Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3651.

Solve : How to remove coolwwwsearch.toolband?

Answer»

Hi,

I have just purchased a new PC and am using Window 7. As I was scanning the PC with SPYBOT, it tells me I have 3 coolwwwsearch.toolband trojan on the computer. I have tried removing them but Spybot keeps telling me it cannot REMOVE them.

Can someone TELL me what this trojan does and how to remove it?

Thanks in advance.Go here...

http://www.malwarebytes.org/mbam.php

Download the free version. Install & run.

Alan &LT;&GT;<

3652.

Solve : Free AVG anti-virus - I can't find it?

Answer»

Can you tell me how to find AVG to be sure I have it installed? I looked at "programs" and it isn't there.
Someone told me to re-INSTALL it, and if I already had it, it wd tell me.
But when I try to install it, I click on "download" and nothing happens.

thanks

ellenIf you don't SEE it in your Programs and you have not icon for it in the lower RIGHT corner of your screen, then you don't have it installed.

Quote

But when I try to install it, I click on "download" and nothing happens.
That statement doesn't make much sense. You need to download first, then install it. You can get it at http://free.avg.com/us-en/homepageI click on download free.
I get a msg box that says:
"Opening avg_free_stb_all_9_40_cnet.ex"

The box asks "Would you like to save?"

There is no option except "save" or cancel.

I save.

the screen says thanks for downloading AVG but there is no AVG icon and no avg program listed under "all programs".

?

thanks,
ellenI just a msg in my inbox:

"AVG Anti-Virus Free EDITION 9.0.704

Thanks for downloading the latest version of AVG Anti-Virus Free Edition 9.0.704. "

You say, after I download, I install - how do I do that?
and where is it?

Dang, last time I installed avg, it sure wasn't this complicated.I had to download avgfix.zip to sort mine out.

hope this helps Quote from: ellenr on DECEMBER 10, 2009, 02:41:51 AM
The box asks "Would you like to save?"
There is no option except "save" or cancel.
I save.
the screen says thanks for downloading AVG but there is no AVG icon and no avg program listed under "all programs"...
Save to "where"? That's where to find it.

Quote from: ellenr on December 10, 2009, 04:35:55 AM
...
1. You say, after I download, I install - how do I do that?
2. and where is it?
3. Dang, last time I installed avg, it sure wasn't this complicated...
1. Double-click the file that was downloaded.
2. Wherever you told it to save it.
3. Too many drugs?
3653.

Solve : All Anti-spyware software fails?

Answer»

Ok FJN. Let's try this scan.

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan LogSD, below is the log from ESETScan:

C:\Program Files\Mozilla Firefox\plugins\NPZoneSB.dllWin32/Toolbar.MyWebSearch applicationcleaned by deleting (after the next restart) - quarantined
C:\Program Files\ZoneAlarmSB\bar\1.bin\NPZONESB.DLLWin32/Toolbar.MyWebSearch applicationcleaned by deleting - quarantined

Also, and I feel kind of stupid for not trying this before, I installed SAS to a new directory instead of the original directory. This got around this issue I was having with being unable to access the original .exe. I performed an SAS scan and pasted the log below:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/08/2009 at 00:28 AM

Application Version : 4.31.1000

Core Rules Database Version : 4344
Trace Rules Database Version: 2193

Scan type : Complete Scan
Total Scan Time : 00:44:33

Memory items scanned : 412
Memory threats detected : 0
Registry items scanned : 5064
Registry threats detected : 32
File items scanned : 24251
File threats detected : 2

Adware.E404 Helper/Variant-AL
HKU\S-1-5-21-3063908644-3062810159-149590578-501\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2231839A-F38E-4066-BF3C-959006189942}

Adware.E404 Helper/Variant-AK
HKU\S-1-5-21-3063908644-3062810159-149590578-501\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{34B9C611-629C-43AA-9F9D-4B58086EA729}

Adware.E404 Helper/Variant-AH
HKU\S-1-5-21-3063908644-3062810159-149590578-501\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A2F3A2E-4B59-4932-B2C3-2E7F13B03207}

Adware.E404 Helper/Variant-AO
HKU\S-1-5-21-3063908644-3062810159-149590578-501\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CAD68085-8805-4FD3-AA1E-2E282ED7E7A2}

Rogue.Component/Trace
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD)
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #Type
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #Start
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #ErrorControl
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #ImagePath
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #DisplayName
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #ObjectName
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) #FailureActions
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Security
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Security#Security
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Enum
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Enum#0
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Enum#Count
HKLM\System\CURRENTCONTROLSET\SERVICES\AVG FREE8 WATCHDOG (AVG8WD) \Enum#NextInstance
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP)
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #Type
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #Start
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #ErrorControl
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #ImagePath
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #DisplayName
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #ObjectName
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) #FailureActions
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Security
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Security#Security
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Enum
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Enum#0
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Enum#Count
HKLM\System\CURRENTCONTROLSET\SERVICES\DHCP CLIENT (DHCP) \Enum#NextInstance

Adware.Tracking Cookie
C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt

Adware.CouponBar
C:\WINDOWS\SYSTEM32\CPNPRT2.CID
Did you run SAS before or after the ESET scan?i ran SAS after ESET. was that bad?Quote

i ran SAS after ESET. was that bad?
No. I was just curious. Please do this:

Download ComboFix by sUBs from one of the below links. Be sure to save it to the

Desktop.

link # 1
Link # 2

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts.
Double-click combofix.exe and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.I hadn't deleted ComboFix from the first time you told me to use it, but I followed "link #1" from your last email anyway and saved to ComboFix2 on my desktop. After disabling all the security stuff, I ran it. It got to "Stage 3" and then nothing. I thought it might just be taking a long time, so I left it alone for an hour. It was still at stage 3, so I closed it. I tried running this "ComboFix2" a few more times and it never made it past stage 3. I tried downloading from "Link #2" in your previous email, but that took me to a page that "no longer exists" Then I tried running the original "ComboFix." I did not let it update because I was afraid that was what kept the newer "ComboFix2" from running. This time, the scan finished. Pasted below is the log from that scan and a new HJT log.

ComboFix 09-12-02.08 - Mary Neill 12/09/2009 18:52.5.1 - x86
Running from: c:\documents and settings\Mary Neill\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-09 21:50 . 2009-12-09 21:50--------d-----w-c:\windows\LastGood
2009-12-08 06:08 . 2009-12-08 06:08--------d-sh--w-c:\documents and settings\NetworkService\IETldCache
2009-12-08 04:06 . 2009-12-08 04:06--------d-----w-c:\program files\SUPERAntiSpyware2
2009-12-08 04:05 . 2009-12-08 04:05--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-12-08 03:29 . 2009-12-08 03:29--------d-----w-c:\program files\ESET
2009-12-08 03:26 . 2009-12-08 05:190----a-w-c:\documents and settings\Mary Neill\Local Settings\Application Data\prvlcl.dat
2009-12-08 02:48 . 2009-12-08 02:49--------d-----w-c:\program files\Spybot - Search & Destroy2009
2009-12-08 01:05 . 2009-12-08 01:054844296----a-w-c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-08 01:04 . 2009-12-03 21:1438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-08 01:04 . 2009-12-08 01:05--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-12-08 01:04 . 2009-12-03 21:1319160----a-w-c:\windows\system32\drivers\mbam.sys
2009-11-30 01:42 . 2009-12-08 18:39117760----a-w-c:\documents and settings\Mary Neill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-30 01:41 . 2009-11-30 01:41--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-30 01:41 . 2009-12-09 23:55--------d-----w-c:\program files\SUPERAntiSpyware
2009-11-30 01:41 . 2009-11-30 01:41--------d-----w-c:\documents and settings\Mary Neill\Application Data\SUPERAntiSpyware.com
2009-11-29 19:10 . 2009-11-28 21:01497944----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-29 19:10 . 2009-11-28 21:013963648----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-29 19:08 . 2009-11-28 21:00877848----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-11-29 19:08 . 2009-11-28 21:001657112----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-28 22:08 . 2009-11-28 22:08--------d-sh--w-c:\documents and settings\Administrator.MARYNEILL\IETldCache
2009-11-28 21:48 . 2009-11-29 02:57--------d-----w-c:\program files\Spybot - Search & Destroy FRESH
2009-11-28 21:16 . 2009-11-28 21:16--------d-----w-c:\documents and settings\All Users\Application Data\Electronic Arts
2009-11-28 21:02 . 2009-11-28 21:05--------d-----w-C:\$AVG
2009-11-28 21:00 . 2009-11-28 21:00--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2009-11-28 20:59 . 2009-12-03 19:29--------d-----w-c:\windows\SxsCaPendDel
2009-11-25 23:09 . 2009-12-03 19:29--------d--h--w-c:\windows\PIF
2009-11-25 21:11 . 2009-11-25 21:11--------d-----w-c:\program files\CCleaner
2009-11-21 18:58 . 2009-11-21 19:01--------d-----w-c:\documents and settings\Mary Neill\Application Data\SPORE
2009-11-21 18:58 . 2009-11-21 18:58--------d--h--r-c:\documents and settings\Mary Neill\Application Data\SecuROM
2009-11-21 18:57 . 2009-11-21 18:57--------d-----w-C:\ProgramData
2009-11-21 18:57 . 2009-11-21 18:571216----a-w-c:\windows\system32\ealregsnapshot1.reg
2009-11-21 18:57 . 2009-11-21 18:57--------d-----w-c:\documents and settings\Mary Neill\Local Settings\Application Data\Downloaded Installations
2009-11-21 18:40 . 2009-11-21 18:58--------d-----w-c:\program files\Electronic Arts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-08 06:09 . 2007-12-09 01:34--------d-----w-c:\program files\Google
2009-12-08 04:21 . 2005-11-07 04:05--------d--h--w-c:\program files\InstallShield Installation Information
2009-12-08 03:34 . 2008-09-01 21:01--------d-----w-c:\documents and settings\Mary Neill\Application Data\Move Networks
2009-12-08 03:34 . 2009-05-31 01:12--------d-----w-c:\program files\Graboid
2009-12-08 03:33 . 2006-09-26 23:51--------d-----w-c:\documents and settings\Mary Neill\Application Data\Lavasoft
2009-12-08 03:28 . 2006-09-26 23:12--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-03 19:42 . 2005-11-07 04:26--------d-----w-c:\program files\Trend Micro
2009-11-29 02:24 . 2009-04-12 23:39--------d-----w-c:\documents and settings\Mary Neill\Application Data\uTorrent
2009-11-29 02:01 . 2008-04-19 18:35--------d-----w-c:\program files\IObit
2009-11-28 21:15 . 2006-09-26 23:11--------d-----w-c:\program files\Spybot - Search & Destroy
2009-11-28 21:08 . 2009-09-07 23:42--------d-----w-c:\program files\Cell Phone Manager
2009-11-28 21:01 . 2009-03-14 22:27360584----a-w-c:\windows\system32\drivers\avgtdix.sys
2009-11-28 21:01 . 2009-03-14 22:27333192----a-w-c:\windows\system32\drivers\avgldx86.sys
2009-11-28 21:01 . 2009-03-14 22:2728424----a-w-c:\windows\system32\drivers\avgmfx86.sys
2009-11-28 21:01 . 2009-03-14 22:2712464----a-w-c:\windows\system32\avgrsstx.dll
2009-11-28 21:00 . 2008-12-04 00:45--------d-----w-c:\program files\AVG
2009-11-25 20:33 . 2005-06-22 23:54--------d-----w-c:\program files\Opera
2009-11-21 18:58 . 2008-03-19 21:41107888----a-w-c:\windows\system32\CmdLineExt.dll
2009-11-21 18:37 . 2005-12-25 02:0943982-c--a-w-c:\documents and settings\Mary Neill\Application Data\wklnhst.dat
2009-11-21 18:37 . 2007-09-14 19:41--------d-----w-c:\program files\LEGO Media
2009-11-21 18:36 . 2008-03-19 21:42--------d-----w-c:\documents and settings\All Users\Application Data\WildTangent
2009-11-21 18:35 . 2008-05-01 20:10--------d-----w-c:\program files\WildGames
2009-11-15 16:57 . 2007-09-14 19:41346-c--a-w-c:\windows\EReg213.dat
2009-11-11 03:39 . 2009-08-19 21:01--------d-----w-c:\program files\JetAudio
2009-10-11 02:45 . 2009-10-11 02:45--------d-----w-c:\program files\7-Zip
2009-09-11 14:18 . 2004-08-10 18:51136192----a-w-c:\windows\system32\msv1_0.dll
2006-08-25 00:17 . 2005-12-01 01:1856-csh--r-c:\windows\system32\7FA7908E3A.sys
2006-08-25 00:17 . 2005-12-01 01:183766-csha-w-c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( [emailprotected]_19.34.00 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-11-30 01:41 . 2009-12-03 00:1565024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-12-08 04:06 . 2009-12-08 04:0665024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2009-11-30 01:41 . 2009-12-03 00:1518944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-12-08 04:06 . 2009-12-08 04:0618944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-08 06:09 . 2009-12-08 06:0925214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ARPPRODUCTICON.exe
+ 2009-12-08 04:06 . 2009-12-08 04:065120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
- 2009-11-30 01:41 . 2009-12-03 00:155120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2009-12-08 06:09 . 2009-12-08 06:091258496 c:\windows\Installer\bb77bb.msi
+ 2009-12-08 04:06 . 2009-12-08 04:061583616 c:\windows\Installer\4adcfc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-23 2001648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-04-17 54576]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-28 2020120]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware2\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21548352----a-w-c:\program files\SUPERAntiSpyware2\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-28 21:0112464----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare Software\\bin\\EasyShare.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Mary Neill\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys

