      PATH: C:\

      boot.ini
      IO.SYS
      MSDOS.SYS
      NTDETECT.COM
      ntldr
      pagefile.sys
      System Volume Information


      User Profile check



      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
      ProfilesDirectoryREG_EXPAND_SZ%SystemDrive%\Documents and Settings
      DefaultUserProfileREG_SZDefault User
      AllUsersProfileREG_SZAll Users

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
      FlagsREG_DWORD0xc
      StateREG_DWORD0x0
      RefCountREG_DWORD0x1
      SidREG_BINARY010100000000000512000000
      ProfileImagePathREG_EXPAND_SZ%systemroot%\system32\config\systemprofile

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
      ProfileImagePathREG_EXPAND_SZ%SystemDrive%\Documents and Settings\LocalService
      SidREG_BINARY010100000000000513000000
      FlagsREG_DWORD0x9
      StateREG_DWORD0x100
      CentralProfileREG_SZ
      ProfileLoadTimeLowREG_DWORD0xb7a20b70
      ProfileLoadTimeHighREG_DWORD0x1cb1066
      RefCountREG_DWORD0x2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
      ProfileImagePathREG_EXPAND_SZ%SystemDrive%\Documents and Settings\NetworkService
      SidREG_BINARY010100000000000514000000
      FlagsREG_DWORD0x9
      StateREG_DWORD0x100
      CentralProfileREG_SZ
      ProfileLoadTimeLowREG_DWORD0xb77e482a
      ProfileLoadTimeHighREG_DWORD0x1cb1066
      RefCountREG_DWORD0x1

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1935655697-688789844-725345543-1004
      ProfileImagePathREG_EXPAND_SZ%SystemDrive%\Documents and Settings\Tom
      SidREG_BINARY01050000000000051500000011C35F7354190E2 907E53B2BEC030000
      FlagsREG_DWORD0x0
      StateREG_DWORD0x100
      CentralProfileREG_SZ
      ProfileLoadTimeLowREG_DWORD0x58f65472
      ProfileLoadTimeHighREG_DWORD0x1ca9614
      RefCountREG_DWORD0x0
      RunLogonScriptSyncREG_DWORD0x0
      OptimizedLogonStatusREG_DWORD0xb

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1935655697-688789844-725345543-1005
      ProfileImagePathREG_EXPAND_SZ%SystemDrive%\Documents and Settings\Tom_2
      SidREG_BINARY01050000000000051500000011C35F7354190E2 907E53B2BED030000
      FlagsREG_DWORD0x0
      StateREG_DWORD0x100
      CentralProfileREG_SZ
      ProfileLoadTimeLowREG_DWORD0xd1f3f9c0
      ProfileLoadTimeHighREG_DWORD0x1cb1070
      RefCountREG_DWORD0x1
      RunLogonScriptSyncREG_DWORD0x0
      OptimizedLogonStatusREG_DWORD0xb

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1935655697-688789844-725345543-500
      ProfileImagePathREG_EXPAND_SZ%SystemDrive%\Documents and Settings\Administrator.TOM-2C5350163A3.000
      SidREG_BINARY01050000000000051500000011C35F7354190E2 907E53B2BF4010000
      FlagsREG_DWORD0x0
      StateREG_DWORD0x100
      CentralProfileREG_SZ
      ProfileLoadTimeLowREG_DWORD0x9c42c616
      ProfileLoadTimeHighREG_DWORD0x1cafd66
      RefCountREG_DWORD0x1
      RunLogonScriptSyncREG_DWORD0x0
      OptimizedLogonStatusREG_DWORD0xb


      Current Scheduled Tasks

      PATH: C:\Windows\Tasks

      desktop.ini
      SA.DAT


      Windows Drivers and NT-Services

      Volume in drive C has no label.
      Volume Serial Number is 5CAB-263F

      Directory of C:\Windows\System32\Drivers

      Volume in drive C has no label.
      Volume Serial Number is 5CAB-263F

      Directory of C:\Windows\System32\Drivers

      08/17/2001 02:46 PM 6,400 enum1394.sys
      08/17/2001 02:51 PM 3,328 pciide.sys
      08/17/2001 02:59 PM 3,072 audstub.sys
      07/17/2004 12:35 PM 67,866 netwlan5.img
      07/17/2004 12:36 PM 64,352 ativmc20.cod
      07/17/2004 11:55 PM 129,045 cxthsfs2.cty
      08/03/2004 11:29 PM 701,440 ati2mtag.sys
      08/03/2004 11:29 PM 327,040 ati2mtaa.sys
      08/03/2004 11:29 PM 57,856 atinbtxx.sys
      08/03/2004 11:29 PM 52,224 atinraxx.sys
      08/03/2004 11:29 PM 12,047 ati1pdxx.sys
      08/03/2004 11:29 PM 11,615 ati1mdxx.sys
      08/03/2004 11:29 PM 56,623 ati1btxx.sys
      08/03/2004 11:29 PM 13,824 atinmdxx.sys
      08/03/2004 11:29 PM 14,336 atinpdxx.sys
      08/03/2004 11:29 PM 13,824 atinttxx.sys
      08/03/2004 11:29 PM 28,672 atinsnxx.sys
      08/03/2004 11:29 PM 73,216 atintuxx.sys
      08/03/2004 11:29 PM 34,735 ati1xsxx.sys
      08/03/2004 11:29 PM 29,455 ati1xbxx.sys
      08/03/2004 11:29 PM 36,463 ati1tuxx.sys
      08/03/2004 11:29 PM 21,343 ati1ttxx.sys
      08/03/2004 11:29 PM 26,367 ati1snxx.sys
      08/03/2004 11:29 PM 31,744 atinxbxx.sys
      08/03/2004 11:29 PM 63,663 ati1rvxx.sys
      08/03/2004 11:29 PM 30,671 ati1raxx.sys
      08/03/2004 11:29 PM 63,488 atinxsxx.sys
      08/03/2004 11:29 PM 104,960 atinrvxx.sys
      08/03/2004 11:29 PM 452,736 mtxparhm.sys
      08/03/2004 11:29 PM 11,295 wadv08nt.sys
      08/03/2004 11:29 PM 11,807 wadv07nt.sys
      08/03/2004 11:29 PM 11,871 wadv09nt.sys
      08/03/2004 11:29 PM 11,935 wadv11nt.sys
      08/03/2004 11:29 PM 25,471 watv10nt.sys
      08/03/2004 11:29 PM 22,271 watv06nt.sys
      08/03/2004 11:29 PM 166,912 s3gnbm.sys
      08/03/2004 11:41 PM 1,309,184 mtlstrm.sys
      08/03/2004 11:41 PM 126,686 mtlmnt5.sys
      08/03/2004 11:41 PM 180,360 ntmtlfax.sys
      08/03/2004 11:41 PM 13,776 recagent.sys
      08/03/2004 11:41 PM 129,535 slnt7554.sys
      08/03/2004 11:41 PM 404,990 slntamr.sys
      08/03/2004 11:41 PM 13,240 slwdmsup.sys
      08/03/2004 11:41 PM 95,424 slnthal.sys
      08/03/2004 11:41 PM 220,032 hsfbs2s2.sys
      08/03/2004 11:41 PM 685,056 hsfcxts2.sys
      08/03/2004 11:41 PM 11,868 mdmxsdk.sys
      08/03/2004 11:41 PM 1,041,536 hsfdpsp2.sys
      08/04/2004 01:00 PM 21,376 tsbvcap.sys
      08/04/2004 01:00 PM 6,784 parvdm.sys
      08/04/2004 01:00 PM 51,712 tosdvd.sys
      08/04/2004 01:00 PM 17,792 ptilink.sys
      08/04/2004 01:00 PM 8,832 rasacd.sys
      08/04/2004 01:00 PM 16,512 raspti.sys
      08/04/2004 01:00 PM 11,648 acpiec.sys
      08/04/2004 01:00 PM 3,456 oprghdlr.sys
      08/04/2004 01:00 PM 31,360 atmepvc.sys
      08/04/2004 01:00 PM 55,936 nwlnkspx.sys
      08/04/2004 01:00 PM 352,256 atmuni.sys
      08/04/2004 01:00 PM 63,232 nwlnknb.sys
      08/04/2004 01:00 PM 32,512 nwlnkfwd.sys
      08/04/2004 01:00 PM 12,416 nwlnkflt.sys
      08/04/2004 01:00 PM 2,944 null.sys
      08/04/2004 01:00 PM 12,160 mouhid.sys
      08/04/2004 01:00 PM 4,224 rdpcdd.sys
      08/04/2004 01:00 PM 4,224 beep.sys
      08/04/2004 01:00 PM 12,032 nikedrv.sys
      08/04/2004 01:00 PM 4,352 wmilib.sys
      08/04/2004 01:00 PM 12,032 rio8drv.sys
      08/04/2004 01:00 PM 12,032 riodrv.sys
      08/04/2004 01:00 PM 5,888 rootmdm.sys
      08/04/2004 01:00 PM 10,496 dxapi.sys
      08/04/2004 01:00 PM 12,160 fsvga.sys
      08/04/2004 01:00 PM 13,952 cbidf2k.sys
      08/04/2004 01:00 PM 18,688 cdaudio.sys
      08/04/2004 01:00 PM 4,224 mnmdd.sys
      08/04/2004 01:00 PM 4,736 usbd.sys
      08/04/2004 01:00 PM 7,680 mcd.sys
      08/04/2004 01:00 PM 262,528 cinemst2.sys
      08/04/2004 01:00 PM 32,896 ipfltdrv.sys
      08/04/2004 01:00 PM 11,776 cpqdap01.sys
      08/04/2004 01:00 PM 34,432 rawwan.sys
      08/04/2004 01:00 PM 12,032 ws2ifsl.sys
      08/04/2004 01:00 PM 58,112 vdmindvd.sys
      08/04/2004 01:00 PM 14,592 smclib.sys
      08/04/2004 01:00 PM 7,936 fs_rec.sys
      08/04/2004 01:00 PM 646 gmreadme.txt
      08/04/2004 01:00 PM 3,440,660 gm.dls
      08/04/2004 01:00 PM 5,888 dmload.sys
      08/04/2004 01:00 PM 125,056 ftdisk.sys
      08/04/2004 01:00 PM 3,328 dxgthk.sys
      01/07/2005 06:07 PM 145,920 Hdaudio.sys
      01/04/2006 08:41 AM 1,389,056 Monfilt.sys
      09/28/2006 07:55 PM 77,568 WudfPf.sys
      09/28/2006 08:00 PM 82,944 WudfRd.sys
      10/18/2006 09:00 PM 38,528 wpdusb.sys
      11/30/2006 09:50 AM 64,360 mfeapfk.sys
      11/30/2006 09:50 AM 72,264 mfeavfk.sys
      11/30/2006 09:50 AM 52,136 mfetdik.sys
      11/30/2006 09:50 AM 168,776 mfehidk.sys
      11/30/2006 09:50 AM 34,152 mfebopk.sys
      09/17/2007 09:07 AM 6,853,088 nv4_mini.sys
      04/13/2008 05:36 PM 144,384 hdaudbus.sys
      04/13/2008 05:39 PM 20,480 secdrv.sys
      04/13/2008 05:39 PM 142,592 aec.sys
      04/13/2008 07:31 PM 35,840 processr.sys
      04/13/2008 07:31 PM 42,752 p3.sys
      04/13/2008 07:31 PM 37,376 amdk6.sys
      04/13/2008 07:31 PM 36,736 crusoe.sys
      04/13/2008 07:31 PM 36,352 intelppm.sys
      04/13/2008 07:31 PM 37,760 amdk7.sys
      04/13/2008 07:32 PM 66,048 udfs.sys
      04/13/2008 07:32 PM 30,848 npfs.sys
      04/13/2008 07:32 PM 19,072 msfs.sys
      04/13/2008 07:32 PM 180,608 mrxdav.sys
      04/13/2008 07:32 PM 196,224 rdpdr.sys
      04/13/2008 07:32 PM 129,792 fltmgr.sys
      04/13/2008 07:33 PM 44,544 fips.sys
      04/13/2008 07:36 PM 5,888 smbali.sys
      04/13/2008 07:36 PM 187,776 acpi.sys
      04/13/2008 07:36 PM 42,368 agp440.sys
      04/13/2008 07:36 PM 42,752 alim1541.sys
      04/13/2008 07:36 PM 40,960 sisagp.sys
      04/13/2008 07:36 PM 44,928 agpcpq.sys
      04/13/2008 07:36 PM 43,008 amdagp.sys
      04/13/2008 07:36 PM 42,240 viaagp.sys
      04/13/2008 07:36 PM 46,464 gagp30kx.sys
      04/13/2008 07:36 PM 44,672 uagp35.sys
      04/13/2008 07:36 PM 37,248 isapnp.sys
      04/13/2008 07:36 PM 63,744 mf.sys
      04/13/2008 07:36 PM 120,192 pcmcia.sys
      04/13/2008 07:36 PM 68,224 pci.sys
      04/13/2008 07:36 PM 79,232 sdbus.sys
      04/13/2008 07:36 PM 15,488 mssmbios.sys
      04/13/2008 07:36 PM 73,472 sr.sys
      04/13/2008 07:38 PM 71,168 dxg.sys
      04/13/2008 07:39 PM 384,768 update.sys
      04/13/2008 07:39 PM 42,368 mountmgr.sys
      04/13/2008 07:39 PM 24,576 kbdclass.sys
      04/13/2008 07:39 PM 23,040 mouclass.sys
      04/13/2008 07:39 PM 14,592 kbdhid.sys
      04/13/2008 07:39 PM 5,376 mspclock.sys
      04/13/2008 07:39 PM 4,992 mspqm.sys
      04/13/2008 07:39 PM 7,552 mskssrv.sys
      04/13/2008 07:39 PM 4,352 swenum.sys
      04/13/2008 07:40 PM 80,128 parport.sys
      04/13/2008 07:40 PM 15,744 serenum.sys
      04/13/2008 07:40 PM 27,392 fdc.sys
      04/13/2008 07:40 PM 20,480 flpydisk.sys
      04/13/2008 07:40 PM 57,600 redbook.sys
      04/13/2008 07:40 PM 24,960 pciidex.sys
      04/13/2008 07:40 PM 96,384 scsiport.sys
      04/13/2008 07:40 PM 96,512 atapi.sys
      04/13/2008 07:40 PM 14,208 diskdump.sys
      04/13/2008 07:40 PM 62,976 cdrom.sys
      04/13/2008 07:40 PM 11,904 sffdisk.sys
      04/13/2008 07:40 PM 36,352 disk.sys
      04/13/2008 07:40 PM 11,008 sffp_sd.sys
      04/13/2008 07:40 PM 11,392 sfloppy.sys
      04/13/2008 07:40 PM 10,240 sffp_mmc.sys
      04/13/2008 07:40 PM 19,712 partmgr.sys
      04/13/2008 07:40 PM 14,976 tape.sys
      04/13/2008 07:40 PM 42,112 imapi.sys
      04/13/2008 07:41 PM 52,352 volsnap.sys
      04/13/2008 07:43 PM 14,208 wacompen.sys
      04/13/2008 07:43 PM 12,672 mutohpen.sys
      04/13/2008 07:44 PM 81,664 videoprt.sys
      04/13/2008 07:44 PM 20,992 vga.sys
      04/13/2008 07:44 PM 153,344 dmio.sys
      04/13/2008 07:44 PM 799,744 dmboot.sys
      04/13/2008 07:45 PM 52,864 dmusic.sys
      04/13/2008 07:45 PM 6,272 splitter.sys
      04/13/2008 07:45 PM 56,576 swmidi.sys
      04/13/2008 07:45 PM 172,416 kmixer.sys
      04/13/2008 07:45 PM 2,944 drmkaud.sys
      04/13/2008 07:45 PM 60,160 drmk.sys
      04/13/2008 07:45 PM 49,408 stream.sys
      04/13/2008 07:45 PM 24,960 hidparse.sys
      04/13/2008 07:45 PM 36,864 hidclass.sys
      04/13/2008 07:45 PM 19,200 hidir.sys
      04/13/2008 07:45 PM 10,368 hidusb.sys
      04/13/2008 07:45 PM 15,104 usbscan.sys
      04/13/2008 07:45 PM 30,208 usbehci.sys
      04/13/2008 07:45 PM 20,608 usbuhci.sys
      04/13/2008 07:45 PM 143,872 usbport.sys
      04/13/2008 07:45 PM 59,520 usbhub.sys
      04/13/2008 07:45 PM 26,368 usbstor.sys
      04/13/2008 07:45 PM 25,600 usbcamd.sys
      04/13/2008 07:45 PM 25,728 usbcamd2.sys
      04/13/2008 07:45 PM 15,872 usbintel.sys
      04/13/2008 07:46 PM 25,344 sonydcam.sys
      04/13/2008 07:46 PM 53,376 1394bus.sys
      04/13/2008 07:46 PM 61,696 ohci1394.sys
      04/13/2008 07:46 PM 121,984 usbvideo.sys
      04/13/2008 07:46 PM 18,944 bthusb.sys
      04/13/2008 07:46 PM 25,600 hidbth.sys
      04/13/2008 07:46 PM 36,480 bthprint.sys
      04/13/2008 07:46 PM 59,136 rfcomm.sys
      04/13/2008 07:46 PM 37,888 bthmodem.sys
      04/13/2008 07:46 PM 17,024 bthenum.sys
      04/13/2008 07:51 PM 61,824 nic1394.sys
      04/13/2008 07:51 PM 59,904 atmarpc.sys
      04/13/2008 07:51 PM 60,800 arp1394.sys
      04/13/2008 07:51 PM 55,808 atmlane.sys
      04/13/2008 07:51 PM 101,120 bthpan.sys
      04/13/2008 07:53 PM 40,320 nmnt.sys
      04/13/2008 07:53 PM 71,552 bridge.sys
      04/13/2008 07:53 PM 36,608 ip6fw.sys
      04/13/2008 07:54 PM 11,264 irenum.sys
      04/13/2008 07:55 PM 14,592 ndisuio.sys
      04/13/2008 07:56 PM 12,288 tunmp.sys
      04/13/2008 07:56 PM 34,688 netbios.sys
      04/13/2008 07:56 PM 88,320 nwlnkipx.sys
      04/13/2008 07:56 PM 35,072 msgpc.sys
      04/13/2008 07:56 PM 69,120 psched.sys
      04/13/2008 07:56 PM 12,800 usb8023x.sys
      04/13/2008 07:56 PM 12,800 usb8023.sys
      04/13/2008 07:56 PM 30,592 rndismpx.sys
      04/13/2008 07:56 PM 30,592 rndismp.sys
      04/13/2008 07:57 PM 20,864 ipinip.sys
      04/13/2008 07:57 PM 152,832 ipnat.sys
      04/13/2008 07:57 PM 34,560 wanarp.sys
      04/13/2008 07:57 PM 10,112 ndistapi.sys
      04/13/2008 07:57 PM 14,336 asyncmac.sys
      04/13/2008 07:57 PM 40,576 ndproxy.sys
      04/13/2008 07:57 PM 41,472 raspppoe.sys
      04/13/2008 08:00 PM 19,072 tdi.sys
      04/13/2008 08:00 PM 30,080 modem.sys
      04/13/2008 08:14 PM 63,744 cdfs.sys
      04/13/2008 08:14 PM 143,744 fastfat.sys
      04/13/2008 08:15 PM 64,512 serial.sys
      04/13/2008 08:15 PM 574,976 ntfs.sys
      04/13/2008 08:15 PM 60,800 sysaudio.sys
      04/13/2008 08:16 PM 49,536 classpnp.sys
      04/13/2008 08:16 PM 141,056 ks.sys
      04/13/2008 08:17 PM 105,344 mup.sys
      04/13/2008 08:17 PM 83,072 wdmaud.sys
      04/13/2008 08:18 PM 52,480 i8042prt.sys
      04/13/2008 08:19 PM 146,048 portcls.sys
      04/13/2008 08:19 PM 51,328 rasl2tp.sys
      04/13/2008 08:19 PM 48,384 raspptp.sys
      04/13/2008 08:20 PM 182,656 ndis.sys
      04/13/2008 08:20 PM 91,520 ndiswan.sys
      04/13/2008 08:21 PM 162,816 netbt.sys
      04/13/2008 08:28 PM 175,744 rdbss.sys
      04/14/2008 01:11 AM 3,775 adv11nt5.dll
      04/14/2008 01:11 AM 3,711 adv09nt5.dll
      04/14/2008 01:11 AM 4,255 adv01nt5.dll
      04/14/2008 01:11 AM 3,967 adv02nt5.dll
      04/14/2008 01:11 AM 3,135 adv08nt5.dll
      04/14/2008 01:11 AM 3,615 adv05nt5.dll
      04/14/2008 01:11 AM 3,647 adv07nt5.dll
      04/14/2008 01:11 AM 21,183 atv01nt5.dll
      04/14/2008 01:11 AM 17,279 atv10nt5.dll
      04/14/2008 01:11 AM 14,143 atv06nt5.dll
      04/14/2008 01:11 AM 25,471 atv04nt5.dll
      04/14/2008 01:11 AM 11,359 atv02nt5.dll
      04/14/2008 01:11 AM 15,423 ch7xxnt5.dll
      04/14/2008 01:12 AM 3,901 siint5.dll
      04/14/2008 01:12 AM 11,325 vchnt5.dll
      04/14/2008 01:13 AM 40,840 termdd.sys
      04/14/2008 01:13 AM 12,040 tdpipe.sys
      04/14/2008 01:13 AM 21,896 tdtcp.sys
      04/14/2008 01:13 AM 139,656 rdpwd.sys
      05/08/2008 03:02 PM 203,136 rmcast.sys
      06/13/2008 12:05 PM 272,128 bthport.sys
      06/20/2008 12:51 PM 361,600 tcpip.sys
      08/05/2008 01:10 PM 1,684,736 Ambfilt.sys
      08/14/2008 11:04 AM 138,496 afd.sys
      10/30/2008 02:14 PM 117,888 Rtenicxp.sys
      01/20/2009 11:53 AM 5,027,840 RtkHDAud.sys
      06/24/2009 12:18 PM 92,928 ksecdd.sys
      10/20/2009 05:20 PM 265,728 http.sys
      11/05/2009 06:22 AM 9,984 scncap.sys
      11/27/2009 11:31 PM 21,035 AegisP.sys
      11/28/2009 06:43 AM disdn
      12/31/2009 05:50 PM 353,792 srv.sys
      02/11/2010 01:02 PM 226,880 tcpip6.sys
      02/24/2010 02:11 PM 455,680 mrxsmb.sys
      02/24/2010 09:49 PM UMDF
      04/14/2010 05:30 PM 28,880 aavmker4.sys
      04/14/2010 05:31 PM 19,024 aswFsBlk.sys
      04/14/2010 05:31 PM 94,800 aswmon.sys
      04/14/2010 05:31 PM 100,432 aswmon2.sys
      04/14/2010 05:31 PM 23,376 aswRdr.sys
      04/14/2010 05:35 PM 162,768 aswSP.sys
      04/14/2010 05:35 PM 46,672 aswTdi.sys
      06/15/2010 09:02 PM ..
      06/15/2010 09:02 PM .
      06/15/2010 09:05 PM etc
      285 File(s) 40,196,416 bytes
      5 Dir(s) 58,725,122,048 bytes free