R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-12 133104]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware2\SASENUM.SYS [2009-11-23 7408]
R4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [2006-04-03 14032]
S1 AvgLdx86;AVG Free AVI LOADER Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-11-28 333192]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-11-28 360584]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware2\SASDIFSV.SYS [2009-11-23 9968]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2009-11-28 906520]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2009-11-28 285392]

.
Contents of the 'Scheduled Tasks' folder

2009-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-12 18:54]

2009-12-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-12 18:54]

2009-12-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3063908644-3062810159-149590578-1006Core.job
- c:\documents and settings\Mary Neill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-18 19:35]

2009-12-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3063908644-3062810159-149590578-1006UA.job
- c:\documents and settings\Mary Neill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-18 19:35]

2009-12-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = 127.0.0.1:9090
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Mary Neill\Application Data\Mozilla\Firefox\Profiles\owxdew7q.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com | www.gmail.com | hxxp://mail.yahoo.com | http://puzzles.usatoday.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Mary Neill\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWTHost.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 18:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3063908644-3062810159-149590578-1006\Software\SecuROM\License information*]
"datasecu"=hex:10,cc,08,bd,a2,bf,35,04,4a,79,bc,95,c4,f3,26,0c,e3,25,4a,5e,fb,
64,12,f1,86,1a,5b,33,0f,cb,04,76,a5,f1,c9,5a,9f,37,54,0a,3b,e1,f6,cb,4d,0c,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(516)
c:\program files\SUPERAntiSpyware2\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3352)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-09 19:00
ComboFix-quarantined-files.txt 2009-12-10 00:00
ComboFix2.txt 2009-12-03 19:38

Pre-Run: 11,017,535,488 bytes free
Post-Run: 10,996,162,560 bytes free

- - End Of File - - 5EE34222AD01FA4A0305F30F5D9F044C






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:52 PM, on 12/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-3063908644-3062810159-149590578-1006\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart (User '?')
O4 - HKUS\S-1-5-21-3063908644-3062810159-149590578-1006\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-us.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware2\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 6590 bytes

Hello FJN. First of all, I apologize for getting you to run the SECOND ComboFix scan. All the logs look good now. How's your computer running now? Any issues?SD,

Computer is running great now. Thanks for your help. That's good news, FJN. Now we have to do some clean-up. You can uninstall HJT but you can keep SAS and MBAM. Update them and run them about once a week to keep your computer clean.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* MAKE sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all CRITICAL updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Safe Surfing!
3654.

Solve : Re: Atapi.sys infected - Trojan Horse Packed.Protector.C?

Answer» HI, I have the same problem, or had. I used ComboFix, as is written up.

I had that TROJAN and the same dile was infected and also I had svchost problem.

I will post a log file here, and thenk you in advance for assistence:

ComboFix 09-12-10.01 - goga 12/11/2009 12:56:21.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.498 [GMT 1:00]
Running from: c:\documents and settings\goga\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\goga\Start Menu\Programs\Startup\siszyd32.exe
c:\windows\system32\av_md.exe
c:\windows\system32\config\systemprofile\av_md.exe
c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd
D:\la.txt

----- BITS: Possible infected sites -----

hxxp://www.rsiwarrior.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SKYNET
-------\Service_SKYNET


((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.

2009-12-11 07:53 . 2009-12-11 08:04--------d-----w-c:\windows\LastGood
2009-12-11 07:39 . 2004-08-03 21:3120992----a-w-c:\windows\system32\drivers\RTL8139.sys
2009-12-11 07:34 . 2001-08-23 15:0024661----a-w-c:\windows\system32\spxcoins.dll
2009-12-11 07:34 . 2001-08-23 15:0013312----a-w-c:\windows\system32\irclass.dll
2009-12-10 21:07 . 2009-12-10 21:07--------d-----w-c:\documents and settings\goga\Local Settings\Application Data\PlentyofTorrents
2009-12-10 21:07 . 2009-12-10 21:07--------d-----w-c:\program files\Conduit
2009-12-10 21:07 . 2009-12-10 21:07--------d-----w-c:\documents and settings\goga\Local Settings\Application Data\Conduit
2009-12-10 20:58 . 2009-12-10 20:58--------d-----w-C:\Nikoletina
2009-12-10 19:40 . 2009-12-10 19:40--------d-----w-c:\documents and settings\goga\Application Data\Uniblue
2009-12-10 19:00 . 2009-12-10 19:27--------d-----w-c:\documents and settings\goga\Application Data\Lavasoft
2009-12-10 18:42 . 2009-12-10 23:52--------d-----w-c:\windows\LastGood.Tmp
2009-12-10 16:30 . 2009-12-10 18:53--------d-----w-c:\program files\Enigma Software Group
2009-12-09 22:54 . 2009-12-09 22:56--------d-----w-C:\Nights.In.Rodanthe.2008.DVDRiP.XViD
2009-12-07 23:38 . 2009-03-30 08:3396104----a-w-c:\windows\system32\drivers\avipbb.sys
2009-12-07 23:38 . 2009-02-13 10:2922360----a-w-c:\windows\system32\drivers\avgntmgr.sys
2009-12-07 23:38 . 2009-02-13 10:1745416----a-w-c:\windows\system32\drivers\avgntdd.sys
2009-12-07 23:38 . 2009-12-07 23:38--------d-----w-c:\program files\Avira
2009-12-07 23:38 . 2009-12-07 23:38--------d-----w-c:\documents and settings\All Users\Application Data\Avira
2009-12-06 21:13 . 2009-12-06 21:13--------d--h--w-c:\windows\PIF
2009-12-03 17:59 . 2004-08-03 22:56221184----a-w-c:\windows\system32\wmpns.dll
2009-11-28 14:40 . 2009-11-28 14:40152576----a-w-c:\documents and settings\goga\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-28 14:39 . 2009-11-28 14:3979488----a-w-c:\documents and settings\goga\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-27 21:30 . 2009-11-27 21:30--------d-----w-c:\documents and settings\goga\Application Data\Acoustica
2009-11-27 21:09 . 2009-11-27 21:09--------d-----w-c:\documents and settings\goga\Local Settings\Application Data\HELP
2009-11-27 18:16 . 2009-11-27 18:16--------d-----w-c:\documents and settings\goga\Application Data\Corel
2009-11-27 18:00 . 2009-11-27 18:00--------d-----w-c:\windows\Corel
2009-11-26 23:06 . 2009-11-26 23:29--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
2009-11-25 00:11 . 2009-11-25 00:11--------d-----w-C:\PROBA
2009-11-22 00:29 . 2009-11-22 00:2914911----a-w-C:\Calculator.zip
2009-11-22 00:29 . 2009-11-22 00:29--------d-----w-C:\Calculator
2009-11-20 12:45 . 2009-12-04 19:39--------d-----w-c:\documents and settings\goga\Application Data\DC++
2009-11-20 12:45 . 2009-11-20 12:45--------d-----w-c:\documents and settings\goga\Local Settings\Application Data\DC++
2009-11-20 12:34 . 2009-11-20 12:34--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-11-19 19:34 . 2009-11-23 18:34--------d-----w-C:\java
2009-11-19 18:59 . 2009-11-19 18:59--------d-----w-c:\documents and settings\goga\workspace
2009-11-16 08:49 . 2009-11-23 18:33--------d-----w-C:\Kalkulator kopija 1
2009-11-14 14:16 . 2009-11-14 14:20--------d-----w-c:\documents and settings\goga\Application Data\ZoomBrowser EX
2009-11-14 14:11 . 2009-11-14 14:16--------d-----w-c:\documents and settings\goga\Application Data\CameraWindowDC
2009-11-14 14:11 . 2009-11-14 14:11--------d-----w-c:\documents and settings\goga\Application Data\CANON INC
2009-11-14 14:11 . 2001-08-17 21:365632----a-w-c:\windows\system32\ptpusb.dll
2009-11-14 14:11 . 2004-08-03 23:56159232----a-w-c:\windows\system32\ptpusd.dll
2009-11-14 14:11 . 2004-08-03 21:5815104----a-w-c:\windows\system32\drivers\usbscan.sys
2009-11-14 13:46 . 2009-11-14 13:47--------d-----w-c:\program files\Canon
2009-11-14 13:46 . 2009-11-14 13:46--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-11-14 13:40 . 2009-11-14 13:40--------d-----w-c:\program files\Common Files\Canon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 12:27 . 2009-10-24 17:30--------d-----w-c:\documents and settings\goga\Application Data\uTorrent
2009-12-11 07:50 . 2009-10-21 13:5122780----a-w-c:\windows\system32\emptyregdb.dat
2009-12-10 19:23 . 2009-12-10 19:2316----a-w-c:\windows\system32\config\systemprofile\Application Data\fvgqad.dat
2009-12-10 11:58 . 2009-12-10 11:5816----a-w-c:\documents and settings\NetworkService\Application Data\fvgqad.dat
2009-12-10 11:58 . 2009-12-10 11:584----a-w-c:\documents and settings\goga\Application Data\avdrn.dat
2009-12-09 22:23 . 2009-10-30 22:43--------d-----w-c:\documents and settings\goga\Application Data\Skype
2009-12-09 20:44 . 2009-10-30 23:04--------d-----w-c:\documents and settings\goga\Application Data\skypePM
2009-12-08 13:39 . 2009-10-21 19:0356816----a-w-c:\windows\system32\drivers\avgntflt.sys
2009-12-07 23:39 . 2009-10-21 19:5530639----a-w-c:\documents and settings\goga\Application Data\usrstats.dat
2009-12-07 23:36 . 2009-12-07 23:360---ha-w-c:\documents and settings\All Users\Application Data\BIT7.tmp
2009-11-28 14:45 . 2009-10-30 13:58--------d-----w-c:\program files\Java
2009-11-27 19:19 . 2009-10-21 19:5342168----a-w-c:\documents and settings\goga\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-27 18:02 . 2009-10-21 14:15--------d--h--w-c:\program files\InstallShield Installation Information
2009-11-27 17:37 . 2009-10-21 14:15--------d-----w-c:\program files\Common Files\InstallShield
2009-11-25 18:03 . 2009-10-21 14:37--------d-----w-c:\program files\Common Files\Adobe
2009-11-20 21:46 . 2009-11-03 18:35--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-19 10:52 . 2009-10-21 19:31--------d-----w-c:\documents and settings\goga\Application Data\Yahoo!
2009-11-13 13:01 . 2009-10-22 18:51--------d-----w-c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-05 10:17 . 2009-10-21 15:12--------d-----w-c:\documents and settings\goga\Application Data\AdobeUM
2009-11-03 18:42 . 2009-11-03 18:39--------d-----w-c:\documents and settings\goga\Application Data\Media Player Classic
2009-11-02 23:01 . 2009-11-02 23:01--------d-----w-c:\program files\DVBViewerTE
2009-11-02 21:54 . 2009-11-02 21:54--------d-----w-c:\documents and settings\goga\Application Data\DivX
2009-11-01 14:30 . 2009-10-21 19:41--------d-----w-c:\documents and settings\goga\Application Data\Ahead
2009-10-31 16:28 . 2009-10-31 16:28--------d-----w-c:\program files\Common Files\Apple
2009-10-31 16:27 . 2009-10-31 16:27--------d-----w-c:\program files\Apple Software Update
2009-10-31 16:27 . 2009-10-31 16:27--------d-----w-c:\documents and settings\All Users\Application Data\Apple
2009-10-30 23:04 . 2009-10-30 23:0456---ha-w-c:\windows\system32\ezsidmv.dat
2009-10-30 22:43 . 2009-10-30 22:42--------d-----w-c:\program files\Skype
2009-10-30 22:43 . 2009-10-30 22:42--------d-----w-c:\documents and settings\All Users\Application Data\Skype
2009-10-30 22:42 . 2009-10-30 22:42--------d-----w-c:\program files\Common Files\Skype
2009-10-30 13:58 . 2009-10-30 13:58152576----a-w-c:\documents and settings\goga\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-27 23:30 . 2009-10-27 23:30--------d-----w-c:\program files\Hewlett-Packard
2009-10-24 23:31 . 2009-10-21 19:06--------d-----w-c:\documents and settings\goga\Application Data\BSplayer Pro
2009-10-22 23:49 . 2009-10-21 19:19--------d-----w-c:\documents and settings\goga\Application Data\Winamp
2009-10-22 19:26 . 2009-10-22 19:26--------d-----w-c:\documents and settings\goga\Application Data\ACD Systems
2009-10-22 19:24 . 2009-10-22 19:10--------d-----w-c:\program files\Microsoft SQL Server
2009-10-22 19:19 . 2009-10-21 16:49--------d-----w-c:\program files\Microsoft.NET
2009-10-22 16:32 . 2009-10-22 16:32--------d-----w-c:\documents and settings\goga\Application Data\Teleca
2009-10-21 19:57 . 2009-10-21 19:56--------d-----w-c:\program files\Common Files\Teleca Shared
2009-10-21 19:57 . 2009-10-21 19:57--------d-----w-c:\program files\Sony Ericsson
2009-10-21 19:56 . 2009-10-21 19:56--------d-----w-c:\documents and settings\goga\Application Data\Sony Ericsson
2009-10-21 19:56 . 2009-10-21 19:54--------d-----w-c:\documents and settings\All Users\Application Data\Teleca
2009-10-21 19:56 . 2009-10-21 19:54--------d-----w-c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-10-21 19:56 . 2009-10-21 19:56--------d-----w-c:\program files\Common Files\Sony Ericsson Shared
2009-10-21 19:41 . 2009-10-21 19:39--------d-----w-c:\program files\Common Files\Ahead
2009-10-21 19:33 . 2009-10-21 19:33--------d-----w-c:\documents and settings\All Users\Application Data\ACD Systems
2009-10-21 19:33 . 2009-10-21 19:09--------d-----w-c:\program files\ACD Systems
2009-10-21 19:31 . 2009-10-21 19:29--------d-----w-c:\program files\Yahoo!
2009-10-21 19:31 . 2009-10-21 19:29--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-21 19:31 . 2009-10-21 19:31--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-10-21 16:49 . 2009-10-21 16:49--------d-----w-c:\program files\Microsoft ActiveSync
2009-10-21 16:33 . 2009-10-21 16:33--------d-----w-c:\documents and settings\All Users\Application Data\McAfee
2009-10-21 16:06 . 2009-10-21 16:06--------d-----w-c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-21 15:31 . 2009-10-21 15:31--------d-----w-c:\documents and settings\All Users\Application Data\CMUV
2009-10-21 15:07 . 2009-10-21 15:07--------d-----w-c:\documents and settings\All Users\Application Data\Technisat
2009-10-21 15:06 . 2009-10-21 15:06--------d-----w-c:\program files\MainConcept
2009-10-21 14:55 . 2009-10-21 13:5586327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-21 14:47 . 2009-10-21 14:33--------d-----w-c:\program files\ProgDVB
2009-10-21 14:21 . 2009-10-21 14:210----a-w-c:\windows\nsreg.dat
2009-10-21 14:15 . 2009-10-21 14:15--------d-----w-c:\program files\Intel
2009-10-21 13:57 . 2009-10-21 13:57--------d-----w-c:\program files\microsoft frontpage
2009-10-11 03:17 . 2009-10-30 13:59411368----a-w-c:\windows\system32\deploytk.dll
2009-09-25 16:42 . 2009-11-02 21:51120056----a-w-c:\windows\system32\pxcpyi64.exe
2009-09-25 16:42 . 2009-11-02 21:51118520----a-w-c:\windows\system32\pxinsi64.exe
2009-09-24 18:16 . 2009-10-21 19:29607472----a-w-c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
"uTorrent"="d:\programi\uTorrent\uTorrent.exe" [2009-12-09 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="d:\programi\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - d:\programi\TechniSat DVB\bin\Server4PC.exe [2009-11-3 338448]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RSI Warrior.lnk]
backup=c:\windows\pss\RSI Warrior.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2004-08-03 22:56110592----a-w-c:\windows\system32\bthprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 14:395244216----a-w-d:\programi\YAHOOM~1\MESSEN~1\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 14:40155648----a-w-c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08417792----a-w-d:\programi\K-Lite Codec Pack\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-05-28 08:14528384----a-r-d:\programi\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-09 16:19289584----a-w-d:\programi\uTorrent\uTorrent.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programi\\Yahoo messenger\\Messenger\\YahooMessenger.exe"=
"d:\\Programi\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/8/2009 12:38 AM 108289]
.
------- Supplementary Scan -------
.
uStart Page =
IE: E&xport to Microsoft Excel - d:\programi\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\goga\Application Data\Mozilla\Firefox\Profiles\gz6ssm5a.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: d:\programi\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: d:\programi\Mozilla *Blocked Russian URL*\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\goga\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: d:\programi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programi\Reader\browser\nppdf32.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - trued:\programi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{6a54b25b-4736-4fbd-bdb5-ce12dfc25e37} - c:\program files\PlentyofTorrents\tbPlen.dll
BHO-{6a54b25b-4736-4fbd-bdb5-ce12dfc25e37} - c:\program files\PlentyofTorrents\tbPlen.dll
Toolbar-{6a54b25b-4736-4fbd-bdb5-ce12dfc25e37} - c:\program files\PlentyofTorrents\tbPlen.dll
WebBrowser-{6A54B25B-4736-4FBD-BDB5-CE12DFC25E37} - c:\program files\PlentyofTorrents\tbPlen.dll
AddRemove-PlentyofTorrents Toolbar - c:\progra~1\PLENTY~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-11 13:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\imapi.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
COMPLETION time: 2009-12-11 13:31:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-11 12:31