      Virtual drives found?



      Environment variables

      ALLUSERSPROFILE=C:\Documents and Settings\All Users
      APPDATA=C:\Documents and Settings\Tom_2\Application Data
      CommonProgramFiles=C:\Program Files\Common Files
      COMPUTERNAME=TOM-2C5350163A3
      ComSpec=C:\WINDOWS\system32\cmd.exe
      DEFLOGDIR=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
      FP_NO_HOST_CHECK=NO
      HOMEDRIVE=C:
      HOMEPATH=\Documents and Settings\Tom_2
      LOGONSERVER=\\TOM-2C5350163A3
      NUMBER_OF_PROCESSORS=2
      OS=Windows_NT
      Path=C:\WINDOWS\System32;GL;C:\Program Files\Java\jdk1.6.0_17\bin;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\WBEM
      PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      PROCESSOR_ARCHITECTURE=x86
      PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
      PROCESSOR_LEVEL=6
      PROCESSOR_REVISION=0f06
      ProgramFiles=C:\Program Files
      PROMPT=$P$G
      SESSIONNAME=Console
      SystemDrive=C:
      SystemRoot=C:\WINDOWS
      TEMP=C:\DOCUME~1\Tom_2\LOCALS~1\Temp
      TMP=C:\DOCUME~1\Tom_2\LOCALS~1\Temp
      USERDOMAIN=TOM-2C5350163A3
      USERNAME=Tom_2
      USERPROFILE=C:\Documents and Settings\Tom_2
      VSEDEFLOGDIR=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
      windir=C:\WINDOWS
      __COMPAT_LAYER=EnableNXShowUI


      Stealth malware?


      Internet Explorer


      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
      Default_Page_URLREG_SZhttp://go.microsoft.com/fwlink/?LinkId=69157
      Default_Search_URLREG_SZhttp://go.microsoft.com/fwlink/?LinkId=54896
      Search PageREG_SZhttp://go.microsoft.com/fwlink/?LinkId=54896
      Enable_Disk_CacheREG_SZyes
      Cache_Percent_of_DiskREG_BINARY0A000000
      Delete_Temp_Files_On_ExitREG_SZyes
      Local PageREG_SZC:\WINDOWS\system32\blank.htm
      Anchor_Visitation_HorizonREG_BINARY01000000
      Use_Async_DNSREG_SZyes
      Placeholder_WidthREG_BINARY1A000000
      Placeholder_HeightREG_BINARY1A000000
      Start PageREG_SZhttp://go.microsoft.com/fwlink/?LinkId=69157
      CompanyNameREG_SZMicrosoft Corporation
      Custom_KeyREG_SZMICROSO
      Wizard_VersionREG_SZ6.0.2600.0000
      FullScreenREG_SZno
      Default_Secondary_Page_URLREG_MULTI_SZ\0
      Extensions Off PageREG_SZabout:NoAdd-ons
      Security Risk PageREG_SZabout:SecurityRisk
      Check_AssociationsREG_SZyes
      StatusBarWebREG_DWORD0x1
      SearchControlWidthREG_DWORD0x12c
      ForceGDIPlusREG_DWORD0x0
      DEPOffREG_DWORD0x0
      MaxRenderLineREG_DWORD0xfa0
      UseClearTypeREG_SZyes
      Page_TransitionsREG_DWORD0x1
      Use_DlgBox_ColorsREG_SZyes
      Anchor UnderlineREG_SZyes
      Display Inline ImagesREG_SZyes
      Display Inline VideosREG_DWORD0x1
      Play_Background_SoundsREG_SZyes
      Play_AnimationsREG_SZyes
      Print_BackgroundREG_SZno
      SmoothScrollREG_DWORD0x1
      XMLHTTPREG_DWORD0x1
      Show image placeholdersREG_DWORD0x0
      Disable Script DebuggerREG_SZyes
      Enable AutoImageResizeREG_SZyes
      XDomainRequestREG_DWORD0x1
      DOMStorageREG_DWORD0x1
      IE8RunOnceLastShownREG_DWORD0x0
      IE8RunOncePerInstallCompletedREG_DWORD0x0
      IE8TourNoShowREG_DWORD0x0
      IE8TourShownREG_DWORD0x0
      FrameTabWindowREG_DWORD0x1
      AdminTabProcsREG_DWORD0x1
      SessionMergingREG_DWORD0x1
      FrameMergingREG_DWORD0x1
      HangResistantFrameREG_DWORD0x0
      TabShutdownDelayREG_DWORD0xea60
      FrameShutdownDelayREG_DWORD0x0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
      User AgentREG_SZMozilla/4.0 (compatible; MSIE 8.0; Win32)
      IE5_UA_Backup_FlagREG_SZ5.0
      NoNetAutodialREG_DWORD0x0
      MigrateProxyREG_DWORD0x1
      EmailNameREG_SZ[emailprotected]
      AutoConfigProxyREG_SZwininet.dll
      MimeExclusionListForCacheREG_SZmultipart/mixed multipart/x-mixed-replace multipart/x-byteranges
      WarnOnPostREG_BINARY01000000
      UseSchannelDirectlyREG_BINARY01000000
      EnableHttp1_1REG_DWORD0x1
      UrlEncodingREG_DWORD0x0
      SecureProtocolsREG_DWORD0xa0
      PrivDiscUiShownREG_DWORD0x1
      PrivacyAdvancedREG_DWORD0x0
      ZonesSecurityUpgradeREG_BINARYC808B2B401DCCA01
      DisableCachingOfSSLPagesREG_DWORD0x0
      WarnonZoneCrossingREG_DWORD0x1
      EnableNegotiateREG_DWORD0x1
      ProxyEnableREG_DWORD0x0
      SyncMode5REG_DWORD0x3
      GlobalUserOfflineREG_DWORD0x0
      EnableAutodialREG_DWORD0x0
      ProxyHttp1.1REG_DWORD0x1
      EnablePunycodeREG_DWORD0x1
      ShowPunycodeREG_DWORD0x0
      CreateUriCacheSizeREG_DWORD0x50
      CoInternetCombineIUriCacheSizeREG_DWORD0x50
      SecurityIdIUriCacheSizeREG_DWORD0x1e
      SpecialFoldersCacheSizeREG_DWORD0x8
      WarnOnIntranetREG_DWORD0x1
      WarnonBadCertRecvingREG_DWORD0x1
      WarnOnPostRedirectREG_DWORD0x0
      WarnOnHTTPSToHTTPRedirectREG_DWORD0x1