Pre-Run: 1,662,324,736 bytes free
Post-Run: 2,440,630,272 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - FF20F7077F51FCF155F7A5A5D1E21025
dzi. Please don't hijack another person's thread. Start one of your own. Go to the first thread in this forum and follow the instructions. Someone will help you with your particular problem. Moved to NEW topic.
3655.

Solve : Atapi.sys infected - Trojan Horse Packed.Protector.C?

Answer»

Let me know how everything is after these steps.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now TYPE Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide SYSTEM/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, EXECUTION time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.Ok, all doneIf there are no more malware issues we can finish up now.

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the SCAN to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ACTIVEX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok, thank you very much!Your welcome.

Safe surfing...
3656.

Solve : Pop up saying I need to download an Antivir program?

Answer»

About twice a day I've been getting a pop up saying I need to download an antivir program through install.exec. It's saying I have 95 trojans and some worms in my computer and to run this software. I already have Norton Antivir and SPYBOT Search and DESTROY and it's not catching any of these viruses. Has anyone else seen this? My son has been playing FREE games ONLINE could it be from that?Uninstall spybot. Download and run MalwareBytes or SUPERANTISPYWARE. Are the definitions in NAV current? If so, run a full scan with NAV.

3657.

Solve : malware - atapi.sys infected??

Answer»

Hi there, I'm running XP SP3 and have been suffering from NASTY piece of malware, which visibly only re-directs me from some google links I click on (and my PC has been restarting instead of hibernating), though from scanning/healing with the usual programs - Comodo, Spybot, AdAware, AntiMalware etc. nothing was being permanently resolved.
I had a search around and I'm pretty sure I've got a rootkit problem. I tried using esage.com's Rootkit.Win32.TDSS remover, though I don't have my windows CD to repair the file it found as infected - windows/system32/drivers/atapi.sys
How dangerous is this, and should I still do banking using this computer? I want rid of the problem whatever, but I'd just like to know what you think I might be dealing with.

As I did the SuperAS scan, Comodo alerted me to a few things as it went through, including:

Name: [emailprotected]
Locations: C:\32788R22FWJFW.0.tmp\hidec.exe
C:\32788R22FWJFW.0.tmp\iexplore.exe
C:\32788R22FWJFW.0.tmp\n.pif
C:\32788R22FWJFW.0.tmp\NirCmd.cfxxe



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/13/2009 at 02:01 PM

Application Version : 4.31.1000

Core Rules Database Version : 4364
Trace Rules Database Version: 2207

Scan type : Complete Scan
Total Scan Time : 01:21:19

Memory items scanned : 411
Memory threats detected : 0
Registry items scanned : 5809
Registry threats detected : 0
File items scanned : 75228
File threats detected : 1

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\[emailprotected][1].txt

---------------------------------------------

Malwarebytes' Anti-Malware 1.42
Database version: 3351
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

13/12/2009 14:16:30
mbam-log-2009-12-13 (14-16-30).txt

Scan type: Quick Scan
Objects scanned: 120890
Time elapsed: 5 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:18:52, on 13/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\BONJOUR\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Wireless CONSOLE 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ASUSTPE.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Documents and Settings\Tom\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Tom\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Program Files\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [ASUSTPE] C:\WINDOWS\system32\ASUSTPE.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-2386165330-1228240430-1135775065-1005\..\Run: [ASUSTPE] C:\WINDOWS\system32\ASUSTPE.exe (User '?')
O4 - HKUS\S-1-5-21-2386165330-1228240430-1135775065-1005\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: CCC.lnk = ? (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Service for CDROM ACCESS - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 6905 bytes

3658.

Solve : VirtualBox?

Answer»

I was recently sent a file (.exe) that I would like to use if it what it says it is but even though I scanned it with my AV and all those web ones which scan it with many AVs I'm not CONVINCED. I heard I can run it in VirtualBox and it won't hurt my computer, is this TRUE?Nothing is bulletproof. But I would imagine that VB will be enough to protect you. If you've scanned it with MULTIPLE scanners then I would imagine it's safe.

You can also run it through the Comodo Instant Malware Analysis (CIMA) to get an idea what it's GOING to do. http://camas.comodo.com/

3659.

Solve : Trojan horse Rootkit-Pakes.U infected?

Answer»

SD, I did as instructed and the same happened, program ran as should and did not produce a log again.Hello timmyrob.

Try this please.

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

FCopy::
h:\windows\$NtServicePackUninstall$\atapi.sys | h:\windows\system32\drivers\atapi.sys


3. Go to the Notepad WINDOW and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
Alright SD, I did it again and this time is gave me a log! So here it is. I went ahead and added another HJT log as well, wasn't sure if you'd need one or not.

[Saving space, attachment deleted by admin]Hi timmyrob. It's looking good. Could you please do this for me?

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan archives.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan LogNo problems with running the scan, here is the log

[Saving space, attachment deleted by admin]Hi timmyrob.

Please check your PM inbox messages for the next set of instructions.here is my avenger log evil and SD

[Saving space, attachment deleted by admin]We can't read that and there was an error.

Please do this only don't attach the log, just copy and paste it into the reply.

* Run avenger.exe by double-clicking on it.
* Do not change any check box options!!
* Copy everything in the Code box below, and paste it into the Input script here window:

Code: [Select]Comment:

Files to move:
h:\documents and settings\timmy\Desktop\atapi.sys | H:\WINDOWS\system32\drivers\atapi.sys

* Now click the Execute button.
* Click Yes to the prompt to confirm you want to execute.
* Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
* Your PC should reboot, if not, reboot it yourself.
* A log file from Avenger will be PRODUCED at C:\avenger.txt and it will pop-up for you to view when you login after reboot.

* Add the Avenger log in your next post. Here is the avenger log copy and pasted:


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at H:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: "h:\documents and settings\timmy\Desktop" is a folder, not a file!
File move operation "h:\documents and settings\timmy\Desktop|H:\WINDOWS\system32\drivers\atapi.sys" failed!
Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY)
--> use "Folders to delete:" instead of "Files to delete:" to delete a directory


Completed script processing.

*******************

Finished! Terminate.
I messed that up.

Please do this only don't attach the log, just copy and paste it into the reply.

* Run avenger.exe by double-clicking on it.
* Do not change any check box options!!
* Copy everything in the Code box below, and paste it into the Input script here window:

Code: [Select]Comment:

Files to move:
h:\documents and settings\timmy\Desktop\atapi.sys | H:\WINDOWS\system32\drivers\atapi.sys

* Now click the Execute button.
* Click Yes to the prompt to confirm you want to execute.
* Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
* Your PC should reboot, if not, reboot it yourself.
* A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.

* Add the Avenger log in your next post. here is the new log from avenger copy and pasted:


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at H:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "h:\documents and settings\timmy\Desktop\atapi.sys|H:\WINDOWS\system32\drivers\atapi.sys" completed successfully.

Completed script processing.

*******************

Finished! Terminate.
Okay we can finish up finally.

* Click START then RUN
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter.

The above procedure will:
* Delete: ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* DEPENDING on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the Secunia Software Inspector to check for out of date software.