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CACHE

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
      NoUpdateCheckREG_DWORD0x1
      Disable Script DebuggerREG_SZyes
      Anchor UnderlineREG_SZyes
      Cache_Update_FrequencyREG_SZOnce_Per_Session
      Display Inline ImagesREG_SZyes
      Do404SearchREG_BINARY01000000
      Local PageREG_SZC:\WINDOWS\system32\blank.htm
      Save_Session_History_On_ExitREG_SZno
      Show_FullURLREG_SZno
      Show_StatusBarREG_SZyes
      Show_ToolBarREG_SZyes
      Show_URLinStatusBarREG_SZyes
      Show_URLToolBarREG_SZyes
      Use_DlgBox_ColorsREG_SZyes
      Search PageREG_SZhttp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      XMLHTTPREG_DWORD0x1
      UseClearTypeREG_SZyes
      Enable Browser ExtensionsREG_SZyes
      Play_Background_SoundsREG_SZyes
      Play_AnimationsREG_SZyes
      IE8RunOnceLastShownREG_DWORD0x1
      IE8RunOncePerInstallCompletedREG_DWORD0x0
      IE8RunOnceCompletionTimeREG_BINARYFA96355738E2CA01
      IE8TourShownREG_DWORD0x1
      IE8TourShownTimeREG_BINARY98397CED9309CB01
      StatusBarWebREG_DWORD0x1
      SearchControlWidthREG_DWORD0x12c
      ForceGDIPlusREG_DWORD0x0
      SuppressScriptDebuggerDialogREG_DWORD0x0
      Page_TransitionsREG_DWORD0x1
      CSS_CompatREG_SZdoctype
      Expand Alt TextREG_SZno
      Display Inline VideosREG_DWORD0x1
      Print_BackgroundREG_SZno
      Use StylesheetsREG_DWORD0x1
      SmoothScrollREG_DWORD0x1
      Show image placeholdersREG_DWORD0x0
      DisableScriptDebuggerIEREG_SZyes
      Move System CaretREG_SZno
      Force Offscreen CompositionREG_DWORD0x0
      Enable AutoImageResizeREG_SZyes
      UseThemesREG_DWORD0x1
      UseHRREG_DWORD0x0
      Q300829REG_DWORD0x0
      Cleanup HTCsREG_DWORD0x0
      XDomainRequestREG_DWORD0x1
      DOMStorageREG_DWORD0x1
      IE8TourNoShowREG_DWORD0x0
      FrameTabWindowREG_DWORD0x1
      AdminTabProcsREG_DWORD0x1
      SessionMergingREG_DWORD0x1
      FrameMergingREG_DWORD0x1
      HangResistantFrameREG_DWORD0x0
      TabShutdownDelayREG_DWORD0xea60
      FrameShutdownDelayREG_DWORD0x0
      CompatibilityFlagsREG_DWORD0x0
      FullScreenREG_SZno
      Window_PlacementREG_BINARY2C0000000200000003000000FFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFF2700000027000000470300 00A7020000
      IE8RunOnceLastShown_TIMESTAMPREG_BINARYC4C87FE1C40CCB01
      RunOnceHasShownREG_DWORD0x1
      RunOnceCompleteREG_DWORD0x1
      Check_AssociationsREG_SZyes

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default Feeds

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Touch

      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
      SearchAssistantREG_SZhttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
      CustomizeSearchREG_SZhttp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
      {CFBFAE00-17A6-11D0-99CB-00C04FD64497}REG_SZ

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\QuickComplete

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt


      Security Center


      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
      FirstRunDisabledREG_DWORD0x1
      AntiVirusOverrideREG_DWORD0x0
      FirewallOverrideREG_DWORD0x0
      AntiVirusDisableNotifyREG_DWORD0x0
      FirewallDisableNotifyREG_DWORD0x0
      UpdatesDisableNotifyREG_DWORD0x0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
      EnableFirewallREG_DWORD0x0
      DoNotAllowExceptionsREG_DWORD0x0
      DisableNotificationsREG_DWORD0x1

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
      EnableFirewallREG_DWORD0x1
      DoNotAllowExceptionsREG_DWORD0x0
      DisableNotificationsREG_DWORD0x0

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
      %windir%\system32\sessmgr.exeREG_SZ%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      %windir%\Network Diagnostic\xpnetdiag.exeREG_SZ%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      C:\Program Files\McAfee\Common Framework\FrameworkService.exeREG_SZC:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service
      C:\Program Files\Orbitdownloader\orbitdm.exeREG_SZC:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
      C:\Program Files\Orbitdownloader\orbitnet.exeREG_SZC:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit
      C:\Program Files\Steam\steamapps\sirtom125\garrysmod\hl2.exeREG_SZC:\Program Files\Steam\steamapps\sirtom125\garrysmod\hl2.exe:*:Enabled:hl2
      C:\Program Files\ijji\ijji REACTOR\REACTOR.exeREG_SZC:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Enabled:Reactor Application
      C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exeREG_SZC:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe
      C:\Program Files\Java\jre6\bin\java.exeREG_SZC:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary


      Uninstall List


      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\avast5

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Cheat Engine 5.5_is1

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ijjiSetup

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB884016

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB884267

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB885353

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB886612

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB887078

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB887626

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888111WXPSP2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB888656

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB889858

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB891122

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB892130

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB892313

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB893240

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB893241

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB893803

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895181

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895316

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB895572

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB897586

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB898549

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB900399

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB902344

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB907658

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911565

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB911854

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923561

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923789

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB929399

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB939683

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB941569

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB946648

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950762

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950974

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951066

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951376-v2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951748

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951978

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952004

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952069_WM9

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952287

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952954

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954154_WM11

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954155_WM9

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954550-v5

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955069

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955759

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956572

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956744

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956802

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956803

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956844

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB957097

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958644

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958687

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958869

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB959426

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960225

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960803

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960859

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961118

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961371-v2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961501

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB967715

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968389

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968816_WM9

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969059

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969947

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB970238

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB970430

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971468

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971486

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971557

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971633

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971657

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971737

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971961-IE8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB972270

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973354

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973507

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973525

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973540_WM9

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973687

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973815

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973869

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973904

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974112

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974318

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974392

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974455

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974571

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975025

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975467

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975560

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975561

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975713

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB976002-v5

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB976098-v2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB976662-IE8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB977165

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB977816

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB977914

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978037

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978251

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978262

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978338

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978542

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978601

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978706

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979306

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979309

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979683

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980182-IE8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980232

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980302-IE8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB981332-IE8

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KOIELangPack

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\M953297

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 1.1 (1033)

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 3.5 SP1

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSCompPackV1

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSI30-Beta1

      HKEY_LOPlease run a free online scan with the ESET Online Scanner
      • Tick the box next to YES, I accept the Terms of Use
      • Click Start
      • When asked, allow the ActiveX control to install
      • Click Start
      • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
      • Click Scan (This scan can take several hours, so please be patient)
      • Once the scan is completed, you may close the window
      • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      • Copy and paste that log as a reply to this topic
      I can't use it because im on another computer, my own doesn't have internet because of my problem, sorry.Please download the latest version of Kaspersky GetSystemInfo (GSI) from Kaspersky and save it to your Desktop.

      Note: please close all other applications running on your system.

      Double click GetSystemInfo.exe to open it. It will display an agreement. Click on I Agree to continue.

      Click the Settings button.



      Set the slider to Maximum.



      IMPORTANT! Then, click Customize - choose Driver / Ports tab and uncheck Scan Ports.




      On the General tab, make sure all of the boxes are checked.




      On the Misc tab, make sure all the checkboxes are checked.

      Then, click OK on the windows that you launched.



      Click Create Report to run it.


      It will begin scanning.

      It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop.

      It should automatically upload it to http://www.getsysteminfo.com. If it does not, then please submit it manually by going to the site and doing the upload process.

      It will redirect to a page, where it will provide a sharing URL for specialists. Copy and paste the url of the GSI Parser report in your next reply.Sorry my late reply I was away at grandparents.

      GetSystemInfo version 4.0.1.243:


      Time[:]6/30/2010 10:04:17 PM



      BuildNumber[:]
      InstallDate[:]
      Manufacturer[:]Award Software International, Inc.
      Name[:]Award Modular BIOS v6.00PG
      PrimaryBIOS[:]True
      ReleaseDate[:]20090409000000.000000+000
      SerialNumber[:]
      SMBIOSBIOSVersion[:]F2
      SMBIOSMajorVersion[:]2
      SMBIOSMinorVersion[:]4
      SMBIOSPresent[:]True
      SoftwareElementID[:]Award Modular BIOS v6.00PG
      SoftwareElementState[:]3
      Status[:]OK
      TargetOperatingSystem[:]0
      version[:]GBT - 42302e31




      AddressWidth[:]32
      Architecture[:]0
      Availability[:]3
      Caption[:]x86 Family 6 Model 15 Stepping 6
      CpuStatus[:]1
      CurrentClockSpeed[:]2666
      CurrentVoltage[:]10
      DataWidth[:]32
      Description[:]x86 Family 6 Model 15 Stepping 6
      DeviceID[:]CPU0
      Family[:]2
      LastErrorCode[:]
      Level[:]6
      LoadPercentage[:]4
      Manufacturer[:]GenuineIntel
      MaxClockSpeed[:]2666
      Name[:]Intel(R) Core(TM)2 CPU 6700 @ 2.66GHz
      NumberOfCores[:]
      NumberOfLogicalProcessors[:]
      ProcessorType[:]3
      Role[:]CPU
      SocketDesignation[:]Socket 775
      Status[:]OK
      StatusInfo[:]3
      Stepping[:]6
      SystemName[:]TOM-2C5350163A3
      UpgradeMethod[:]15
      version[:]Model 15, Stepping 6
      VoltageCaps[:]




      BootDevice[:]\Device\HarddiskVolume1
      BuildNumber[:]2600
      BuildType[:]Multiprocessor Free
      Caption[:]Microsoft Windows XP Home Edition
      CountryCode[:]1
      CSDVersion[:]Service Pack 3
      Description[:]
      FreePhysicalMemory[:]1544976
      FreeSpaceInPagingFiles[:]3136948
      FreeVirtualMemory[:]2053876
      InstallDate[:]20091127220618.000000+000
      LastBootUpTime[:]20100630171809.375000+060
      LocalDateTime[:]20100630220419.140000+060
      Manufacturer[:]Microsoft Corporation
      NumberOfProcesses[:]32
      NumberOfUsers[:]2
      OSLanguage[:]1033
      ServicePackMajorVersion[:]3
      ServicePackMinorVersion[:]0
      SizeStoredInPagingFiles[:]3477284
      SystemDevice[:]\Device\HarddiskVolume1
      SystemDirectory[:]C:\WINDOWS\system32
      TotalVirtualMemorySize[:]2097024
      TotalVisibleMemorySize[:]2060716
      version[:]5.1.2600
      WindowsDirectory[:]C:\WINDOWS




      BootupState[:]Normal boot
      DNSHostName[:]
      Domain[:]MSHOME
      DomainRole[:]0
      Manufacturer[:]Gigabyte Technology Co., Ltd.
      Model[:]EG41MF-US2H
      NetworkServerModeEnabled[:]True
      PartOfDomain[:]
      PCSystemType[:]
      Status[:]OK
      SupportContactDescription[:]
      SystemType[:]X86-based PC
      UserName[:]TOM-2C5350163A3\Tom_2
      Workgroup[:]