  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and GET all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky WEBSITE. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
3660.

Solve : Virut Easy Removal??

Answer»

I was browsing through google for information on http://zief.pl/rc/ and found a page on symantec CLAIMING that Virut is extremely easy to remove (http://www.symantec.com/security_response/writeup.jsp?docid=2009-020418-0204-99&tabid=1). As EvilFantasy knows, the only WAY to truly get RID of it is to format your computer...Or is it?

Not many PEOPLE here use Norton AV, because the scanner is bloated. But Symantec generally knows what they're doing. Evil, could this possibly be a better solution for removing Virut?

If you are indeed infected, don't do anything without consultation with a professional (EvilFantasy) first.There is no miracle cure for this. All of the major antivirus have a removal tool for Virut but they don't work.Quote

W32.Virut!html

This is only the inline frame version of Virut, and it is easy to remove. Just edit the source code of the HTML file and remove the frame.What about the malicious files it installs?

Do you believe that malware is actually that neat and tidy?Heck no.

I'm just saying that Symantec is outlining the iframe part of the infection.Quote from: evilfantasy on April 24, 2009, 03:48:19 PM
There is no miracle cure for this. All of the major antivirus have a removal tool for Virut but they don't work.
Thank you for pointing this out.I can confirm they don't work. tried out two or three before saying to *CENSORED* with it and reformatting.
3661.

Solve : Combofix log?

Answer»

Edit 4-28-09: I was able to get this cleaned up. Thank you anyway.


I have been working on my neighbor's computer since yesterday. Couldn't get any of the AVs to install, couldn't get Malwarebytes t install, couldn't get superantispyware to install. Looking through another post, I tried combofix and got it to generate a log. Here it is, any help would be VERY appreciated!

LOG:

ComboFix 09-04-25.A3 - Janet Frye 04/26/2009 9:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.701 [GMT -4:00]
Running from: c:\documents and settings\Janet Frye\desktop\combo-fix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\UACkuxoetpeiqwuoou.sys
c:\windows\system32\UACaqhrqaorxsmrtdu.log
c:\windows\system32\UACijyfmpfxclqiamk.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkyhsdipdkxelxle.dll
c:\windows\system32\UAClmxydipyjlojdji.dll
c:\windows\system32\UACmlogknwdgatauue.log
c:\windows\system32\UACocyxfcppxgfxkrw.log
c:\windows\system32\UACtpkeovywpvayjva.dll
c:\windows\system32\UACvngoaqlnlesyupd.dat
c:\windows\system32\UACyypvqpwoweljfdo.dll
c:\windows\system32\wincontrol.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-4-26 )))))))))))))))))))))))))))))))
.

2009-04-26 12:06 . 2009-04-26 12:31--------d---a-wc:\documents and settings\All Users\Application Data\TEMP
2009-04-26 12:04 . 2005-06-18 15:44212240----a-wc:\windows\system32\RichTx32.ocx
2009-04-26 12:04 . 2004-03-09 05:00124688----a-wc:\windows\system32\MSWinSck.ocx
2009-04-26 12:04 . 2009-04-26 12:04--------d-----wc:\program files\Common Files\eSellerate
2009-04-26 12:04 . 2007-06-08 17:531753088----a-wc:\windows\system32\ExGrid.dll
2009-04-26 12:04 . 2007-06-05 14:20602112----a-wc:\windows\system32\ExMenu.dll
2009-04-26 12:04 . 2007-06-05 14:19516096----a-wc:\windows\system32\ExTab.dll
2009-04-26 12:04 . 2007-04-03 20:51614400----a-wc:\windows\system32\ExButton.dll
2009-04-26 12:04 . 2007-04-03 20:51307200----a-wc:\windows\system32\ExPMenu.dll
2009-04-26 12:04 . 2005-10-11 18:40356352----a-wc:\windows\system32\eSellerateEngine.dll
2009-04-26 12:04 . 2005-10-04 12:11118784----a-wc:\windows\system32\eWebControl.dll
2009-04-26 12:04 . 1998-04-24 05:00368912----a-wc:\windows\system32\vbar332.dll
2009-04-26 12:04 . 2009-04-26 12:04--------d-----wc:\program files\AnswersThatWork
2009-04-26 11:05 . 2009-04-26 12:33--------d-----wc:\documents and settings\All Users\Application Data\avg8
2009-04-26 10:59 . 2005-12-14 05:40135168----a-wc:\windows\system32\igfxres.dll
2009-04-26 04:03 . 2004-08-10 08:1373728-c--a-wc:\windows\system32\dllcache\ehresja.dll
2009-04-26 04:03 . 2004-08-10 08:1369632-c--a-wc:\windows\system32\dllcache\ehresko.dll
2009-04-26 04:03 . 2004-08-10 08:1369632-c--a-wc:\windows\system32\dllcache\ehresfr.dll
2009-04-26 04:03 . 2004-08-10 08:1369632-c--a-wc:\windows\system32\dllcache\ehresde.dll
2009-04-26 04:01 . 2004-08-10 11:005632-c--a-wc:\windows\system32\dllcache\smimsgif.dll
2009-04-26 04:00 . 2001-08-18 02:3665536-c--a-wc:\windows\system32\dllcache\EXCH_mailmsg.dll
2009-04-26 03:59 . 2004-08-10 11:0078848-c--a-wc:\windows\system32\dllcache\dayi.ime
2009-04-26 03:58 . 2003-03-24 20:5220540-c--a-wc:\windows\system32\dllcache\admin.dll
2009-04-26 03:55 . 2009-04-26 03:55488---ha-rc:\windows\system32\logonui.exe.manifest
2009-04-26 03:55 . 2009-04-26 03:55749---ha-rc:\windows\WindowsShell.Manifest
2009-04-26 03:55 . 2009-04-26 03:55749---ha-rc:\windows\system32\wuaucpl.cpl.manifest
2009-04-26 03:55 . 2009-04-26 03:55749---ha-rc:\windows\system32\sapi.cpl.manifest
2009-04-26 03:55 . 2009-04-26 03:55749---ha-rc:\windows\system32\nwc.cpl.manifest
2009-04-26 03:55 . 2009-04-26 03:55749---ha-rc:\windows\system32\ncpa.cpl.manifest
2009-04-26 03:37 . 2004-08-10 11:0013753----a-rc:\windows\SET91.tmp
2009-04-26 03:37 . 2004-08-10 11:001086058----a-rc:\windows\SET85.tmp
2009-04-26 03:37 . 2004-08-10 11:00106147----a-rc:\windows\SET82.tmp
2009-04-26 02:55 . 2009-04-26 02:55--------d-----wc:\program files\CCleaner
2009-04-25 22:54 . 2004-08-10 11:0016384-c--a-wc:\windows\system32\dllcache\isignup.exe
2009-04-25 22:54 . 2004-08-10 11:0032768-c--a-wc:\windows\system32\dllcache\icwdl.dll
2009-04-25 22:54 . 2004-08-10 11:0086016-c--a-wc:\windows\system32\dllcache\icwconn2.exe
2009-04-25 22:54 . 2004-08-10 11:00214528-c--a-wc:\windows\system32\dllcache\icwconn1.exe
2009-04-25 22:54 . 2004-08-10 11:0020480-c--a-wc:\windows\system32\dllcache\inetwiz.exe
2009-04-25 22:27 . 2006-03-30 10:0322339----a-rc:\windows\SET12F.tmp
2009-04-25 22:27 . 2005-03-30 17:5410559----a-rc:\windows\SET130.tmp
2009-04-25 22:27 . 2004-08-10 11:007334-c--a-wc:\windows\system32\dllcache\wmerrenu.cat
2009-04-25 22:27 . 2004-08-10 11:0013753----a-rc:\windows\SETEC.tmp
2009-04-25 22:27 . 2004-08-10 11:001086058----a-rc:\windows\SETE0.tmp
2009-04-25 22:27 . 2004-08-10 11:00106147----a-rc:\windows\SETDD.tmp
2009-04-25 18:13 . 2009-04-25 18:13--------d-----wc:\windows\dell
2009-04-18 19:28 . 2009-03-26 19:231900544----a-wc:\windows\system32\usbaaplrc.dll
2009-04-18 19:11 . 2009-04-18 19:11--------d-----wc:\program files\Bonjour
2009-04-17 16:18 . 2009-04-17 16:18--------d-----wc:\program files\Common Files\Uninstall
2009-04-17 16:18 . 2009-04-17 16:18--------d-----wc:\program files\PAV
2009-04-17 01:58 . 2009-04-17 01:58--------d-----wc:\documents and settings\Trevor\Local Settings\Application Data\Apple Computer
2009-04-16 02:51 . 2008-05-03 11:552560----a-wc:\windows\system32\xpsp4res.dll
2009-03-29 20:01 . 2009-03-29 20:01--------d-----wc:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 12:10 . 2008-01-27 20:46--------d-----wc:\program files\Windows Live Toolbar
2009-04-26 03:53 . 2005-08-16 10:3834380----a-wc:\windows\system32\emptyregdb.dat
2009-04-26 03:53 . 2009-04-26 03:531663----a-wc:\windows\Inf\COME3.tmp
2009-04-26 03:41 . 2006-12-31 19:194128----a-wC:\INFCACHE.1
2009-04-26 01:36 . 2006-12-21 03:22--------d-----wc:\documents and settings\All Users\Application Data\Trend Micro
2009-04-26 01:20 . 2006-12-21 03:32--------d-----wc:\documents and settings\All Users\Application Data\Viewpoint
2009-04-26 00:09 . 2007-02-05 20:24--------d-----wc:\program files\Spybot - Search & Destroy
2009-04-26 00:09 . 2007-02-05 20:24--------d-----wc:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-26 00:08 . 2007-02-05 17:33--------d-----wc:\program files\SBC Self Support Tool
2009-04-25 23:16 . 2008-01-27 20:44--------d-----wc:\program files\MSN Messenger
2009-04-25 23:16 . 2009-03-08 01:37244---ha-wC:\sqmnoopt17.sqm
2009-04-25 23:16 . 2009-03-08 01:37232---ha-wC:\sqmdata17.sqm
2009-04-25 22:51 . 2009-04-25 22:51873----a-wc:\windows\Inf\COM386.tmp
2009-04-25 20:00 . 2009-02-17 20:37--------d-----wc:\program files\AntWar_at
2009-04-22 22:45 . 2009-03-07 21:32172---ha-wC:\sqmnoopt16.sqm
2009-04-22 22:45 . 2009-03-07 21:32172---ha-wC:\sqmdata16.sqm
2009-04-22 22:44 . 2009-03-03 00:27268---ha-wC:\sqmdata15.sqm
2009-04-22 22:44 . 2009-03-03 00:27244---ha-wC:\sqmnoopt15.sqm
2009-04-22 19:40 . 2009-03-02 22:40268---ha-wC:\sqmdata14.sqm
2009-04-22 19:40 . 2009-03-02 22:40244---ha-wC:\sqmnoopt14.sqm
2009-04-21 20:25 . 2009-03-02 22:34268---ha-wC:\sqmdata13.sqm
2009-04-21 20:25 . 2009-03-02 22:34244---ha-wC:\sqmnoopt13.sqm
2009-04-21 00:13 . 2009-02-28 17:45268---ha-wC:\sqmdata12.sqm
2009-04-21 00:13 . 2009-02-28 17:45244---ha-wC:\sqmnoopt12.sqm
2009-04-20 23:58 . 2009-02-28 16:52268---ha-wC:\sqmdata11.sqm
2009-04-20 23:58 . 2009-02-28 16:52244---ha-wC:\sqmnoopt11.sqm
2009-04-20 23:50 . 2009-02-26 04:13268---ha-wC:\sqmdata10.sqm
2009-04-20 23:50 . 2009-02-26 04:13244---ha-wC:\sqmnoopt10.sqm
2009-04-20 23:41 . 2009-02-25 01:08268---ha-wC:\sqmdata09.sqm
2009-04-20 23:41 . 2009-02-25 01:08244---ha-wC:\sqmnoopt09.sqm
2009-04-19 17:38 . 2009-02-24 01:39268---ha-wC:\sqmdata08.sqm
2009-04-19 17:38 . 2009-02-24 01:39244---ha-wC:\sqmnoopt08.sqm
2009-04-18 19:30 . 2009-02-23 23:11268---ha-wC:\sqmdata07.sqm
2009-04-18 19:30 . 2009-02-23 23:11244---ha-wC:\sqmnoopt07.sqm
2009-04-18 19:14 . 2008-09-16 00:04--------d-----wc:\program files\Safari
2009-04-18 17:52 . 2009-02-23 02:34268---ha-wC:\sqmdata06.sqm
2009-04-18 17:52 . 2009-02-23 02:34244---ha-wC:\sqmnoopt06.sqm
2009-04-17 22:42 . 2009-02-21 13:53268---ha-wC:\sqmdata05.sqm
2009-04-17 22:42 . 2009-02-21 13:53244---ha-wC:\sqmnoopt05.sqm
2009-04-17 16:26 . 2009-02-19 11:52268---ha-wC:\sqmdata04.sqm
2009-04-17 16:26 . 2009-02-19 11:52244---ha-wC:\sqmnoopt04.sqm
2009-04-17 03:02 . 2009-02-19 02:29268---ha-wC:\sqmdata03.sqm
2009-04-17 03:02 . 2009-02-19 02:29244---ha-wC:\sqmnoopt03.sqm
2009-04-15 18:17 . 2009-02-16 01:23268---ha-wC:\sqmdata02.sqm
2009-04-15 18:17 . 2009-02-16 01:23244---ha-wC:\sqmnoopt02.sqm
2009-04-09 02:17 . 2009-02-14 23:29268---ha-wC:\sqmdata01.sqm
2009-04-09 02:17 . 2009-02-14 23:29244---ha-wC:\sqmnoopt01.sqm
2009-04-07 20:18 . 2008-01-27 20:51268---ha-wC:\sqmdata00.sqm
2009-04-07 20:18 . 2008-01-27 20:51244---ha-wC:\sqmnoopt00.sqm
2009-04-07 19:41 . 2009-03-08 16:39268---ha-wC:\sqmdata19.sqm
2009-04-07 19:41 . 2009-03-08 16:39244---ha-wC:\sqmnoopt19.sqm
2009-04-07 01:06 . 2009-03-08 15:41268---ha-wC:\sqmdata18.sqm
2009-04-07 01:06 . 2009-03-08 15:41244---ha-wC:\sqmnoopt18.sqm
2009-03-26 23:17 . 2007-03-18 17:331786--sha-wc:\windows\system32\KGyGaAvL.sys
2009-03-26 23:17 . 2007-01-03 14:19--------d-----wc:\documents and settings\Janet Frye\Application Data\Corel
2009-03-26 19:23 . 2007-12-25 14:2136864----a-wc:\windows\system32\drivers\usbaapl.sys
2009-03-20 19:24 . 2009-03-13 00:29--------d-----wc:\documents and settings\Janet Frye\Application Data\Move Networks
2009-03-02 01:00 . 2008-11-13 00:1834----a-wc:\documents and settings\Janet Frye\jagex_runescape_preferences.dat
2008-09-15 22:58 . 2006-12-21 03:4693288----a-wc:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-01-02 16:50 . 2008-01-02 16:5032----a-wc:\documents and settings\All Users\Application Data\ezsid.dat
2006-12-31 18:15 . 2006-12-31 17:14133----a-wc:\documents and settings\Janet Frye\Local Settings\Application Data\fusioncache.dat
2006-12-21 03:46 . 2008-01-21 16:2670568----a-wc:\documents and settings\Kyle\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-12-21 03:46 . 2008-01-21 16:1870568----a-wc:\documents and settings\Trevor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-12-21 03:46 . 2006-12-31 17:1470568----a-wc:\documents and settings\Janet Frye\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-12-21 03:46 . 2006-12-31 17:1470568----a-wc:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-11-16 17:12 . 2007-01-15 17:1232----a-rc:\documents and settings\All Users\hash.dat
2005-08-17 02:52 . 2008-01-21 16:26136----a-wc:\documents and settings\Kyle\Local Settings\Application Data\fusioncache.dat
2005-08-17 02:52 . 2008-01-21 16:18136----a-wc:\documents and settings\Trevor\Local Settings\Application Data\fusioncache.dat
2005-08-17 02:52 . 2006-12-31 17:14136----a-wc:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2005-08-17 02:52 . 2005-08-17 02:52136----a-wc:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2002-07-26 22:02 . 2007-07-11 18:08153088----a-wc:\program files\UNWISE.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Janet Frye^Start Menu^Programs^Startup^Picture MOTION Browser Media Check Tool.lnk]
path=c:\documents and settings\Janet Frye\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\Pinnacle\\Shared Files\\Programs\\MediaManager\\PMSManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-08-30 29744]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-04-26 c:\windows\Tasks\Check UPDATES for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{4AFC04A3-B551-4B68-9BEB-8677D90150D9} - c:\windows\system32\wincontrol.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth MALWARE detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-26 09:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1241513954-2828669199-4241389553-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,27,fe,ff,64,28,
e1,63,cf,c8,28,51,af,b0,29,a3,98,42,10,56,5d,c2,7d,b5,ce,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,b7,2c,d8,b4,34,
86,66,78,71,3b,04,66,8b,46,0d,96,6b,87,eb,48,ec,5a,ce,ce,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,9e,62,0c,ba,20,
EE,d4,d1,25,da,ec,7e,55,20,c9,26,88,2e,d2,24,0c,76,4d,b4,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,86,c8,d2,9d,fd,
33,27,e7,3e,1e,9e,e0,57,5a,93,61,92,c2,b0,41,ce,2c,98,b8,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,ac,dd,0d,a0,ed,
76,ee,78,cd,44,cd,b9,a6,33,6c,cd,cd,66,bf,f6,11,f1,a4,8a,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,3b,17,b5,9b,65,
26,d9,91,b0,18,ed,a7,3f,8d,37,a4,80,fc,94,6c,a0,f7,be,7a,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,57,f1,31,f4,3d,
d8,6d,82,31,77,e1,ba,b1,f8,68,02,a3,84,e2,fa,14,e2,f5,26,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,73,7f,1a,05,b0,
f4,72,79,83,6c,56,8b,a0,85,96,ab,86,d2,01,c1,44,5f,3c,90,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,44,72,2d,18,11,
9c,6e,37,51,fa,6e,91,28,9e,14,cc,d0,ce,cb,cc,b1,d5,f6,88,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,72,98,b4,bd,2b,
53,95,76,b1,cd,45,5a,a8,c4,f8,b9,90,7a,84,11,4e,8b,15,5f,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,fb,f2,a6,4e,49,
56,71,a5,e3,0e,66,d5,eb,bc,2f,6b,e4,28,b4,09,10,b9,58,eb,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,1d,8f,5c,f2,30,
8b,b3,f9,fa,ea,66,7f,d4,3b,6b,70,6f,93,78,82,8f,1c,ad,a6,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\0* 2*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\�*& 2*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\�*& Æ]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1072)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\Creative LABS Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-04-26 9:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-26 13:32

Pre-Run: 86,817,038,336 bytes free
Post-Run: 88,891,490,304 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
338--- E O F ---2009-04-16 14:58

3662.

Solve : I have a few trojans, please help asap?

Answer»

Working on that now. Is my computer completely free of Trojans?It's free of anything I can find. I don't TELL anyone they are completely MALWARE free, not even myself...

There is always a chance.Okay, THANK you very much, you saved my computer. (Or at least some repair BILLS)

3663.

Solve : Possible virus infection?

Answer»

As SUGGESTED by Broni, I am POSTING here to check if my computer is virus free

Any help is MUCH appreciated

Here are the logs:




[attachment deleted by admin]

3664.

Solve : Laptop internet connection problems (all 3 logs)?

Answer»

This laptop has FRUSTRATED me for WEEKS. It has had continuous wireless networking problems in the PAST. But after the results of one of my desktops, I began to think this was a PROBLEM done by some sort of malware.

[attachment deleted by admin]

3665.

Solve : Can someone please look at my logs??

Answer»

My comouter was hijacked by a version of the Vundo trojan. I posted on the Networking forum first because my internet connection blew right when my computer was pumped with trojans and rogue anti-spywares. I have logs from MBAM, HJT and SAS. Thanks for the help.



[attachment deleted by admin]Bad news I'm afraid.

The logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. Trying to fix this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information.

Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace!

Do not back up to another machine, as it may become compromised. Burn to DVD/CD, or to an external DRIVE which has nothing else on it, and which you can format should it happen to become infected from the backups.

I suggest running at least 3 of the below scanners on the backup files. Run the first SCAN then reboot before running the second then reboot after the second before running the third.

-) Dr.Web CureIt!
-) AVG Win32/Virut Removal Tool
-) Symantwc W32.Virut Removal Tool
-) McAfee Avert Stinger
-) Microsoft Windows Malicious SOFTWARE Removal Tool

If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

I strongly suggest you do the following immediately!

If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.

From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.
Unfortunately I think I am locked out of my computer. i ran that CureIt removal tool and when I restarted my computer, a blue screen came up with my USERNAME. I clicked on my username and it says saving files, logging off and restarts the log in screen again. You have to reformat and reinstall. http://www.windowsreinstall.com/I don't have the Windows XP CD, so I cannot reinstall that way.

Is there a way I can reformat without the CD?Nope. You have to have a CD. Can you borrow one?I could, though it is unlikely.

I have 3 computers in my home, 2 desktops and 1 laptop. The desktop I am posting on right now is clean (it's mine the other 2 are from other family members). Would you mind if I post HJT, MBAM and SAS logs of the laptop that has had problems connecting to the internet (but no real adware, pop-ups or trojans) in this topic?Please start a new topic for separate computers.Thank you so much for aiding me through this. My other computer's logs are in my other topic.

3666.

Solve : Pictures to external hardrive?

Answer»

Hey, I know that my computer is infected with MALWARE and VIRUSES and stuff and Im working on fixing it. But if I were to move my pictures from my computer to an external HARDRIVE would the infections move onto the external hardrive as WELL? Quote from: Avooc on APRIL 26, 2009, 04:53:50 PM

Hey, I know that my computer is infected with malware and viruses and stuff and Im working on fixing it. But if I were to move my pictures from my computer to an external hardrive would the infections move onto the external hardrive as well?
That depends on what is infecting your computer.
3667.

Solve : problem on my office?

Answer»

Does not mean piracy is right.Quote from: Carbon Dudeoxide on April 26, 2009, 06:41:09 PM

Does not mean piracy is right.

Of course not!ok i buy office after i get my salary ok i just only try pirate office bcoz' on off my GAVE my installer
Quote from: hackers128gb on April 26, 2009, 08:41:58 PM
... i just only try pirate office bcoz' on off my gave my installer

That MADE no sense whatsoever. Is English not your native language?

OpenOffice.org is a free office suite. Perhaps it would meet your needs; it has enough FEATURES for MANY computer users who need word processing, spreadsheet, etc. ok tnx i will try again using openoffice
3668.

Solve : All of my browers stop working sporadically?

Answer»

This is a repost from almost 2 weeks ago, I havn't gotten any reponses. I really need HELP with this.

All of my browers (IE, Firefox, and Opera) stop working sporadically, and the only WAY I can get them to work is to do a hard shutdown. My system will not allow me to do a soft shutdown, or reset when the browsers stop working. I am still able to use instant messengers when this happens. I had a virus a few days ago but I don't think it is completely gone, even though the virus was causing a completely different problem (see six POINTED star post) Here are the logs that were mentioned to post.

[attachment deleted by admin]It doesn't appear to be a malware issue.

A few things to try.

Reset SETTINGS for Internet Explorer 6

Reset Explorer Settings IE 6

Reset Settings in Internet Explorer 7

Reset Explorer Settings IE 7

----------

Does this behavior persist if you START IE7 in No Add-ons mode?

IE7 in No Add-ons mode

    1. Right-click on the blue IE desktop icon and select Start without Add-ons;

    2. Start > (All) Programs > Accessories > System Tools > Internet Explorer
    (No add-ons).

Troubleshooting and Internet Explorer’s (No Add-ons) Mode:
http://blogs.msdn.com/ie/archive/2006/07/25/678113.aspx

RIES
Does the problem persist if you Reset IE7 Settings (RIES)?
http://support.microsoft.com/kb/923737 <- Read before using!
3669.

Solve : logs to look at?

Answer»

pc take awhile to boot up.also when i open the broswer the first time or email
the first time on any giving day they are slow to open also.this has been for
a couple of weeks now. thanks

[ATTACHMENT deleted by admin]HI last couple of weeks my pc boots real slow.also once it's going if i open the
browser or email they take awhile to open only on the first try .as LONG as i don't shut down. can someone take a look at these logs. i followed the REMARKS on
what to do .thanks.

[attachment deleted by admin]

3670.

Solve : can someone look at these logs??

Answer» ALRIGHT, THANKS for all the TIME you have SPENT HELPING me!!!
3671.

Solve : Disable Autoplay to prevent virus from being spread via removable disk?

Answer»

Just something to keep in mind when using USB sticks to transfer data between PCs.

Disable Autoplay to prevent virus from being spread VIA removable disk
Removable storage devices such as USB flash memory has simple plug-and-play design that allows you to EASILY and quickly transfer and store data. However it also makes virus and spyware spread easily. Many viruses transmit via USB drives by utilizing system Autorun features. To do this a virus FIRST copies itself and the "autorun.ini" file into removable disk. When you plug your removable disk into your PC, the system reads the autorun.ini first, then it runs the virus executable file specified in autorun.ini. The virus executable is then launched and copied to your system. To protect your system against this kind of virus/spyware, you need to disable the Autorun features on your system.