      [][:]ComSpec => %SystemRoot%\system32\cmd.exe
      [][:]DEFLOGDIR => C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
      [][:]FP_NO_HOST_CHECK => NO
      [][:]NUMBER_OF_PROCESSORS => 2
      [][:]OS => Windows_NT
      [][:]PATHEXT => .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      [][:]PROCESSOR_ARCHITECTURE => x86
      [][:]PROCESSOR_IDENTIFIER => x86 Family 6 Model 15 Stepping 6, GenuineIntel
      [][:]PROCESSOR_LEVEL => 6
      [][:]PROCESSOR_REVISION => 0f06
      [][:]TEMP => %SystemRoot%\TEMP
      [][:]TMP => %SystemRoot%\TEMP
      [][:]VSEDEFLOGDIR => C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
      [][:]windir => %SystemRoot%
      [NT AUTHORITY\SYSTEM][:]TEMP => %USERPROFILE%\Local Settings\Temp
      [NT AUTHORITY\SYSTEM][:]TMP => %USERPROFILE%\Local Settings\Temp
      [NT AUTHORITY\LOCAL SERVICE][:]TEMP => %USERPROFILE%\Local Settings\Temp
      [NT AUTHORITY\LOCAL SERVICE][:]TMP => %USERPROFILE%\Local Settings\Temp
      [NT AUTHORITY\NETWORK SERVICE][:]TEMP => %USERPROFILE%\Local Settings\Temp
      [NT AUTHORITY\NETWORK SERVICE][:]TMP => %USERPROFILE%\Local Settings\Temp
      [TOM-2C5350163A3\Tom_2][:]Path => GL;C:\Program Files\Java\jdk1.6.0_17\bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM
      [TOM-2C5350163A3\Tom_2][:]TEMP => %USERPROFILE%\Local Settings\Temp
      [TOM-2C5350163A3\Tom_2][:]TMP => %USERPROFILE%\Local Settings\Temp



      Name[:]Microsoft XPS Document Writer
      Default[:]True
      HorizontalResolution[:]600
      JobCountSinceLastReset[:]0
      Local[:]True
      Network[:]False
      PortName[:]XPSPort:
      PrinterState[:]0
      PrintProcessor[:]WinPrint
      Priority[:]1
      Published[:]False
      Queued[:]False
      RawOnly[:]False
      ServerName[:]
      Shared[:]False
      ShareName[:]
      SpoolEnabled[:]True
      Status[:]Unknown
      VerticalResolution[:]600
      WorkOffline[:]False










      ConfigManagerErrorCode[:]0
      DeviceID[:]HDAUDIO\FUNC_01&VEN_10EC&DEV_0888&SUBSYS_1458A002&REV_1000\4&2F790C35&0&0201
      Manufacturer[:]Realtek
      Name[:]Realtek High Definition Audio
      ProductName[:]Realtek High Definition Audio
      Status[:]OK
      StatusInfo[:]3




      Category[:]0
      CategoryString[:]
      EventCode[:]258
      EventIdentifier[:]-2147483390
      EventType[:]2
      Logfile[:]Application
      Message[:]The update failed; see event log.
      RecordNumber[:]2408
      SourceName[:]McLogEvent
      TimeGenerated[:]20100628214007.000000+060
      TimeWritten[:]20100628214007.000000+060
      Type[:]warning
      User[:]NT AUTHORITY\SYSTEM

      Category[:]0
      CategoryString[:]
      EventCode[:]1802
      EventIdentifier[:]-1073740022
      EventType[:]1
      Logfile[:]Application
      Message[:]The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
      RecordNumber[:]2405
      SourceName[:]SecurityCenter
      TimeGenerated[:]20100628080609.000000+060
      TimeWritten[:]20100628080609.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1
      EventIdentifier[:]1073741825
      EventType[:]1
      Logfile[:]Application
      Message[:]
      RecordNumber[:]2404
      SourceName[:]JavaQuickStarterService
      TimeGenerated[:]20100628080556.000000+060
      TimeWritten[:]20100628080556.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1802
      EventIdentifier[:]-1073740022
      EventType[:]1
      Logfile[:]Application
      Message[:]The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
      RecordNumber[:]2401
      SourceName[:]SecurityCenter
      TimeGenerated[:]20100628072100.000000+060
      TimeWritten[:]20100628072100.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1
      EventIdentifier[:]1073741825
      EventType[:]1
      Logfile[:]Application
      Message[:]
      RecordNumber[:]2400
      SourceName[:]JavaQuickStarterService
      TimeGenerated[:]20100628072043.000000+060
      TimeWritten[:]20100628072043.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1
      EventIdentifier[:]1073741825
      EventType[:]1
      Logfile[:]Application
      Message[:]
      RecordNumber[:]2409
      SourceName[:]JavaQuickStarterService
      TimeGenerated[:]20100629175909.000000+060
      TimeWritten[:]20100629175909.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1802
      EventIdentifier[:]-1073740022
      EventType[:]1
      Logfile[:]Application
      Message[:]The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
      RecordNumber[:]2410
      SourceName[:]SecurityCenter
      TimeGenerated[:]20100629175925.000000+060
      TimeWritten[:]20100629175925.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]258
      EventIdentifier[:]-2147483390
      EventType[:]2
      Logfile[:]Application
      Message[:]The update failed; see event log.
      RecordNumber[:]2413
      SourceName[:]McLogEvent
      TimeGenerated[:]20100629215505.000000+060
      TimeWritten[:]20100629215505.000000+060
      Type[:]warning
      User[:]NT AUTHORITY\SYSTEM

      Category[:]0
      CategoryString[:]
      EventCode[:]1
      EventIdentifier[:]1073741825
      EventType[:]1
      Logfile[:]Application
      Message[:]
      RecordNumber[:]2414
      SourceName[:]JavaQuickStarterService
      TimeGenerated[:]20100630073651.000000+060
      TimeWritten[:]20100630073651.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1802
      EventIdentifier[:]-1073740022
      EventType[:]1
      Logfile[:]Application
      Message[:]The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
      RecordNumber[:]2415
      SourceName[:]SecurityCenter
      TimeGenerated[:]20100630073705.000000+060
      TimeWritten[:]20100630073705.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1
      EventIdentifier[:]1073741825
      EventType[:]1
      Logfile[:]Application
      Message[:]
      RecordNumber[:]2418
      SourceName[:]JavaQuickStarterService
      TimeGenerated[:]20100630172038.000000+060
      TimeWritten[:]20100630172038.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]1802
      EventIdentifier[:]-1073740022
      EventType[:]1
      Logfile[:]Application
      Message[:]The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus and Firewall.
      RecordNumber[:]2419
      SourceName[:]SecurityCenter
      TimeGenerated[:]20100630172054.000000+060
      TimeWritten[:]20100630172054.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]258
      EventIdentifier[:]-2147483390
      EventType[:]2
      Logfile[:]Application
      Message[:]The update failed; see event log.
      RecordNumber[:]2422
      SourceName[:]McLogEvent
      TimeGenerated[:]20100630214105.000000+060
      TimeWritten[:]20100630214105.000000+060
      Type[:]warning
      User[:]NT AUTHORITY\SYSTEM

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]6782
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630181720.000000+060
      TimeWritten[:]20100630181720.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]6781
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630181720.000000+060
      TimeWritten[:]20100630181720.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]6668
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630181712.000000+060
      TimeWritten[:]20100630181712.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]6667
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630181712.000000+060
      TimeWritten[:]20100630181712.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7026
      EventIdentifier[:]-1073734798
      EventType[:]1
      Logfile[:]System
      Message[:]The following boot-start or system-start driver(s) failed to load: mfetdik Tcpip
      RecordNumber[:]6658
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630172155.000000+060
      TimeWritten[:]20100630172155.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7023
      EventIdentifier[:]-1073734801
      EventType[:]1
      Logfile[:]System
      Message[:]The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
      RecordNumber[:]6657
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630172155.000000+060
      TimeWritten[:]20100630172155.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The IPSEC Services service depends on the following nonexistent service: IPSec
      RecordNumber[:]6656
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630172155.000000+060
      TimeWritten[:]20100630172155.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6655
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630172155.000000+060
      TimeWritten[:]20100630172155.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DHCP Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6654
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630172155.000000+060
      TimeWritten[:]20100630172155.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]39
      EventIdentifier[:]-2108030937
      EventType[:]2
      Logfile[:]System
      Message[:]The time service is unable to register for network configuration change events. This may occur when TCP/IP is not correctly configured. The time service will be unable to sync time from network providers, but will still use locally installed hardware provdiers, if any are available.
      RecordNumber[:]6653
      SourceName[:]W32Time
      TimeGenerated[:]20100630172050.000000+060
      TimeWritten[:]20100630172050.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]4311
      EventIdentifier[:]-1073737513
      EventType[:]1
      Logfile[:]System
      Message[:]Initialization failed because the driver device could not be created.
      RecordNumber[:]6652
      SourceName[:]NetBT
      TimeGenerated[:]20100630171814.000000+060
      TimeWritten[:]20100630171844.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7026
      EventIdentifier[:]-1073734798
      EventType[:]1
      Logfile[:]System
      Message[:]The following boot-start or system-start driver(s) failed to load: mfetdik Tcpip
      RecordNumber[:]6644
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630073806.000000+060
      TimeWritten[:]20100630073806.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7023
      EventIdentifier[:]-1073734801
      EventType[:]1
      Logfile[:]System
      Message[:]The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
      RecordNumber[:]6643
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630073806.000000+060
      TimeWritten[:]20100630073806.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The IPSEC Services service depends on the following nonexistent service: IPSec
      RecordNumber[:]6642
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630073806.000000+060
      TimeWritten[:]20100630073806.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6641
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630073806.000000+060
      TimeWritten[:]20100630073806.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DHCP Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6640
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630073806.000000+060
      TimeWritten[:]20100630073806.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]39
      EventIdentifier[:]-2108030937
      EventType[:]2
      Logfile[:]System
      Message[:]The time service is unable to register for network configuration change events. This may occur when TCP/IP is not correctly configured. The time service will be unable to sync time from network providers, but will still use locally installed hardware provdiers, if any are available.
      RecordNumber[:]6639
      SourceName[:]W32Time
      TimeGenerated[:]20100630073701.000000+060
      TimeWritten[:]20100630073701.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]4311
      EventIdentifier[:]-1073737513
      EventType[:]1
      Logfile[:]System
      Message[:]Initialization failed because the driver device could not be created.
      RecordNumber[:]6638
      SourceName[:]NetBT
      TimeGenerated[:]20100630073427.000000+060
      TimeWritten[:]20100630073457.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]6634
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629215502.000000+060
      TimeWritten[:]20100629215502.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]6633
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629215502.000000+060
      TimeWritten[:]20100629215502.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7026
      EventIdentifier[:]-1073734798
      EventType[:]1
      Logfile[:]System
      Message[:]The following boot-start or system-start driver(s) failed to load: mfetdik Tcpip
      RecordNumber[:]6627
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629180025.000000+060
      TimeWritten[:]20100629180025.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7023
      EventIdentifier[:]-1073734801
      EventType[:]1
      Logfile[:]System
      Message[:]The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
      RecordNumber[:]6626
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629180025.000000+060
      TimeWritten[:]20100629180025.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The IPSEC Services service depends on the following nonexistent service: IPSec
      RecordNumber[:]6625
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629180025.000000+060
      TimeWritten[:]20100629180025.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6624
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629180025.000000+060
      TimeWritten[:]20100629180025.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DHCP Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6623
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100629180025.000000+060
      TimeWritten[:]20100629180025.000000+060
      Type[:]error
      User[:]

      Category[:]6
      CategoryString[:]Software Sync
      EventCode[:]16
      EventIdentifier[:]16
      EventType[:]1
      Logfile[:]System
      Message[:]Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
      RecordNumber[:]6622
      SourceName[:]Windows Update Agent
      TimeGenerated[:]20100629180023.000000+060
      TimeWritten[:]20100629180023.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]39
      EventIdentifier[:]-2108030937
      EventType[:]2
      Logfile[:]System
      Message[:]The time service is unable to register for network configuration change events. This may occur when TCP/IP is not correctly configured. The time service will be unable to sync time from network providers, but will still use locally installed hardware provdiers, if any are available.
      RecordNumber[:]6621
      SourceName[:]W32Time
      TimeGenerated[:]20100629175920.000000+060
      TimeWritten[:]20100629175920.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]4311
      EventIdentifier[:]-1073737513
      EventType[:]1
      Logfile[:]System
      Message[:]Initialization failed because the driver device could not be created.
      RecordNumber[:]6620
      SourceName[:]NetBT
      TimeGenerated[:]20100629175645.000000+060
      TimeWritten[:]20100629175715.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]36
      EventIdentifier[:]-2108030940
      EventType[:]2
      Logfile[:]System
      Message[:]The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized.
      RecordNumber[:]6617
      SourceName[:]W32Time
      TimeGenerated[:]20100628214521.000000+060
      TimeWritten[:]20100628214521.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]6616
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628214004.000000+060
      TimeWritten[:]20100628214004.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]6615
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628214004.000000+060
      TimeWritten[:]20100628214004.000000+060
      Type[:]error
      User[:]