To disable Autorun features, please follow these steps.

1. Click Start, then click Run, type "gpedit.msc" to open the Group Policy dialog.
2. In the left pane, expand the Computer Configuration in LOCAL Computer Policy.
3. Then locate and expand Administrative Templates.
4. Select System.
5. In the right pane, double click Turn off Autoplay to open the properties dialog.
6. Select the Enabled radio box. In the Turn off Autoplay on: select list, select
All drives to disable autoplay on all drives.
7. Click OK to save the change.
8. Done.

Better to be safe than sorry....Good advice, but note that it will not work on Windows XP Home Edition and Media Center Edition.

Not sure about Vista.Quote

and Media Center Edition.

That is the same as XP Pro so it should work.

This should work on anything. Panda USB and AutoRun VaccineQuote from: evilfantasy on April 28, 2009, 09:47:59 AM
That is the same as XP Pro so it should work.
Oh gpedit exists on MCE? Didn't know that. Thanks. Yep. MCE is XP Pro with a TV card.
3672.

Solve : Checking for programs that may be commandeering my internet?

Answer»

In addition to the problems I have posted, I have had problems with my dsl modem. When I cannot get an internet connection, the modem "dsl" light is on, the "internet" light is off but the access light to my computer is flashing rapidly. I have gone through all the steps on your SITE to remove malware and have come up with nothing serious. So will someone look at my Hyjack This log. It seems ok. I have also run the hackerwhacker trace port but it doesn't SEEM to finish.

[attachment deleted by admin]Have you tried disabling Zone Alarm?Yes, then turn it back on and everything RETURNS to normal. However, sometimes I have to reboot the modem.Your settings/software/??? must not be agreeing with Zome Alarm.

Try another good free firewall.

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you CHOOSE this ONE)
2) Online Armor
3) Sunbelt/Kerio
4) Agnitum
5) PC Tools Firewall Plus

3673.

Solve : Help! Can someone please check this log and advise, Thanks?

Answer»
Re: Can't open Internet Properties or attach files to my e-mail
« Reply #26 on: April 26, 2009, 04:10:28 PM »

I ran Hijackthis and the log is below. I am sure there is something here that is not right. Can it be checked? I took no further ACTION after running the scan. Can you advise on what I should do next?

Many thanks
Brenda

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:00:22 PM, on 4/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\INTEL\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\CyberLink Codec\PDVDServ.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADL.EXE
C:\Program Files\Google\Google DESKTOP Search\GoogleDesktop.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\JAVA\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Administrator\Application Data\Smilebox\SmileboxTray.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\igfxsrvc.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search BAR = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [igfxhkcmd] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [igfxpers] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "HDAShCut.exe"
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"
O4 - HKLM\..\Run: [AGRSMMSG] "AGRSMMSG.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [IndicatorUtility] "C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe"
O4 - HKLM\..\Run: [LoadFUJ02E3] "C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe"
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] "C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe"
O4 - HKLM\..\Run: [LoadBtnHnd] "C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink Codec\PDVDServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] "c:\PROGRA~1\mcafee.com\agent\mcagent.exe"
O4 - HKLM\..\Run: [MCUpdateExe] "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe"
O4 - HKLM\..\Run: [MPFExe] "C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector v2] "C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe"
O4 - HKLM\..\Run: [MsmqIntCert] "regsvr32" /s mqrt.dll
O4 - HKLM\..\Run: [EPSON Stylus CX4700 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADL.EXE" /P26 "EPSON Stylus CX4700 Series" /O6 "USB001" /M "Stylus CX4700"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [QuickCare2.2] "C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" /P QuickCare2.2
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [FJUPDNV_Chitose] "C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] "C:\PROGRA~1\AVG\AVG8\avgtray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SmileboxTray] "C:\Documents and Settings\Administrator\Application Data\Smilebox\SmileboxTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {63232850-FBA2-4316-9C20-35944F7F07B1} - http://qwest.live.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by113fd.bay113.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-00AA0055595A} - http://www.networksolutionsemailpopwizard.com/TrueSwitchEC.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

--
End of file - 18002 byte
3674.

Solve : This can't take much to fix.......Please?

Answer»

So my avast professional is going to expire, I tried to go back and download the free home edition and it would not let me. So I put the pro back on and everything has gone haywire since then and I don't know if that is the reason why. My yahoo mail won't let me sign on and check my mail, it just gives me a blank page. Not only that I can't click on links or go to microsoft updates? Please help. I can't even click to add more attachments so I'll have to copy and paste. sorry



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:06 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.evansville.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.evansville.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [TVTunerLib] C:\Program Files\Common Files\Sony Shared\TVTunerLib\TVTLInstTool.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VZRemoteCommander] C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_1
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - EXTRA context menu item: Transfer by Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1176776688203
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown OWNER - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment FILE Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 12519 bytes


Malwarebytes' Anti-Malware 1.36
Database version: 2047
Windows 5.1.2600 Service Pack 3

4/27/2009 9:26:05 AM
mbam-log-2009-04-27 (09-26-05).txt

Scan type: Quick Scan
Objects scanned: 79785
Time elapsed: 7 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



[attachment deleted by admin]

3675.

Solve : pls help re: wma/trojandownloader.getcodec.gen?

Answer»

i downloaded a file from limewire but what i gotis this nasty trojan instead.
pls help m remove this threat before my wife throws me out of our house.

Norman Malware Cleaner
Copyright © 1990 - 2009, Norman ASA. Built 2009/04/24 09:14:41

Norman Scanner Engine Version: 6.00.06
Nvcbin.def Version: 6.00.00, Date: 2009/04/24 09:14:41, Variants: 3125455

Scan started: 25/04/2009 02:53:06

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Home 5.1.2600(Safe mode with network) Service Pack 2
Logged on user: YOUR-CAB733E7E9\Administrator

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\WINDOWS\System32\iassdo32.dll" -> ""


Scanning running processes and process memory...

C:\WINDOWS\Explorer.EXE(1420) (C:\WINDOWS\system32\6D.tmp!0x033E0000) (Infected with W32/Agent.LFUR)
File marked for defered cleaning (reboot required)

Number of processes/threads found: 744
Number of processes/threads scanned: 744
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 0
Total scanning time: 16s


Scanning file system...

Scanning: C:\*.*

C:\WINDOWS\system32\6D.tmp (Infected with W32/Agent.LFUR)
File marked for defered cleaning (reboot required)

C:\WINDOWS\system32\NetworkService32\117.crack.zip/crack.by.ORiON/crack.exe (Infected with W32/DLoader.OFDJ)
Deleted file

C:\WINDOWS\system32\NetworkService32\118.keygen.zip/keygen.from.Black.X/keygen.exe (Infected with W32/DLoader.OFDK)
Deleted file

C:\WINDOWS\system32\NetworkService32\120.setup.zip/keygen_from_iFLUENCE/keygen.exe (Infected with W32/DLoader.OFDJ)
Deleted file


Running post-scan cleanup routine:
Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\WINDOWS\System32\iassdo32.dll" -> ""

Number of files found: 154289
Number of archives unpacked: 5711
Number of files scanned: 154280
Number of files not scanned: 9
Number of files skipped due to exclude list: 0
Number of infected files found: 4
Number of infected files repaired/deleted: 3
Number of infections removed: 3
Total scanning time: 23m 42s


------------------------------------------------------------------


here's my hjt log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:30:21 AM, on 4/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\PowerS.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\VM303_STI.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\ManyCam 2.3\ManyCam.exe
C:\Program Files\SpeedItUpFree\SpeedItUp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\59fc8f12b80caa991163249076d0bcca\update\update.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://reg.vugames.com/home.do?sku=71608&src=WREG
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PowerS] C:\WINDOWS\PowerS.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\SpeedItUpFree\SpeedItUp.exe -MINI
O4 - Startup: IMVU.lnk = C:\Documents and Settings\Steven\Application Data\IMVUClient\IMVUClient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Steven\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112219676640
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EA53CA55-AB2B-461B-BE08-2A9F2E770168}: NameServer = 192.168.1.1,192.168.1.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\iassdo32.dll
O20 - Winlogon Notify: 2cab3e87579 - C:\WINDOWS\System32\iassdo32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Network Location Awareness (NLA) (Nla) - Unknown owner - C:\Program Files\websrv\websrv.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10572 bytes
Download Malwarebytes' Anti-Malware (MBAM)

Alternate MBAM download link

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.thanks a lot for the quick reply. here's the log from mbam:


    Malwarebytes' Anti-Malware 1.36
    Database version: 2036
    Windows 5.1.2600 Service Pack 3

    4/25/2009 6:52:50 AM
    mbam-log-2009-04-25 (06-52-50).txt

    Scan type: Quick Scan
    Objects scanned: 86118
    Time elapsed: 4 minute(s), 1 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 1
    Files Infected: 60

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\iassdo32.dll (Trojan.Agent) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\2cab3e87579 (Trojan.Agent) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\iassdo32.dll -> Delete on reboot.

    Folders Infected:
    C:\WINDOWS\system32\NetworkService32 (Worm.Archive) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\iassdo32.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\NetworkService32\117.crack.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\117.crack.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\118.keygen.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\118.keygen.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\119.serial.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\119.serial.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\120.setup.zip (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\120.setup.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\121.music.mp3 (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\121.music.mp3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\122.music.snd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\122.music.snd.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\123.music.au (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\123.music.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\124.video.wmv (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\NetworkService32\124.video.wmv.kwd (Worm.Archive) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gpkrsrc32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\fmark2.dat (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drmstor32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dmdskmgr32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DHCPMON32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\glu3232.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\imm3232.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dmutil32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\ImagX732.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\eventcls32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fltlib32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\duser32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DGSETUP32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dimap32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dmime32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dmocx32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DMSERVER32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DMSYNTH32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DOCPROP32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dpcdll32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DPNADDR32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DPSERIAL32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DPVOICE32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DPWSOCKX32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DSOUND3D32.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dssenh32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\DINPUT832.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dswave32.dll (Worm.P2P) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drprov32.dll (Worm.P2P) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dplayx32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dpnmodem32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\encdec32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\fsusd32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\els32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\f49f4daa.dat (Trojan.Koobface) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\iasads32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dxdiagn32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dxtmsft32.dll (Worm.P2P) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gcdef32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\es32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\iasrad32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dpnhupnp32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\dispex32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    Download DDS by sUBs and save it to your desktop. Alternate DDS download link

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.dds

    DDS (Ver_09-03-16.01) - NTFSx86
    Run by Steven at 7:06:50.92 on Sat 04/25/2009
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.483 [GMT 8:00]

    AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Outdated)

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\PowerS.exe
    C:\Program Files\Multimedia Card Reader\shwicon2k.exe
    C:\WINDOWS\LTMSG.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\VM303_STI.EXE
    C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\ManyCam 2.3\ManyCam.exe
    C:\Program Files\SpeedItUpFree\SpeedItUp.exe
    svchost.exe
    svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Steven\Desktop\dds.pif

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
    uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
    uWindow Title = Windows Internet Explorer provided by Yahoo!
    uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = https://reg.vugames.com/home.do?sku=71608&src=WREG
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    mSearchAssistant = hxxp://www.google.com/ie
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_9
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [ManyCam] "c:\program files\manycam 2.3\ManyCam.exe"
    uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
    uRun: [SpeedItUpEX] c:\program files\speeditupfree\SpeedItUp.exe -MINI
    mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [PowerS] c:\windows\PowerS.exe
    mRun: [Sunkist2k] c:\program files\multimedia card reader\shwicon2k.exe
    mRun: [farstone]
    mRun: [LTMSG] LTMSG.exe 7
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [nwiz] nwiz.exe /install
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
    mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
    mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [BigDog303] c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
    mRun: [LVCOMS] c:\program files\common files\logitech\qcdriver3\LVCOMS.EXE
    mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [nod32upd] rundll32 "c:\program files\eset\fc_upd.dll",NOD32Ioctl
    mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
    StartupFolder: c:\docume~1\steven\startm~1\programs\startup\imvu.lnk - c:\documents and settings\steven\application data\imvuclient\IMVUClient.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
    IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
    IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\steven\start menu\programs\imvu\Run IMVU.lnk
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    LSP: c:\windows\system32\imon.dll
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112219676640
    DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
    DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R0 SI3112r;ATI-437A Serial ATA Controller;c:\windows\system32\drivers\SI3112r.sys [2004-8-28 97920]
    R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-4-25 15424]
    R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2009-4-25 552064]
    R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-10 602392]
    R3 CXTuner;Conexant TVTuner;c:\windows\system32\drivers\CXTuner.sys [2005-3-31 28127]
    R3 CXVideo;Conexant Capture;c:\windows\system32\drivers\CXVCap.sys [2005-3-31 100092]
    R3 CXXBar;Conexant CROSSBAR;c:\windows\system32\drivers\CXXBar.sys [2005-3-31 8301]
    R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
    R3 SunkFilt62;Alcor Micro Corp - 6362;c:\windows\system32\drivers\sunkfilt62.sys [2004-7-24 46536]
    S2 Network Location Awareness (NLA) (Nla) ;Network Location Awareness (NLA) (Nla) ;c:\program files\websrv\websrv.exe --> c:\program files\websrv\websrv.exe [?]
    S3 SunkFilt6;Alcor Micro Corp - 6360;\??\c:\windows\system32\drivers\sunkfilt6.sys --> c:\windows\system32\drivers\sunkfilt6.sys [?]

    =============== Created Last 30 ================

    2009-04-25 06:59512,096a-------c:\windows\system32\drivers\amon.sys
    2009-04-25 06:59298,104a-------c:\windows\system32\imon.dll
    2009-04-25 06:5915,424a-------c:\windows\system32\drivers\nod32drv.sys
    2009-04-25 06:47--d-----c:\docume~1\steven\applic~1\Malwarebytes
    2009-04-25 06:4715,504a-------c:\windows\system32\drivers\mbam.sys
    2009-04-25 06:4638,496a-------c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-25 06:46--d-----c:\program files\Malwarebytes' Anti-Malware
    2009-04-25 06:46--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-04-25 04:39--d-----c:\windows\system32\scripting
    2009-04-25 04:39--d-----c:\windows\system32\en
    2009-04-25 04:39--d-----c:\windows\l2schemas
    2009-04-25 04:39--d-----c:\windows\system32\bits
    2009-04-25 04:36--d-----c:\windows\ServicePackFiles
    2009-04-25 04:30--d-----c:\windows\EHome
    2009-04-25 04:30--d-----c:\program files\Trend Micro
    2009-04-25 02:2514,123a-------c:\windows\GnuHashes.ini
    2009-04-24 19:571,542a--sh---c:\windows\system32\GroupPolicy000.dat
    2009-04-24 19:56615a-------c:\windows\system32\OiUCZVG.vbs
    2009-04-24 19:56615a-------c:\windows\system32\GHz7U94BXB0tf.vbs
    2009-04-24 19:53615a-------c:\windows\system32\q3RkZjT3pCdOpdK.vbs
    2009-04-24 19:500a-------c:\windows\system32\iasnap32.dll
    2009-04-24 19:480a-------c:\windows\system32\inetmib132.dll
    2009-04-24 19:480a-------c:\windows\system32\inetcfg32.dll
    2009-04-24 19:480a-------c:\windows\system32\imeshare32.dll
    2009-04-24 19:480a-------c:\windows\system32\ImagXpr732.dll
    2009-04-24 19:480a-------c:\windows\system32\imagr532.dll
    2009-04-24 19:39615a-------c:\windows\system32\ontfZYW.vbs
    2009-04-21 20:562,297,552a-------c:\windows\system32\d3dx9_26.dll
    2009-04-21 20:55--d-----c:\windows\system32\AGEIA
    2009-04-21 20:54--d-----c:\program files\common files\Wise Installation Wizard
    2009-04-21 11:2549,152a----r--c:\windows\amcap.exe
    2009-04-17 13:34284,160-c------c:\windows\system32\dllcache\pdh.dll
    2009-04-17 13:34401,408-c------c:\windows\system32\dllcache\rpcss.dll
    2009-04-17 13:34110,592-c------c:\windows\system32\dllcache\services.exe
    2009-04-17 13:34473,600-c------c:\windows\system32\dllcache\fastprox.dll
    2009-04-17 13:34729,088-c------c:\windows\system32\dllcache\lsasrv.dll
    2009-04-17 13:34453,120-c------c:\windows\system32\dllcache\wmiprvsd.dll
    2009-04-17 13:34227,840-c------c:\windows\system32\dllcache\wmiprvse.exe
    2009-04-17 13:34714,752-c------c:\windows\system32\dllcache\ntdll.dll
    2009-04-17 13:34617,472-c------c:\windows\system32\dllcache\advapi32.dll
    2009-04-17 13:342,145,280-c------c:\windows\system32\dllcache\ntkrnlmp.exe
    2009-04-17 13:342,189,056-c------c:\windows\system32\dllcache\ntoskrnl.exe
    2009-04-17 13:332,023,936-c------c:\windows\system32\dllcache\ntkrpamp.exe
    2009-04-17 13:112,560--------c:\windows\system32\xpsp4res.dll
    2009-04-17 13:11215,552-c------c:\windows\system32\dllcache\wordpad.exe
    2009-04-08 20:57--d-----c:\program files\Alcohol Soft
    2009-04-07 22:1364,902a-------c:\windows\War3Unin.dat
    2009-04-07 22:13139,264a-------c:\windows\War3Unin.exe
    2009-04-07 22:132,829a-------c:\windows\War3Unin.pif
    2009-04-07 21:182,036,576a-------c:\windows\system32\D3DCompiler_40.dll
    2009-04-07 21:18452,440a-------c:\windows\system32\d3dx10_40.dll
    2009-04-07 21:184,379,984a-------c:\windows\system32\D3DX9_40.dll
    2009-04-07 21:181,358,192a-------c:\windows\system32\D3DCompiler_35.dll
    2009-04-07 21:18444,776a-------c:\windows\system32\d3dx10_35.dll
    2009-04-07 21:183,727,720a-------c:\windows\system32\d3dx9_35.dll
    2009-04-07 21:18--d-----c:\windows\Logs
    2009-04-05 21:36--dsh---c:\documents and settings\steven\IECompatCache

    ==================== Find3M ====================

    2009-04-25 04:4176,487a-------c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-04-24 14:521,513a-------c:\windows\eReg.dat
    2009-04-22 17:4890,112a-------c:\windows\DUMP68cc.tmp
    2009-03-19 00:59724,992a-------c:\windows\iun6002.exe
    2009-03-09 05:19410,984a-------c:\windows\system32\deploytk.dll
    2009-03-08 04:34914,944a-------c:\windows\system32\wininet.dll
    2009-03-08 04:3443,008a-------c:\windows\system32\licmgr10.dll
    2009-03-08 04:3318,944a-------c:\windows\system32\corpol.dll
    2009-03-08 04:33420,352a-------c:\windows\system32\vbscript.dll
    2009-03-08 04:3272,704a-------c:\windows\system32\admparse.dll
    2009-03-08 04:3271,680a-------c:\windows\system32\iesetup.dll
    2009-03-08 04:3134,816a-------c:\windows\system32\imgutil.dll
    2009-03-08 04:3148,128a-------c:\windows\system32\mshtmler.dll
    2009-03-08 04:3145,568a-------c:\windows\system32\mshta.exe
    2009-03-08 04:22156,160a-------c:\windows\system32\msls31.dll
    2009-03-06 22:22284,160a-------c:\windows\system32\pdh.dll
    2009-02-09 20:10729,088a-------c:\windows\system32\lsasrv.dll
    2009-02-09 20:10714,752a-------c:\windows\system32\ntdll.dll
    2009-02-09 20:10617,472a-------c:\windows\system32\advapi32.dll
    2009-02-09 20:10401,408a-------c:\windows\system32\rpcss.dll
    2009-02-09 19:131,846,784a-------c:\windows\system32\win32k.sys
    2009-02-07 19:022,066,048a-------c:\windows\system32\ntkrnlpa.exe
    2009-02-06 19:11110,592a-------c:\windows\system32\services.exe
    2009-02-06 19:082,189,056a-------c:\windows\system32\ntoskrnl.exe
    2009-02-06 18:3935,328a-------c:\windows\system32\sc.exe
    2009-02-04 15:291,023a-------c:\windows\fonts\kamn____.PFM
    2009-02-04 15:291,091a-------c:\windows\fonts\heln____.PFM
    2009-02-04 03:5956,832a-------c:\windows\system32\secur32.dll
    2009-01-28 20:1332,328a-------c:\docume~1\steven\applic~1\GDIPFONTCACHEV1.DAT

    ============= FINISH: 7:07:19.21 ===============







    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-03-16.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 6/7/2005 11:45:49 AM
    System Uptime: 4/25/2009 7:02:12 AM (0 hours ago)

    Motherboard: | | RS480-M
    Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 2199/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 183 GiB total, 155.343 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: 1394 Net Adapter
    Device ID: V1394\NIC1394\FF2E43E00AE6
    Manufacturer: Microsoft
    Name: 1394 Net Adapter
    PNP Device ID: V1394\NIC1394\FF2E43E00AE6
    Service: NIC1394

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    99 Slot Machine
    A4 TECH USB PC Camera H
    Adobe Flash Player 10 ActiveX
    Adobe Shockwave Player 11
    AGEIA PhysX v7.05.17
    ATI - Software Uninstall Utility
    ATI Control Panel
    ATI Display Driver
    BearShare
    Camfrog Video Chat 5.2
    Command & Conquer Generals
    Critical Update for Windows Media Player 11 (KB959772)
    EarthLink MDAC
    Font Creator Program 4.1
    Google Toolbar for Internet Explorer
    HangARoo v2.05
    HijackThis 2.0.2
    Horse Racing Fantasy Community Edition
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    ImTOO 3GP Video Converter
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 7
    Java(TM) 6 Update 13
    LimeWire PRO 4.18.8
    Logitech QuickCam
    Logitech QuickCam Driver Package
    Logitech Updater
    Malwarebytes' Anti-Malware
    ManyCam 2.3 (remove only)
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional with FrontPage
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft XML Parser
    Mighty Slots
    MS Access 97 SP2
    MSN
    MSSoap
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6 Service Pack 2 (KB954459)
    Multimedia Card Reader
    Nero Media Player
    Nero OEM
    NeroVision Express 3
    NOD32 antivirus system
    NOD32 FiX v2.1
    Octoshape add-in for Adobe Flash Player
    PaperPort
    Plenty Jackpot
    PokerStars
    Real Vegas Online
    Realtek AC'97 Audio
    Security Update for CAPICOM (KB931906)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB913433)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    SimCity 3000 Unlimited
    Skype™ 3.8
    Slot Nuts
    Speeditup Free 4.01
    Super Bounce Out! from GameHouse
    Super Collapse! from GameHouse
    Super TextTwist
    Tom Clancy's Ghost Recon Advanced Warfighter® 2
    TV Station
    Update for Windows Internet Explorer 8 (KB968220)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VIP Slots
    Warcraft III: All Products
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinFast(R) Display Driver
    WinRAR archiver
    Yahoo! Messenger
    Yahoo! Software Update
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    4/25/2009 2:18:36 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips nod32drv Processor
    4/25/2009 2:17:23 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    4/24/2009 10:39:20 AM, error: System Error [1003] - Error code 0000004e, parameter1 0000008f, parameter2 0002809d, parameter3 00019385, parameter4 00000000.
    4/24/2009 10:39:17 AM, error: System Error [1003] - Error code 100000d1, parameter1 00000000, parameter2 00000002, parameter3 00000000, parameter4 eb4bc456.
    4/24/2009 10:39:13 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 bf9fb70f, parameter3 eccf689c, parameter4 00000000.
    4/21/2009 11:27:49 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805200dc, parameter3 efb4ec34, parameter4 00000000.
    4/21/2009 11:27:47 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 00000002, parameter3 00000001, parameter4 804f990b.
    4/20/2009 12:02:08 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000000, parameter2 00000002, parameter3 00000001, parameter4 8051e2f2.
    4/20/2009 12:02:06 AM, error: System Error [1003] - Error code 100000d1, parameter1 00000000, parameter2 00000006, parameter3 00000001, parameter4 f7484857.
    4/20/2009 12:02:05 AM, error: System Error [1003] - Error code 1000000a, parameter1 02080120, parameter2 00000002, parameter3 00000000, parameter4 805073a4.
    4/20/2009 12:02:03 AM, error: System Error [1003] - Error code 100000d1, parameter1 00001000, parameter2 00000002, parameter3 00000001, parameter4 f7670ed6.
    4/19/2009 11:59:50 PM, error: System Error [1003] - Error code 0000004e, parameter1 00000099, parameter2 00000000, parameter3 00000000, parameter4 00000000.

    ==== End Of File ===========================

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    DO NOT run it YET!

    Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    DDS::
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    ----------

    Download JavaRa
    • Unzip the file and open the JavaRa.exe
    • Click Remove Older Versions
    • JavaRa will search for and remove any outdated version of Java and remove any that are found.
    • Click Additional Tasks
    • Place a check next to Remove Useless JRE Files and click Go
    • Exit JavaRa
    • Delete the JavaRa files from the Desktop
    am i finished after i removed the javara files? btw, what are the javara files in my desktop? are those the dds, combofix? thanks a lot for your help. you are heaven-sent to me You can delete the JavaRa files.