      Category[:]6
      CategoryString[:]Software Sync
      EventCode[:]16
      EventIdentifier[:]16
      EventType[:]1
      Logfile[:]System
      Message[:]Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
      RecordNumber[:]6614
      SourceName[:]Windows Update Agent
      TimeGenerated[:]20100628174812.000000+060
      TimeWritten[:]20100628174812.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7026
      EventIdentifier[:]-1073734798
      EventType[:]1
      Logfile[:]System
      Message[:]The following boot-start or system-start driver(s) failed to load: mfetdik Tcpip
      RecordNumber[:]6608
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628080710.000000+060
      TimeWritten[:]20100628080710.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7023
      EventIdentifier[:]-1073734801
      EventType[:]1
      Logfile[:]System
      Message[:]The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
      RecordNumber[:]6607
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628080710.000000+060
      TimeWritten[:]20100628080710.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The IPSEC Services service depends on the following nonexistent service: IPSec
      RecordNumber[:]6606
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628080710.000000+060
      TimeWritten[:]20100628080710.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6605
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628080710.000000+060
      TimeWritten[:]20100628080710.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DHCP Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6604
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628080710.000000+060
      TimeWritten[:]20100628080710.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]39
      EventIdentifier[:]-2108030937
      EventType[:]2
      Logfile[:]System
      Message[:]The time service is unable to register for network configuration change events. This may occur when TCP/IP is not correctly configured. The time service will be unable to sync time from network providers, but will still use locally installed hardware provdiers, if any are available.
      RecordNumber[:]6603
      SourceName[:]W32Time
      TimeGenerated[:]20100628080605.000000+060
      TimeWritten[:]20100628080606.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]4311
      EventIdentifier[:]-1073737513
      EventType[:]1
      Logfile[:]System
      Message[:]Initialization failed because the driver device could not be created.
      RecordNumber[:]6602
      SourceName[:]NetBT
      TimeGenerated[:]20100628080332.000000+060
      TimeWritten[:]20100628080402.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7026
      EventIdentifier[:]-1073734798
      EventType[:]1
      Logfile[:]System
      Message[:]The following boot-start or system-start driver(s) failed to load: mfetdik Tcpip
      RecordNumber[:]6594
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628072200.000000+060
      TimeWritten[:]20100628072200.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7023
      EventIdentifier[:]-1073734801
      EventType[:]1
      Logfile[:]System
      Message[:]The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
      RecordNumber[:]6593
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628072200.000000+060
      TimeWritten[:]20100628072200.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The IPSEC Services service depends on the following nonexistent service: IPSec
      RecordNumber[:]6592
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628072200.000000+060
      TimeWritten[:]20100628072200.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6591
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628072200.000000+060
      TimeWritten[:]20100628072200.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The DHCP Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
      RecordNumber[:]6590
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100628072200.000000+060
      TimeWritten[:]20100628072200.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]39
      EventIdentifier[:]-2108030937
      EventType[:]2
      Logfile[:]System
      Message[:]The time service is unable to register for network configuration change events. This may occur when TCP/IP is not correctly configured. The time service will be unable to sync time from network providers, but will still use locally installed hardware provdiers, if any are available.
      RecordNumber[:]6589
      SourceName[:]W32Time
      TimeGenerated[:]20100628072055.000000+060
      TimeWritten[:]20100628072055.000000+060
      Type[:]warning
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]4311
      EventIdentifier[:]-1073737513
      EventType[:]1
      Logfile[:]System
      Message[:]Initialization failed because the driver device could not be created.
      RecordNumber[:]6588
      SourceName[:]NetBT
      TimeGenerated[:]20100628071819.000000+060
      TimeWritten[:]20100628071849.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]7122
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630182214.000000+060
      TimeWritten[:]20100630182214.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]7123
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630182214.000000+060
      TimeWritten[:]20100630182214.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]7124
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630183431.000000+060
      TimeWritten[:]20100630183431.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]7125
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630183431.000000+060
      TimeWritten[:]20100630183431.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]7126
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630183511.000000+060
      TimeWritten[:]20100630183511.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]7127
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630183511.000000+060
      TimeWritten[:]20100630183511.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]7130
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630192433.000000+060
      TimeWritten[:]20100630192433.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]7131
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630192433.000000+060
      TimeWritten[:]20100630192433.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7003
      EventIdentifier[:]-1073734821
      EventType[:]1
      Logfile[:]System
      Message[:]The TCP/IP Protocol Driver service depends on the following nonexistent service: IPSec
      RecordNumber[:]7132
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630214101.000000+060
      TimeWritten[:]20100630214101.000000+060
      Type[:]error
      User[:]

      Category[:]0
      CategoryString[:]
      EventCode[:]7001
      EventIdentifier[:]-1073734823
      EventType[:]1
      Logfile[:]System
      Message[:]The Network Location Awareness (NLA) service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: The dependency service does not exist or has been marked for deletion.
      RecordNumber[:]7133
      SourceName[:]Service Control Manager
      TimeGenerated[:]20100630214101.000000+060
      TimeWritten[:]20100630214101.000000+060
      Type[:]error
      User[:]




      Caption[:]A:
      CreationClassName[:]Win32_LogicalDisk
      Description[:]3 1/2 Inch Floppy Drive
      DeviceID[:]A:
      DriveType[:]2
      FileSystem[:]
      FreeSpace[:]
      MediaType[:]5
      Name[:]A:
      SIZE[:]
      VolumeName[:]
      VolumeSerialNumber[:]

      Caption[:]C:
      CreationClassName[:]Win32_LogicalDisk
      Description[:]Local Fixed Disk
      DeviceID[:]C:
      DriveType[:]3
      FileSystem[:]NTFS
      FreeSpace[:]58629591040
      MediaType[:]12
      Name[:]C:
      SIZE[:]79982587904
      VolumeName[:]
      VolumeSerialNumber[:]5CAB263F

      Caption[:]D:
      CreationClassName[:]Win32_LogicalDisk
      Description[:]CD-ROM Disc
      DeviceID[:]D:
      DriveType[:]5
      FileSystem[:]
      FreeSpace[:]
      MediaType[:]11
      Name[:]D:
      SIZE[:]
      VolumeName[:]
      VolumeSerialNumber[:]

      Caption[:]E:
      CreationClassName[:]Win32_LogicalDisk
      Description[:]Removable Disk
      DeviceID[:]E:
      DriveType[:]2
      FileSystem[:]FAT32
      FreeSpace[:]5837455360
      MediaType[:]
      Name[:]E:
      SIZE[:]7939817472
      VolumeName[:]
      VolumeSerialNumber[:]65386131




      Name[:]Adobe Flash Player 10 ActiveX
      Uninstall[:]C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Vendor[:]Adobe Systems Incorporated
      Version[:]10.0.32.18
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]avast! Free Antivirus
      Uninstall[:]C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
      Vendor[:]Alwil Software
      Version[:]5.0.507.0
      InstallDate[:]
      InstallLocation[:]C:\PROGRA~1\ALWILS~1\Avast5
      Language[:]

      Name[:]avast! Free Antivirus
      Uninstall[:]C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
      Vendor[:]Alwil Software
      Version[:]5.0.507.0
      InstallDate[:]
      InstallLocation[:]C:\PROGRA~1\ALWILS~1\Avast5
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Cheat Engine 5.5
      Uninstall[:]"C:\Program Files\Cheat Engine\unins000.exe"
      Vendor[:]Dark Byte
      Version[:]
      InstallDate[:]20100125
      InstallLocation[:]C:\Program Files\Cheat Engine\
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]Windows Internet Explorer 8
      Uninstall[:]"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20090308.140743
      InstallDate[:]20100414
      InstallLocation[:]
      Language[:]

      Name[:]High Definition Audio Driver Package - KB888111
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20040219.000000
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]High Definition Audio Driver Package - KB888111
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20040219.000000
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]High Definition Audio Driver Package - KB888111
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20040219.000000
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]High Definition Audio Driver Package - KB888111
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]20040219.000000
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Windows Genuine Advantage Validation Tool (KB892130)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091127
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB923561)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB923789)
      Uninstall[:]C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]
      InstallLocation[:]
      Language[:]

      Name[:]Hotfix for Windows Media Format 11 SDK (KB929399)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20100226
      InstallLocation[:]
      Language[:]

      Name[:]Hotfix for Windows Media Player 11 (KB939683)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20100226
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB941569)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091202
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB946648)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB950762)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB950974)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB951066)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB951376-v2)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]2
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB951748)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Update for Windows XP (KB951978)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB952004)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows Media Player (KB952069)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Hotfix for Windows XP (KB952287)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB952954)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows Media Player 11 (KB954154)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20100226
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows Media Player (KB954155)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Hotfix for Windows XP (KB954550-v5)
      Uninstall[:]
      Vendor[:]Microsoft Corporation
      Version[:]5
      InstallDate[:]20091218
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB955069)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Update for Windows XP (KB955759)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20100109
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB956572)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB956744)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB956802)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB956803)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB956844)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB957097)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB958644)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB958687)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB958869)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB959426)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB960225)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB960803)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB960859)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Hotfix for Windows XP (KB961118)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091220
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB961371-v2)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]2
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB961501)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Update for Windows XP (KB967715)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Update for Windows XP (KB968389)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows Media Player (KB968816)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB969059)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB969947)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB970238)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB970430)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091210
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB971468)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20100219
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB971486)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB971557)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Vendor[:]Microsoft Corporation
      Version[:]1
      InstallDate[:]20091128
      InstallLocation[:]
      Language[:]

      Name[:]Security Update for Windows XP (KB971633)
      Uninstall[:]"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Vendor[:]Microsoft CPlease download MySystem-Search from here: Download mirror
      • Save the file to your Desktop.
      • Double-click on mss.exe
      • Allow it to run, and follow the prompts.
      • Once done, it will launch a log.
      • Post it in your next reply.
      Note: the logs are long. Please use more than one post, if necessary.
      3136.

      Solve : bsod/screensaver/backround virus alert?

      Answer»

      Hey guys I think I have a virus or malware no sure. I'm not on the infected COMPUTER since I'm on my laptop and at COLLEGE waiting to go to class. But I have a background saying that I NEED a anti-virus program and that I'm infected. I have a avira anti-virus program and I did a scan on this morning but I didn't see the results since I had to leave for work. I plan on getting the logs and everything done tomorrow. I just curious on what kind of virus this could be since I had anti-virus and it did ask me if I wanted to remove it right away and when I did that it went all to heck. I have a compaq presario amd 1.8 1gig of ram and windows xp home sp3. I MIGHT be able to get the logs done in the morning I'm not sure and post them then but if not it will be sometime in the afternoon.Quote

      just curious on what kind of virus this could be since I had anti-virus and it did ask me if I wanted to remove it right away

      Thats how they are designed, to trick your security for long enough to install themselves.Yeah tell me about it:) anyways I'll try and get the logs to you as soon as I can and pretty much all my scans and log should be done in safe mode or can I do it in normal mode I usually do my antivirus scans in normal modeDo everything in normal mode unless the instructions call for safe mode.okay sounds good i have 2 of the logs done so far

      [recovering disk space -- attachment deleted by admin]You didn't update Java or add the MBAM log.

      HijackThis should be done last.here's my mbam log I'm going to update java

      [recovering disk space -- attachment deleted by admin]updated java and here's my Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 4:34:35 PM, on 9/3/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\windows\system32\RUNDLL32.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Program Files\COMODO\Firewall\cfp.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
      C:\windows\system32\ctfmon.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\COMODO\Firewall\cmdagent.exe
      C:\WINDOWS\system32\CTsvcCDA.EXE
      C:\Program Files\Google\Common\Google UPDATER\GoogleUpdaterService.exe
      C:\windows\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\windows\system32\wuauclt.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
      O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
      O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
      O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
      O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O20 - AppInit_DLLs: C:\windows\system32\guard32.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

      --
      End of file - 8103 bytes
      new hijack this logi've run cc cleaner and i'm doing a another sas scan and if you want me to I will do another hijack this log and malware bytes scan.Looks fine, how is everything now?everything seems to be okay I just got done with a virus scan and it found 3 more but I had them quarantined but other than that I think it's pretty much fixed. Thanks alot for your help Evil. Use the Kaspersky Online Scanner

      In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

      Click on SCAN NOW
      Click on the Accept button and install any components it needs.
      • The program will install and then begin downloading the latest definition files.
      • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
      • This will start the program and scan your system.
      • The scan will take a while, so be patient and let it run.
      • Once the scan is complete, click on View scan report
      • Now, click on the Save Report as button.
      • In Save as type: click the drop arrow and select: Text file [*.txt]
      • Then, click: Save
      • Save the file to your desktop.
      Post the Kaspersky log in your next reply.

      Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
      3137.

      Solve : Keyboard and mouse freeze when I touch any keyboard key?

      Answer»

      I have two different versions of Windows XP on my system. I am able to SELECT which one I want with the enter key. But after Windows comes up with my family's usernames, the keyboard and MOUSE freeze whenever a key is touched. I am able to use the mouse, open documents and files, surf the WEB, etc., just can't type. I think I have CONTACTED a virus, but AVG doesn't find anything. Anybody familiar with a virus that behaves this way?How long has this been happening?

      Have you TRIED a System Restore?Been happening for about a week now. Did not try a system restore - I was not at home when it started so not sure exactly when.What about another keyboard? (preferably a PS/2 keyboard - round plug)

      3138.

      Solve : AVG version 8 ??

      Answer»

      Is it just me or is this newest version of AVG a pain in the &*$% ?
      It has a lot more features than the previous versions, but it seems to hang sometimes when it wants to update and for the last couple of scans, it KEEPS telling me the "Print Shop" software (which I've had installed for ages) is possibly infected.
      Is there a better, free anti-virus program that would be recommended? I have un-installed the Print Shop software for now so it will stop being picked up as a problem.
      Thanks in advance.I used AVG for a few YEARS, but gave up version 8 as a pain. I now use Avira, though I have seen Avast recommended as well.AVG 8 has been a problem for many users. I switched to Avast!, like it and have had no problems.

      Best of luck.AVG8 has indeed been a major pain for many users, myself included. It caused me loads of trouble and it took a bit of work to get it running the way I like. If you're certain that your program is not infected, you could add it to AVG's exceptions. However, if you would like to use a different program, Avast! and Avira are both good choices.Same story here. I installed it (with big problems) on my XP, and kept it for testing reasons.
      Finally, tonight I got fed up.
      For last couple of weeks. it kept flagging three legit Online Armor firewall files.
      You can mark them "Ignore", but next time you restart computer, they're FLAGGED again.
      Tonight, I said, FU, and went for Avira on XP.Thanks everyone...I'm going to play with the SETTINGS & if I can't get to work smoothly in the next day or TWO I am going to try Avast!
      Thanks again.

      3139.

      Solve : plss....open this topic!?

      Answer»

      can someone help me to UNBLOCK blocked websites???

      for example ....my FRIEND blocked "friendster.com" in my PC...

      how could i FIX this???so i can VISIT friendster.comIs this your computer? If your the admin, it should be simple.

      3140.

      Solve : avg 8.0 issues?

      Answer»

      I have been using AVG for years now; and installed 8.0 about 2-3 months ago. It has worked great up until lately; every once in a while I will get a message that a .bin file is missing, and in the last COUPLE of days I get pop ups stating that my update connection is inactive................anybody got any ideas? my system is XP home and works real good, except for this annoying issueUpdate it and the error should go away. This happened with an update a few weeks back and has been fixed.I have it updated and this keeps coming back........I don't know...Reinstall. http://free.avg.com/ww.download-avg-anti-virus-free-editionThanks, Evilfantasy, that is what I am doing; I deleted it TODAY and tried Avira; and it looks pretty good, but I like the AVG format better so I am going to reinstall it. Incidently, it did a good job of identifying some "MALWARE" similarities for some games my wife downloaded from Big Fish Games. I contacted BFG the other day and was told that some of the AV programs sometimes RECOGNIZE them as virus prone because of similar coding.

      thanks for the responseQuote

      I contacted BFG the other day and was told that some of the AV programs sometimes recognize them as virus prone because of similar coding.

      That's a nice spin to put on it. Gig Fish Games are ad supported so yes some antimalware software see them as adware, because it is. Not dangerous, just ad supported.You know, I said that I was going to reinstall the AVG 8.0; well, I have not done this yet, I thought I would watch the Avira for a few days..............and you know what?....we just might have a new friend here. It's really a pretty good program. It's kind of like the dog we own....she just showed up about 6 months ago, and just "fit RIGHT in" with the family.

      gator
      3141.

      Solve : Bio hazard virus logs for review.?

      Answer»

      I had the biohazard screen virus on my computer. I followed all the steps to remove it as instructed, except the first one of installing the antivirus software, (everytime I tried it told me the file was corrupted). The logs of everything should be attached to this POST(I hope)! Thanks for all your help and patience, it is greatly appreciated!!

      [recovering disk space -- attachment deleted by admin]I locked the other topic and we will work from this one.

      You have Norton installed, why are you trying to download a new antivirus?

      Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note: It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

      Here are the two logs you requested (I think), there are windows popping up all the time now for MS security center and such, is this normal and should I just keep closing them?

      Also the Norton Antivirus that I have is from 2003, should I download a more recent antivirus program, or is what I have going to work?

      Thanks for all your help!

      [recovering disk space -- attachment deleted by admin]Yes you will want to update the antivirus, but don't do it until you are malware free.

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they COULD damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [SELECT]KillAll::

      Folder::
      C:\Program Files\MSA
      C:\Program Files\PCHealthCenter
      C:\Program Files\kaqumad
      C:\Documents and Settings\All Users\Application Data\kzyjehex

      File::
      C:\WINDOWS\system32\phc33qj0et1e.bmp
      C:\WINDOWS\system32\lphc33qj0et1e.exe
      C:\WINDOWS\system32\blphc33qj0et1e.scr
      C:\WINDOWS\system32\pqhuvqxi.exe
      C:\WINDOWS\system32\VIE4.exe
      C:\WINDOWS\system32\VIE5.exe
      C:\WINDOWS\system32\VIE3.exe
      C:\WINDOWS\system32\VIE17.exe
      C:\WINDOWS\system32\VIE19.exe
      C:\WINDOWS\system32\VIE1A.exe
      C:\WINDOWS\system32\bczmjsjo.exe
      C:\WINDOWS\system32\VIE8.exe
      C:\winlo.exe
      C:\WINDOWS\system32\2.ico
      C:\WINDOWS\system32\MSA.cpl
      C:\WINDOWS\system32\1.ico
      C:\WINDOWS\system32\jkxcbafw.exe
      C:\WINDOWS\system32\20.tmp
      C:\WINDOWS\system32\sbcpgrir.exe
      C:\WINDOWS\system32\17.tmp
      C:\WINDOWS\system32\xktabeve.exe
      C:\WINDOWS\system32\wdxb.dll
      C:\Program Files\kaqumad\dscuiwin.dll
      C:\WINDOWS\system32\VIEF.exe

      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ActProcWeb"=-
      "chkdbadm"=-
      "\VIE5.exe"=-
      "\VIE3.exe"=-
      "\VIE8.exe"=-
      "ComChk"=-
      "\VIE17.exe"=-
      "\VIE19.exe"=-
      "\VIE1A.exe"=-
      "\VIE4.exe"=-
      "winset"=-
      "\VIEF.exe"=-
      "\VIE13.exe"=-

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Antivirus"=-
      "\VIE5.exe"=-
      "\VIE3.exe"=-
      "\VIE8.exe"=-
      "lphc33qj0et1e"=-
      "\VIE17.exe"=-
      "\VIE19.exe"=-
      "\VIE1A.exe"=-
      "\VIE4.exe"=-
      "\VIEF.exe"=-
      "\VIE13.exe"=-

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
      "WE0Sw06TVc"=-

      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI'm not 100% sure this is going to be the correct log, as my computer froze up with a bunch of pop ups. If I need to do something else, or run something again, just let me know.

      Again I can't thank you enough for taking the time to help me!

      [recovering disk space -- attachment deleted by admin]You really need to run these instructions and post the log ASAP. The malware has regenerated and added more rouge files.

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Delete these files/folders, as follows:

      1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
      It must be Notepad, not Wordpad.
      2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

      Code: [Select]KillAll::

      Folder::
      C:\x

      File::
      C:\WINDOWS\system32\YUR2.exe
      C:\WINDOWS\system32\YUR7.exe
      C:\WINDOWS\system32\YUR4.exe
      C:\WINDOWS\system32\gzorudqn.exe
      C:\WINDOWS\system32\uhglwtmd.exe

      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "DscSet"=-
      "\YUR2.exe"=-
      "\YUR4.exe"=-
      "\YUR7.exe"=-

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "\YUR2.exe"=-
      "\YUR4.exe"=-
      "\YUR7.exe"=-

      3. Go to the Notepad window and click Edit > Paste
      4. Then click File > Save
      5. Name the file CFScript.txt - Save the file to your Desktop
      6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



      ComboFix will begin to execute, just follow the prompts.
      After reboot (in case it asks to reboot), it will produce a log for you.
      Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI apologize, I'll work on it tonight until you let me know it's ok to shut down for the EVENING. When I do shut down, should I turn my computer off completely and unhook the modem, or doesn't that matter?

      [recovering disk space -- attachment deleted by admin]We should be OK after this next scan, but we will have to see.

      Do you know what this is? C:\x



      No, I'm sorry I don't. Pretty sure it is a rouge folder that needs to go. ComboFix couldn't delete it so we will use another tool.

      Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Now download The Avenger by Swandog46 and save it to your Desktop.

      • Extract avenger.exe from the Zip file and save it to your Desktop
      • Run avenger.exe by double-clicking on it.
      • Do not change any check box options!!
      • Copy everything in the Code box below, and paste it into the Input script here window:
      Code: [Select]Comment:

      Folders to delete:
      C:\x

      • Now click the Execute button.
      • Click Yes to the prompt to confirm you want to execute.
      • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
      • Your PC should reboot, if not, reboot it yourself.
      • A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
      • Add the Avenger log in your next post.
      .
      ----------

      Also, now run a new HijackThis scan and post the log. Let me know how the PC is doing as well.Here are the logs, it seems that the pop ups have stopped and that it is running ok for now.

      Do I need to save the old logs for anything, I just have them on my desktop but I didn't know if I should delete them or not?

      [recovering disk space -- attachment deleted by admin]We will do some cleanup now. If any logs are left over then they can be deleted.

      Did you add this to the Desktop yourself? If so it's OK.
      O24 - Desktop Component 0: (no name) - C:\Documents and Settings\eric\My Documents\limehead2.gif

      These are final steps. If you have any questions then just ask.

      ----------

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      .
      .
      The above procedure will:
      • Delete:
        • ComboFix and its associated files and folders.
        • VundoFix backups, if present
        • The C:\Deckard folder, if present
        • The C:_OtMoveIt folder, if present
        • Reset the clock settings.
        • Hide file extensions, if required.
        • Hide System/Hidden files, if required.
        • Set a new, clean Restore Point.
        .
        ----------

        Download OTCleanIt.exe and save it to your Desktop.
        • Double-click OTCleanIt.exe.
        • Click the CleanUp! button.
        • Select Yes when the "Begin cleanup Process?" prompt appears.
        • If you are prompted to Reboot during the cleanup, select Yes.
        • The tool will delete itself once it finishes, if not delete it yourself.
        .
        ----------

        Now run CCleaner.

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all CRITICAL updates.

        ----------

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.I'm working on all the updates right now. If I have any other questions before I get everything done, should I ask you here, or post a new thread on the forum?

        Again, I can't say thank you enough for all of your help and patience, I really do appreciate it!Go ahead and ask here.

        No problem on the help....it's why we're here.I did forget to ask about all of the antispyware and antimalware programs that I downloaded, do I delete those now, or do they need to stay on my computer?

        Also, the antivirus software that I have is from 2003 and may be outdated, should I download something new or leave it as is?
        3142.

        Solve : Computers running slow?

        Answer»

        Hey everyone , was wondering if anyone could TAKE a look at my log .

        Thanks

        Scanned with all spyware , and my anti virus no luck finding anything .

        Logfile of HIJACKTHIS v1.99.1
        Scan saved at 18:56:56, on 29/08/2008
        Platform: Unknown Windows (WinNT 6.00.1905 SP1)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Thomson\ST330\diagnostics\diagnostics.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Microsoft IntelliType Pro\itype.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Xfire\xfire.exe
        C:\Program Files\Steam\Steam.exe
        C:\Program Files\AVG\AVG8\avgtray.exe
        C:\Program Files\AVG\AVG8\avgui.exe
        C:\Program Files\AVG\AVG8\avgscanx.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O4 - HKLM\..\Run: [diagnostics] "C:\Program Files\Thomson\ST330\diagnostics\diagnostics.exe" /icon -l:en
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
        O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\RESTRICTIONS present
        O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control PANEL present
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
        O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
        O11 - OPTIONS group: [INTERNATIONAL] International*
        O13 - Gopher Prefix:
        O17 - HKLM\System\CCS\Services\Tcpip\..\{86478BC7-980B-4B72-9C39-04E362FBCD94}: NameServer = 212.139.132.9 212.139.132.8
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O20 - AppInit_DLLs: avgrsstx.dll
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
        O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
        O23 - Service: SpeedTouch 330 Manager (st330service) - THOMSON Telecom Belgium - C:\Program Files/Thomson/ST330/service/st330service.exe
        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
        O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

        Hm, I don't see anything malicious in your log. I see no reason to think that your speed is a malware issue. You do, however, have these two restrictions...

        O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present


        Did you set these yourself?

        3143.

        Solve : Possibly infected with Win 2008 virus?

        Answer»

        Dell Dimension 8400, Windows XP SP 3, Norton Internet Security 2008. Everything is current and updated. Could you look over these files and see if i'm clean. I thought i may have opened a bad email inerror and got infected but the scans didn't find anything. I trust the malware FOLKS in this forum, as i've followed many threads and you guys do excellent work. Logs are too big to fit here, so i'll add them to next post or two.alwarebytes' Anti-Malware 1.25
        Database version: 1062
        Windows 5.1.2600 Service Pack 2

        9:39:37 AM 8/19/2008
        mbam-log-08-19-2008 (09-39-37).txt

        Scan type: Quick Scan
        Objects scanned: 50783
        Time elapsed: 6 minute(s), 17 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 2
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 2

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8ca5ed52-f3fb-4414-a105-2e3491156990} (Trojan.BHO) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{8ca5ed52-f3fb-4414-a105-2e3491156990} (Trojan.BHO) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\Documents and Settings\Richard\Local Settings\Temp\CmdLineExt02.dll (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Program Files\iWin Games\iWinGamesHookIE.dll (Trojan.BHO) -> Delete on reboot.
        UPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 09/02/2008 at 03:09 PM

        Application Version : 4.15.1000

        Core Rules Database Version : 3554
        Trace Rules Database Version: 1542

        Scan type : Complete Scan
        Total Scan Time : 01:18:46

        Memory items scanned : 503
        Memory threats detected : 0
        Registry items scanned : 6886
        Registry threats detected : 0
        File items scanned : 119431
        File threats detected : 0
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 3:14:17 PM, on 9/2/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\CTsvcCDA.EXE
        C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
        C:\Program Files\iWin Games\iWinGamesInstaller.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
        C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\MsPMSPSv.exe
        C:\WINDOWS\system32\fxssvc.exe
        C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
        C:\WINDOWS\system32\Rundll32.exe
        C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
        C:\WINDOWS\system32\dla\tfswctrl.exe
        C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
        C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe
        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\sniper.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://www.comcast.net/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.comcast.net/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
        R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
        O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
        O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
        O2 - BHO: Symantec Intrusion PREVENTION - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0427.0\msneshellx.dll
        O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
        O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
        O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
        O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
        O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0427.0\msneshellx.dll
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
        O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
        O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
        O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
        O4 - HKLM\..\Run: [eligmini] C:\Program Files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe 0
        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-21-2329528624-2373486969-3315347067-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Candie')
        O4 - HKUS\S-1-5-21-2329528624-2373486969-3315347067-1008\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Candie')
        O4 - S-1-5-21-2329528624-2373486969-3315347067-1008 STARTUP: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe (User 'Candie')
        O4 - S-1-5-21-2329528624-2373486969-3315347067-1008 User Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe (User 'Candie')
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: BLOG This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
        O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
        O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
        O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v44/scrabblecubes/scrabblecubes.cab
        O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
        O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/stg_drm.ocx
        O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab
        O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://playgames.comcast.net/online2/pirate_poppers/PiratePoppers.1.0.0.32.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1212177041812
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116455882406
        O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
        O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} (SpinTop Games Launcher) - http://playgames.comcast.net/online2/mystery_solitaire/SpinTopGamesLauncher.cab
        O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/amun/default/mjolauncher.cab
        O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
        O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx
        O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
        O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
        O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
        O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

        --
        End of file - 15034 bytes

        3144.

        Solve : Safety of NetFxUpdate?

        Answer»

        I don't know if my having upgraded my ancient Windows XP Home Edition laptop to Service PACK 2 on Sunday night is relevant but I want to mention it.

        During its installation, Spybot Search and Destroy asked me to ALLOW quite a lot of changes and I permitted them all.

        At the moment, I am just browsing some web pages, using Firefox, and Spybot has detected ----->

        System Startup global entry
        Value added
        NetFxUpdate_v1.1.4322
        in
        C:WINDOWS\Microsoft.NET\Framework
        and is asking me whether to accept this.
        I haven't deliberately installed any programs this MORNING. Oh ! While I was typing this a box has appeared asking me to re-start my PC. Is this all "normal" when using Automatic Updates from Microsoft now that I have SP2 ?

        How will I ever know that the downloads and alterations are O.K ?
        Perhaps - I should switch to Manual Updates so that I am EXPECTING queries......and my PC won't be switched off if I'm not there to notice that it could be and stop it.Not sure exactly what you mean.

        When I update my computer via Windows Update, it prompts me to restart.I've found that I can change the Windows Update settings in System Properties in the Control Panel so that I can be notified before downloading or installing anything.

        I prefer that.When using Windows Update it is always best to turn off TeaTimer and sometimes even your antivirus and firewall. TeaTimer is a PITA when it comes to Windows Updates. Actually it is a PITA in GENERAL and I NEVER advise anybody to use it.

        How to Disable Spybot's TeaTimer

        3145.

        Solve : UPS trojan?

        Answer»

        Sorry I haven't had much input, you seem to have some of the most unique cases EVER. *Not ENVIOUS

        Hope the GOLF is good!

        3146.

        Solve : www.Actualkeylogger.com (monitor.win32.actualspy)?

        Answer»

        I tried to install this program but my virus scanner PICKED it up and SUGGEST i delet the file. The options were to either Quarantine, delete the INFECTED file, exclude from scan or do nothing. Does anyone use it and if so is it safe to install?um well its a keylogger it loggs keystrokes so i DONT think that should be discussed hereIt's not that kind of Keylogger computerruler. It's the type you use on your computer to monitor your families use. So you can know what they're visiting, etc.

        No need to get to into the discussion of it's uses on your own computer.You have to let the antivirus allow it. Quote from: sjn2009 on August 29, 2008, 06:33:11 PM

        It's not that kind of Keylogger computerruler. It's the type you use on your computer to monitor your families use. So you can know what they're visiting, etc.

        No need to get to into the discussion of it's uses on your own computer.

        Where's the family trust?
        3147.

        Solve : Malware help PLEASE....?

        Answer»

        I'm running my computer on Windows XP SP2. I plugged in a pendrive that I got from my friend and my computer got infected. Explorer was shutting down, and even if I check the "Show Hidden files and Folder" radio button in Tools->Folder Options, hidden files were not being shown. From M Computer, when I clicked on drives, they were being opened from a new Explorer window. I formatted my C: and reinstalled the OS. However, the problem has persisted. I installed AVAST and right now, it is giving me a "Malware Was FOUND" warning for mnl6on3.com for drives C, D, E, F, G, H (all my drives) as Malware name Win32:Rootkit-gen [Rtk] and classification Rootkit.


        Sometimes, none of the drives open, and I have to browse to Windows Explorer using Open With. Yesterday, I was getting an Malware warning for klif.sys everytime I tried to open C Drive. And Avast gave about 10 Malware warnings repeatedly for files in System Volume Information for all the drives.

        Following the instructions given in this forum, I have installed Avast, CCleaner, SUperAntispyware, Malwarebytes Anti-Malware and HijackThis.

        It appears I can enable Hidden folders now, but I still have to associate the drives with Windows Explorer using Open With every time I want to browse to it from My Computer.

        ckvo is there in the startup.

        SuperAntispyware and MBAM logs are attached.

        [recovering disk space -- attachment deleted by admin]HijackThis log:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 9:22:02 PM, on 9/2/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\RTHDCPL.EXE
        C:\WINDOWS\ALCFDRTM.EXE
        C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
        C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
        C:\Program Files\Trend Micro\HijackThis\sniper.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O20 - Winlogon NOTIFY: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

        --
        End of file - 2941 bytes
        Download Deckard's Association File Tool (DAFT) and save it to your desktop.

        • Double-click the daft.exe icon. Read the disclaimer and click OK
        • Click on the Scan button.
        • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a tick in the boxes in question.
        • Click the Fix button.
        • Re-scan and save a logfile.
        • By default, it will save as daft.txt
        • Post the contents of that logfile in your next reply.
        .
        ----------

        Run this Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

        Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

        Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

        Exit out of MessengerDisable then delete the two files that were put on the Desktop.

        ----------

        Let me know how things are now.The content of the daft log:

        DAFT Log saved on 2008-09-03 02:16:47
        -----------------------------------------------------------------------
        All associations okay!




        Everything seems to be fine now. I deleted autorun files on each drive that were point to mnl6on3.com. Thanks a lot, Man!! Windows Explorer association is also okay now.No problem, LOOKS like your associations got messed up somehow.

        Here are a few things you MAY want to do.

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.
        3148.

        Solve : Help the broken Tosh!?!? :-) Trojan.Packed.Execryptor on Windows XP SP3?

        Answer»

        kdfmgr is not malware. It's part of your Trend Micro Internet Security.OMG so he has no idea what he is on about then?
        Doesn't look like it.

        Who told you that?This tech on Trend's live help. Use the VirusTotal.com - Multi engine on-line virus scanner
        (If more than one file needs scanned they must be done separately and logs posted for each one)

        • Copy the file path in the below Code box:
        Code: [Select]C:\Windows\System32\kdfmgr.exe
        • At the upload site, click once inside the window next to Browse.
        • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
        • Next click Send File
          • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
        • This will perform a scan across multiple different virus scanning engines.
        • Important: Wait for all of the scanning engines to complete.
        • Copy and then Paste the link to the results in the next reply.
        Interesting!!

        File has already been analysed:
        MD5: dfc27f9e103c5203538cc7741251949b
        First received: 11.15.2007 18:03:28 (CET)
        Date: 08.21.2008 17:32:00 (CET) [>9D]
        Results: 5/36
        Permalink: analisis/dc033d3dec7f506d6e70b3c251d8d2c2
        Antivirus Version Last Update Result
        AhnLab-V3 2008.8.29.0 2008.08.29 -
        AntiVir 7.8.1.23 2008.08.30 -
        Authentium 5.1.0.4 2008.08.30 -
        Avast 4.8.1195.0 2008.08.30 -
        AVG 8.0.0.161 2008.08.30 -
        BitDefender 7.2 2008.08.30 -
        CAT-QuickHeal 9.50 2008.08.29 (Suspicious) - DNAScan
        ClamAV 0.93.1 2008.08.30 -
        DrWeb 4.44.0.09170 2008.08.30 -
        eSafe 7.0.17.0 2008.08.28 Suspicious File
        eTrust-Vet 31.6.6057 2008.08.29 -
        Ewido 4.0 2008.08.30 -
        F-Prot 4.4.4.56 2008.08.29 -
        F-Secure 7.60.13501.0 2008.08.30 Suspicious:W32/Malware!Gemini
        Fortinet 3.14.0.0 2008.08.30 -
        GData 19 2008.08.30 -
        Ikarus T3.1.1.34.0 2008.08.30 -
        K7AntiVirus 7.10.433 2008.08.30 -
        Kaspersky 7.0.0.125 2008.08.30 -
        MCAFEE 5373 2008.08.29 -
        Microsoft 1.3807 2008.08.25 -
        NOD32v2 3401 2008.08.30 -
        Norman 5.80.02 2008.08.29 -
        Panda 9.0.0.4 2008.08.30 -
        PCTools 4.4.2.0 2008.08.30 -
        Prevx1 V2 2008.08.30 -
        Rising 20.59.51.00 2008.08.30 -
        Sophos 4.33.0 2008.08.30 Sus/ComPack
        Sunbelt 3.1.1592.1 2008.08.30 -
        Symantec 10 2008.08.30 -
        TheHacker 6.3.0.6.068 2008.08.30 -
        TrendMicro 8.700.0.1004 2008.08.29 -
        VBA32 3.12.8.4 2008.08.30 -
        ViRobot 2008.8.30.1357 2008.08.30 -
        VirusBuster 4.5.11.0 2008.08.30 -
        Webwasher-Gateway 6.6.2 2008.08.30 Virus.Win32.FileInfector.gen (suspicious)
        Additional information
        File size: 722472 BYTES
        MD5...: dfc27f9e103c5203538cc7741251949b
        SHA1..: d6e03094b38e0643f02a58bdda391a0b7b6f70a 9
        SHA256: 3915f3c01a941306a65cf6280a0cb7363dcd69d 9e7a954a3d74a37e871c3b46e
        SHA512: 19bc1c09075ff8948f4223c71bd574de8912a4f fdffa71abc33f136547e89454
        cb61c4139c24fee9fe46e7ddd9bb5601c3c0e34 6396747980a658210e48e7296
        PEiD..: UPX v1.03 - v1.04
        TrID..: File type identification
        Win32 Executable Generic (42.3%)
        Win32 Dynamic Link Library (generic) (37.6%)
        Generic Win/DOS Executable (9.9%)
        DOS Executable Generic (9.9%)
        Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
        PEInfo: PE Structure information

        ( base data )
        entrypointaddress.: 0x49e573
        timedatestamp.....: 0x46df868c (Thu Sep 06 04:48:12 2007)
        machinetype.......: 0x14c (I386)

        ( 7 sections )
        name viradd virsiz rawdsiz ntrpy md5
        .text 0x1000 0x19000 0x19000 6.71 528b410618f8507d929805b1051f1a6f
        .rdata 0x1a000 0x5000 0x5000 4.96 276806fd758f7dd1b20540bc5185d149
        .data 0x1f000 0x6000 0x3000 4.23 3cda64e68fdebf5af68177249a223466
        .rsrc 0x25000 0x69000 0x69000 5.76 e1c8154f2bbe78b1ec042e5b783eaf86
        13c2q.c. 0x8e000 0x3000 0x3000 4.60 9ef52caf3b18b14a916a1b735df7160e
        8o42fxd9 0x91000 0x21000 0x20ba2 6.67 a48c6accf5ee4afb376a07acc039bc4d
        0si31ee8 0xb2000 0x1000 0x1000 7.96 8c479de81d17284f4a4ffd9302de8849

        ( 6 IMPORTS )
        > VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
        > KERNEL32.dll: DeviceIoControl, GetPrivateProfileStringA, ExitThread, SleepEx, SetEvent, Sleep, SetThreadPriority, CreateThread, CreateEventA, WaitForSingleObject, ReleaseMutex, GetTickCount, LocalFree, CreateMutexA, MapViewOfFile, CreateFileMappingA, UnmapViewOfFile, GetHandleInformation, GlobalMemoryStatus, WriteConsoleA, SetEnvironmentVariableA, CompareStringW, CompareStringA, SetFilePointer, InitializeCriticalSection, ReadFile, FlushFileBuffers, GetConsoleMode, GetConsoleCP, SetStdHandle, GetTimeZoneInformation, GetLocaleInfoA, GetVersion, GetStringTypeA, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetModuleFileNameA, HeapReAlloc, HeapCreate, HeapDestroy, HeapSize, ExitProcess, DeleteCriticalSection, GetFileType, GetStdHandle, SetHandleCount, LeaveCriticalSection, EnterCriticalSection, GetCurrentDirectoryA, GetFullPathNameA, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, LCMapStringW, MultiByteToWideChar, WideCharToMultiByte, LCMapStringA, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, IsValidCodePage, GetOEMCP, GetACP, InterlockedDecrement, GetSystemInfo, GetModuleHandleA, GetCurrentProcess, GetVersionExA, GetCurrentProcessId, GetCurrentThreadId, GetSystemDefaultLangID, GetUserDefaultLangID, OpenMutexA, GetLastError, GetWindowsDirectoryA, GetSystemDirectoryA, LoadLibraryA, GetProcAddress, DeleteFileA, FindResourceA, LoadResource, LockResource, GetFileAttributesA, SetFileAttributesA, CreateFileA, SizeofResource, WriteFile, CloseHandle, FreeLibrary, GetConsoleOutputCP, WriteConsoleW, SetEndOfFile, GetStringTypeW, InterlockedIncrement, GetCPInfo, GetStartupInfoA, GetProcessHeap, ResumeThread, GetPriorityClass, OpenProcess, VirtualAlloc, VirtualFree, SetLastError, CreateRemoteThread, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, GetDriveTypeA, FindFirstFileA, RtlUnwind, GetSystemTimeAsFileTime, HeapFree, HeapAlloc, RaiseException, GetCommandLineA
        > USER32.dll: FindWindowExA, GetWindowRect, SetWindowPos, GetDC, BeginPaint, EndPaint, RELEASEDC, DestroyWindow, UnregisterClassA, GetWindowTextA, GetWindow, GetKeyboardState, ToAscii, SendInput, MapVirtualKeyExA, GetKeyboardLayout, MapVirtualKeyA, MessageBoxA, GetKeyState, LoadStringA, GetMessageA, TranslateMessage, DispatchMessageA, LoadIconA, LoadCursorA, RegisterClassExA, GetFocus, InSendMessage, ReplyMessage, PostQuitMessage, DefWindowProcA, IsWindow, CreateDialogParamA, EndDialog, GetCursorPos, GetForegroundWindow, SetForegroundWindow, PostMessageA, KillTimer, EnumWindows, GetClassNameA, AttachThreadInput, SetTimer, CreateWindowExA, ShowWindow, UpdateWindow, FindWindowA, GetWindowThreadProcessId, LoadImageA, wsprintfA, OpenInputDesktop, GetUserObjectInformationA, CloseDesktop
        > GDI32.dll: GetObjectA, GetDeviceCaps, CreateCompatibleDC, BitBlt, SelectObject, DeleteDC, DeleteObject, CreateCompatibleBitmap
        > ADVAPI32.dll: OpenSCManagerA, StartServiceA, CreateServiceA, OpenServiceA, ChangeServiceConfigA, CloseServiceHandle, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, GetSecurityDescriptorSacl, GetCurrentHwProfileA
        > SHELL32.dll: ShellExecuteA, SHGetSpecialFolderPathA, Shell_NotifyIconA

        ( 0 exports )

        ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=dfc27f9e103c5203538cc7741251949b
        packers (Kaspersky): PE_Patch
        packers (F-Prot): EXECryptor
        Quote
        TrendMicro 8.700.0.1004 2008.08.29 -

        Not a malicious file.Hey Kevin
        Im done with my poor Tosh performing like this hey and have no patience left to try and work out what is wrong with it.
        been reading online (even others you guys are helping) and there sounds like quite a number of ppl experiencing similar probs to what i am, no one appears to know WHAT the issue is or how to reslove it - unless you are an IT Guru.
        If someone told me 3 wks ago to do thise 20 step process that is around the place and that would fix it i would have given it a shot but since downloading a thousand different antivirus programs. installing/unistalling restarting, have run check disc on startup 3 TIMES, attempted to restore 6 times that all failed. Im over it.
        Can I just reinstall Windows? Will that fix this? You think it will work?
        Cheers
        M
        You might consider a reinstall. That is usually the only guaranteed way to get things back to normal. It might be a Hard Drive issue or something like that.

        You can look through and try any of the suggestions found here > Slow Computer? It May Not Be Malware
        3149.

        Solve : How to uninstall CA Internet Security Suite??

        Answer»

        Hello-

        My laptop recently got hit twice with trojan/malware (first VirusHeat then the XP 2008 or what ever it was called) thanks to my daughter. It thought I had manually gotten rid of them, but apparently I hadn't. First the computer got slower. Then I got a notification from TimeWarner Cable that apparently "emails with the characteristics of SPAM" were being sent from my cable address. Yesterday I started getting BSOD's indicating SESSION5_INITIALIZATION_FAILED blah blah. This was on startup. The only way I could get the computer started was either in safe mode or by selecting "start in the most recent configuration that worked." Google searches seemed to indicate that this SESSION5_... issue was one of the things fixed with XP Sp3 (the lap top is currently Sp2). But something was preventing me from getting the Windows Update for XP3.

        All during this time, I noticed that the LED on the router corresponding to the port it was plugged into was always constantly blinking at a regular about 1X second rate. The LEDs for the other 2 computers and the printer do not blink regularly like this. This probably was an indication that the lap top was constantly pumping something out when it was on.

        In the information from TimeWarner regarding their warning, it gave a bunch of things to try. The first thing I tried was McAfee Stinger. The malware was preventing me from downloading it so I downloaded it to another computer, copied it to a thumb drive, and copied it to the lap top that way. I ran it. It indicated that the "dropper" programs where in phony MP3 files that my daughter said she had gotten from Limewire. It deleted them. After running about 10 minutes, Stinger bombed out and just disappeared with no trace. I tried to run it several times, always after about 10 minutes, it bombed out and disappeared. The first time I ran it in normal mode. The subsequent runs were in safe mode, same deal.

        Then I tried Trend Micro Housecall. This didn't find anything and also quit back to the desktop after about 5 minutes.

        Then I tried the Microsoft Malicious Software Removal Tool The latest version of this also could not be downloaded by the lap top so I again downloaded it elsewhere and copied it over with a thumb drive. I ran this and after about 15 minutes, it too bombed. This time it gave the "Microsoft Windows Malicious Software Removal Tool has encounterd a problem and needs to close Version 2.1.2407.0 etc... etc... SEND error report to Microsoft?..." pop up. I tried several times and always the same thing. It never found anything during the time it was running either.

        Then I got Malwarebytes Anti-Malware, for some reason I could get this one to download directly with the lap top. I got the latest updates, and ran the quick scan. It found 30 infected files and folders. It could delete all but two of them which it said would be deleted on restart. I did that and these last two were in fact deleted. I ran it several more times and it reported all clean each time. It said that the malware I had was a keylogger and something that messes with the internet connection. This was probably why I couldn't download the programs.

        After running these quick scans, TimeWarner suggested installing an anti-virus program. CA Internet Security Suite is free for TW customers so I downloaded it and installed it. It indicated that it needed to run a scan so I let it. It found 9 more infected files and deleted them. Then after about an hour of running, I got a BSOD with the computer locked up. This time the screen indicated STOP: 0x000008E and a problem with KmxFile.sys. and an address. I restarted the computer and now after logging in, it goes straight to the BSOD. It will start in safe mode. Running the earlier configuration that worked does now not work. In normal mode it always goes to the blue screen error after booting up. A Google search of kmxfile.sys indicates that it is a CA component. So now the computer is unusable thanks to this CA program.

        Does anyone know how to uninstall CA Internet Security Suite? I see no uninstall options anywhere.

        Thanks!
        KmxFile.sys is part of the CA firewall I'm pretty sure. Firewalls can be heavy on resources and the STOP error is memory related I think. Did you uninstall your other antivirus and or firewall before installing CA?

        Have you tried in Add or Remove Programs to uninstall it?

        Go to Removal Tools and Methods for Uninstalling Major Antivirus Products and scroll to CA Internet Security for instructions.

        See if you can get a HijackThis log posted.

        Download TrendMicro HijackThis.exe (HJT)

        • Double-click on HJTInstall.
        • Click on the Install button.
        • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
        • Upon install, HijackThis should open for you.
        • Click on the Do a system scan and save a log file button
        • HijackThis will scan and then a log will open in notepad.
        • Copy and then paste the entire contents of the log in your post.
        • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
        Yes kmxfile.sys is definitely part of CA ISS.

        1) From safe mode, I tried to Add/Remove CA ISS. The screens look like what is shown in the link you provided. It said it couldn't remove the anti-virus part or the firewall part but it did remove the anti-spamware part. Still got BSOD after logging in in normal mode. I'm wondering if it couldn't uninstall those components because it was in safe mode.

        2) Looking at the Add/Remove list, I saw that Malwarebytes Anti-Malware installed itself. I had thought that it was a standalone run once sort of program that didn't install itself. So I uninstalled that. Still got BSOD after logging in in normal mode.

        3) What about Windows Firewall? It is there but not enabled (and hasn't been for a while). Does that have to be actually uninstalled?

        4) I can't download HiJack This because the computer will only run in safe mode. The BSOD happens as all the drivers and little icons in the lower right are filling in before I can get a chance to do anything.

        The most recent time I tried to boot it to normal mode, instead of logging in, I clicked turn computer off. Somehow Windows snuck in and said there were a bunch of updates that it said it was going to do before TURNING off. So those ran their course. Then I tried going back to normal mode again, still the same BSOD.

        So essentially the computer is currently unusable.

        Thanks.
        Can you do a System Restore?If you mean the selection "Last Known Good Configuration (your most recent settings that worked)" from the F8 boot up screen, no. That doesn't fix it.Try going in and deleting the CA folder in Program Files. Honestly I'm sort of baffled at the moment on what's going on.Well very strange. This lap top has 3 accounts on it. One has administrator privileges, and the other 2 have the lowest level of privileges. I had always been using the administrator because that's were you can control everything from. But I figured what the hey, and tried to log into one of the other accounts to see what would happen. Lo and behold it booted up fine. Applications ran fine and I could go to websites with Firefox. No BSOD. And the parts of CA ISS that remained (anti-spyware and firewall) after I tried to uninstall it in safe mode were still there and actually running. The firewall was blocking all sorts of things and giving notifications.

        So, from the CA ISS main screen I selected help and there was a CA support web address given (I didn't write it down). I went there and one of the choices is uninstall. I clicked it and it downloaded something to the desk top and ran. Judging by the things that flashed by, it modified stuff in the registry. Then it said to shut down and restart for the uninstall changes to take effect. I did this and logged into the administrator account instead. The CA firewall logo was still up and it now popped up the firewall notifications. And it didn't crash to the BSOD here either. Again I could go to the Internet, and applications worked. But it appeared that ISS had not been fully removed. So I went to Control Panel add/remove programs and it showed as still being there so I selected to uninstall and it cleanly uninstalled all of it. So now it is gone and the computer seems to be working.

        Next I'm going to get XP Sp3 loaded. Windows Update is now causing problems, not finishing and giving "error code: 0xD0000005" Google for this doesn't turn up much useful. So I am going to try the Microsoft Support for that. They say live help is free for Update issues.

        Then I will clean up the hard drive, get rid of all the temp stuff, and maybe re-run Malwarebytes again just to be sure. It seemed to have been the most effective at getting rid of the the associated junk that VirusHeat and XP Antivirus 2008 dumped on the system. The Malwarebytes log included the following classifications of nastiness that it found and deleted:

        rogue.virusheat
        rogue.multiple
        rogue.antivirus2008
        rogue.link
        trojan.fakealert
        trojan.zlob
        hijack.wallpaper
        hijack.displayproperties
        spyware.passwords
        rootkit.dnschanger.h

        The last two are obviously the most troubling. Luckily I never use this computer for accessing bank information and the like. And the filename that was the rogue.link was called "online security test.url". Hah.

        It must have been all the different things that I did while trying to remove this stuff that broke CA ISS and also the Windows Update. The saga is not done yet. After I can get XP Sp3 installed, I may give the CA another try. Or maybe AVG.

        It's amazing to me that the most popular operating system in the world is the one that is the most vulnerable to exploits like this. I also have a W98 SE machine that I've used for over 8 years and it has never gotten anything like this.

        I HOPE all this detail that I have written might help someone else in this situation.

        Thanks for the suggestions.
        There have been some different variations of virus lately that are COMPLETELY crippling systems laving reinstalling the only option. Hopefully MS will help you get the updates fixed.

        Be sure you are 100% free of malware before installing SP3. If not it will cause big problems.

        MalwareBytes is a very good application. That along with your antivirus is all most will ever need.
        3150.

        Solve : A quick check of HJT please guys?!...?

        Answer»

        Hey guys, could SOMEONE please run over this:
        Though during the scan 2 error messages did crop up, they have been attached:
        Anyway here is the scan log, pretty sure its clean, but hey ho, im no expert.

        Logfile of HijackThis v1.99.1
        Scan saved at 18:53:06, on 27/08/2008
        Platform: Unknown Windows (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16681)

        Running PROCESSES:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Windows Media Player\WMPNSCFG.exe
        C:\Windows\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Users\Sam\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDMC6QVV\VundoFix[1].exe
        C:\Users\Sam\Downloads\HijackThis.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avfc.premiumtv.co.uk/page/Home
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.thetechguys.com/welcome
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [UpdateP2GShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe "C:\Program Files\CyberLink\Power2Go" update "SOFTWARE\CyberLink\Power2Go\5.0"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
        O11 - Options group: [INTERNATIONAL] International*
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://click.getmirar.com (HKLM)
        O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
        O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (PERFORMANCE Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
        O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
        O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
        O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

        Thanks very much in advance

        Chris

        [recovering disk space -- attachment deleted by admin]Please post a log from the new version of HJT.

        TrendMicro HijackThis.exe (HJT)

        Also did you add these to the Trusted Zones?

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 13:11:23, on 29/08/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avfc.premiumtv.co.uk/page/Home
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.thetechguys.com/welcome
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [UpdateP2GShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe "C:\Program Files\CyberLink\Power2Go" update "SOFTWARE\CyberLink\Power2Go\5.0"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://click.getmirar.com (HKLM)
        O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
        O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

        --
        End of file - 5561 bytes


        No I didint add them, I just did a quick Google Search of 'Mirar' though and it appears to be somesort of Ad-ware.

        Thanks alot
        Peace
        ChrisOpen HijackThis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        O15 - Trusted Zone: http://click.getmirar.com (HKLM)
        O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
        O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)


        IMPORTANT: Close all windows except for HijackThis and then click Fix checked.

        Exit HijackThis and restart the computer to register the changes MADE by HijackThis.

        ----------

        Your Java is out of date.

        Older versions have vulnerabilities that malicious sites can use to infect your system.

        Download JavaRa and unzip it to your desktop.

        • Double-click on JavaRa.exe to start the program.
        • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
        • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
        • A logfile will pop up.
        • Delete the JavaRa .zip .exe and .html files from the Desktop
        .
        Follow this link to download and install Java Runtime Environment (JRE) 6 Update 7

        ----------

        Everything OK now?

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 13:11:23, on 29/08/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.avfc.premiumtv.co.uk/page/Home
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.thetechguys.com/welcome
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [UpdateP2GShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe "C:\Program Files\CyberLink\Power2Go" update "SOFTWARE\CyberLink\Power2Go\5.0"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O13 - Gopher Prefix:
        O15 - Trusted Zone: http://click.getmirar.com (HKLM)
        O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
        O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

        --
        End of file - 5561 bytes


        Yea everything seems fine now, laptop boots up much quicker and all now.
        Thanks alot!!!!
        Much appreciates
        Bless

        Chris