    Did you work through the ComboFix instructions? I need the log it created.ComboFix 09-04-25.03 - Steven 04/25/2009 7:32.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.573 [GMT 8:00]
    Running from: c:\documents and settings\Steven\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Steven\Desktop\CFScript.txt
    * Created a new restore point
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Administrator\Application Data\020000002cc36e2c579C.manifest
    c:\documents and settings\Administrator\Application Data\020000002cc36e2c579O.manifest
    c:\documents and settings\Administrator\Application Data\020000002cc36e2c579P.manifest
    c:\documents and settings\Administrator\Application Data\020000002cc36e2c579S.manifest
    c:\documents and settings\Steven\Application Data\020000002cc36e2c579C.manifest
    c:\documents and settings\Steven\Application Data\020000002cc36e2c579O.manifest
    c:\documents and settings\Steven\Application Data\020000002cc36e2c579P.manifest
    c:\documents and settings\Steven\Application Data\020000002cc36e2c579S.manifest
    c:\program files\messenger\msmsgs.exe
    c:\windows\GnuHashes.ini
    c:\windows\system32\DIconLib32.dll
    c:\windows\system32\dmconfig32.dll
    c:\windows\system32\dsauth32.dll
    c:\windows\system32\dsdmoprp32.dll
    c:\windows\system32\dskquoui32.dll
    c:\windows\system32\dsquery32.dll
    c:\windows\system32\esent9732.dll
    c:\windows\system32\expsrv32.dll
    c:\windows\system32\faultrep32.dll
    c:\windows\system32\filemgmt32.dll
    c:\windows\system32\fmifs32.dll
    c:\windows\system32\fontsub32.dll
    c:\windows\system32\fwcfg32.dll
    c:\windows\system32\getuname32.dll
    c:\windows\system32\GroupPolicy000.dat
    c:\windows\system32\hccoin32.dll
    c:\windows\system32\hid32.dll
    c:\windows\system32\HLINKPRX32.dll
    c:\windows\system32\hnetmon32.dll
    c:\windows\system32\hpicon32.dll
    c:\windows\system32\hpzcoi0732.dll
    c:\windows\system32\hticons32.dll
    c:\windows\system32\hypertrm32.dll
    c:\windows\system32\iasnap32.dll
    c:\windows\system32\imagr532.dll
    c:\windows\system32\ImagXpr732.dll
    c:\windows\system32\imeshare32.dll
    c:\windows\system32\inetcfg32.dll
    c:\windows\system32\inetmib132.dll
    c:\windows\TEMP\logishrd\LVPrcInj01.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_NETWORK_LOCATION_AWARENESS_(NLA)_(NLA)_
    -------\Service_Network Location Awareness (NLA) (Nla)


    ((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-4-24 )))))))))))))))))))))))))))))))
    .

    2009-04-24 22:47 . 2009-04-24 22:47--------d-----wc:\documents and settings\Steven\Application Data\Malwarebytes
    2009-04-24 22:47 . 2009-04-06 07:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-04-24 22:46 . 2009-04-06 07:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-24 22:46 . 2009-04-24 22:46--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-24 20:50 . 2009-04-24 20:50--------d-sh--wc:\windows\system32\config\systemprofile\IETldCache
    2009-04-24 20:39 . 2009-04-24 20:39--------d-----wc:\windows\system32\scripting
    2009-04-24 20:39 . 2009-04-24 20:39--------d-----wc:\windows\system32\en
    2009-04-24 20:39 . 2009-04-24 20:39--------d-----wc:\windows\l2schemas
    2009-04-24 20:39 . 2009-04-24 20:39--------d-----wc:\windows\system32\bits
    2009-04-24 20:36 . 2009-04-24 20:36--------d-----wc:\windows\ServicePackFiles
    2009-04-24 20:30 . 2009-04-24 20:30--------d-----wc:\windows\EHome
    2009-04-24 18:18 . 2009-04-24 18:18--------d-sh--wc:\documents and settings\Administrator\PrivacIE
    2009-04-24 11:56 . 2009-04-24 11:56615----a-wc:\windows\system32\OiUCZVG.vbs
    2009-04-24 11:56 . 2009-04-24 11:56615----a-wc:\windows\system32\GHz7U94BXB0tf.vbs
    2009-04-24 11:53 . 2009-04-24 11:53615----a-wc:\windows\system32\q3RkZjT3pCdOpdK.vbs
    2009-04-24 11:39 . 2009-04-24 11:39615----a-wc:\windows\system32\ontfZYW.vbs
    2009-04-21 12:56 . 2005-05-26 07:342297552----a-wc:\windows\system32\d3dx9_26.dll
    2009-04-21 12:55 . 2009-04-21 12:55--------d-----wc:\windows\system32\AGEIA
    2009-04-21 03:25 . 2005-12-22 06:1049152----a-rc:\windows\amcap.exe
    2009-04-17 05:34 . 2009-03-06 14:22284160-c----wc:\windows\system32\dllcache\pdh.dll
    2009-04-17 05:34 . 2009-02-09 12:10401408-c----wc:\windows\system32\dllcache\rpcss.dll
    2009-04-17 05:34 . 2009-02-06 11:11110592-c----wc:\windows\system32\dllcache\services.exe
    2009-04-17 05:34 . 2009-02-09 12:10473600-c----wc:\windows\system32\dllcache\fastprox.dll
    2009-04-17 05:34 . 2009-02-09 12:10729088-c----wc:\windows\system32\dllcache\lsasrv.dll
    2009-04-17 05:34 . 2009-02-09 12:10453120-c----wc:\windows\system32\dllcache\wmiprvsd.dll
    2009-04-17 05:34 . 2009-02-06 10:10227840-c----wc:\windows\system32\dllcache\wmiprvse.exe
    2009-04-17 05:34 . 2009-02-09 12:10714752-c----wc:\windows\system32\dllcache\ntdll.dll
    2009-04-17 05:34 . 2009-02-09 12:10617472-c----wc:\windows\system32\dllcache\advapi32.dll
    2009-04-17 05:34 . 2009-02-06 11:062145280-c----wc:\windows\system32\dllcache\ntkrnlmp.exe
    2009-04-17 05:34 . 2009-02-06 11:082189056-c----wc:\windows\system32\dllcache\ntoskrnl.exe
    2009-04-17 05:33 . 2009-02-06 10:322023936-c----wc:\windows\system32\dllcache\ntkrpamp.exe
    2009-04-17 05:11 . 2008-05-03 11:552560------wc:\windows\system32\xpsp4res.dll
    2009-04-17 05:11 . 2008-04-21 12:08215552-c----wc:\windows\system32\dllcache\wordpad.exe
    2009-04-07 14:13 . 2009-04-07 14:2164902----a-wc:\windows\War3Unin.dat
    2009-04-07 14:13 . 2009-04-07 14:202829----a-wc:\windows\War3Unin.pif
    2009-04-07 14:13 . 2009-04-07 14:20139264----a-wc:\windows\War3Unin.exe
    2009-04-07 13:18 . 2008-10-09 20:522036576----a-wc:\windows\system32\D3DCompiler_40.dll
    2009-04-07 13:18 . 2008-10-09 20:52452440----a-wc:\windows\system32\d3dx10_40.dll
    2009-04-07 13:18 . 2008-10-09 20:524379984----a-wc:\windows\system32\D3DX9_40.dll
    2009-04-07 13:18 . 2007-07-19 10:14444776----a-wc:\windows\system32\d3dx10_35.dll
    2009-04-07 13:18 . 2007-07-19 10:141358192----a-wc:\windows\system32\D3DCompiler_35.dll
    2009-04-07 13:18 . 2007-07-19 10:143727720----a-wc:\windows\system32\d3dx9_35.dll
    2009-04-07 13:18 . 2009-04-07 13:18--------d-----wc:\windows\Logs
    2009-04-05 13:36 . 2009-04-05 13:36--------d-sh--wc:\documents and settings\Steven\IECompatCache

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-24 23:34 . 2008-12-01 08:33--------d-----wc:\program files\Eset
    2009-04-24 22:47 . 2009-04-24 22:46--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-04-24 21:53 . 2006-09-16 00:00896216----a-wc:\documents and settings\Steven\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-04-24 20:41 . 2005-03-30 21:1276487----a-wc:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-04-24 20:35 . 2005-03-31 20:04250048--sha-rC:\ntldr
    2009-04-24 20:30 . 2009-04-24 20:30--------d-----wc:\program files\Trend Micro
    2009-04-24 17:37 . 2008-11-30 11:18--------d-----wc:\program files\PokerStars
    2009-04-24 12:46 . 2009-01-17 06:46--------d-----wc:\program files\Slot Nuts
    2009-04-24 12:45 . 2009-01-17 06:26--------d-----wc:\program files\Plenty Jackpot
    2009-04-24 12:45 . 2009-01-17 06:35--------d-----wc:\program files\Mighty Slots
    2009-04-24 12:36 . 2009-01-12 06:34--------d-----wc:\program files\99 Slot Machine
    2009-04-24 11:59 . 2008-12-01 08:25--------d-----wc:\program files\LimeWire
    2009-04-24 11:58 . 2008-12-01 08:25--------d-----wc:\documents and settings\Steven\Application Data\LimeWire
    2009-04-24 06:52 . 2005-03-30 21:17--------d--h--wc:\program files\InstallShield Installation Information
    2009-04-24 06:52 . 2005-06-07 04:021513----a-wc:\windows\eReg.dat
    2009-04-24 06:46 . 2005-06-07 03:56--------d-----wc:\program files\EA Games
    2009-04-24 06:33 . 2009-03-18 16:59--------d-----wc:\program files\SpeedItUpFree
    2009-04-24 05:59 . 2008-11-15 13:12--------d-----wc:\documents and settings\Steven\Application Data\Skype
    2009-04-24 02:45 . 2008-11-16 07:51--------d-----wc:\documents and settings\Steven\Application Data\skypePM
    2009-04-23 06:58 . 2008-11-15 14:27398----a-wC:\Shortcut to My Documents.lnk
    2009-04-22 09:48 . 2005-03-30 13:0290112----a-wc:\windows\DUMP68cc.tmp
    2009-04-22 09:29 . 2009-04-07 14:11--------d-----wc:\program files\Warcraft III
    2009-04-21 12:55 . 2009-04-21 12:55--------d-----wc:\program files\AGEIA Technologies
    2009-04-21 12:54 . 2009-04-21 12:54--------d-----wc:\program files\Common Files\Wise Installation Wizard
    2009-04-21 12:47 . 2009-04-21 12:47--------d-----wc:\program files\UBISOFT
    2009-04-19 15:27 . 2009-04-19 15:201119----a-wC:\aoeWVlog.txt
    2009-04-19 15:26 . 2009-04-19 15:206006----a-wC:\aoedoppl.txt
    2009-04-08 12:57 . 2009-04-08 12:57--------d-----wc:\program files\Alcohol Soft
    2009-03-29 10:21 . 2006-07-06 22:50--------d-----wc:\program files\Java
    2009-03-23 17:54 . 2006-06-29 01:00--------d-----wc:\program files\Common Files\Adobe
    2009-03-21 17:20 . 2008-11-16 08:08--------d-----wc:\documents and settings\All Users\Application Data\Yahoo!
    2009-03-21 17:20 . 2006-10-22 03:55--------d-----wc:\program files\Yahoo!
    2009-03-21 17:20 . 2008-11-16 08:14--------d-----wc:\documents and settings\All Users\Application Data\Yahoo! Companion
    2009-03-18 16:59 . 2009-03-18 16:59724992----a-wc:\windows\iun6002.exe
    2009-03-18 07:02 . 2009-03-18 07:02--------d-----wc:\documents and settings\Steven\Application Data\Uniblue
    2009-03-08 21:19 . 2009-02-02 05:26410984----a-wc:\windows\system32\deploytk.dll
    2009-03-08 03:03 . 2008-11-15 13:08--------d-----wc:\documents and settings\Steven\Application Data\BearShare
    2009-03-07 20:34 . 2005-03-31 20:04914944----a-wc:\windows\system32\wininet.dll
    2009-03-07 20:34 . 2005-03-31 20:0443008----a-wc:\windows\system32\licmgr10.dll
    2009-03-07 20:33 . 2005-03-31 20:0418944----a-wc:\windows\system32\corpol.dll
    2009-03-07 20:33 . 2005-03-31 20:04420352----a-wc:\windows\system32\vbscript.dll
    2009-03-07 20:32 . 2005-03-31 20:0472704----a-wc:\windows\system32\admparse.dll
    2009-03-07 20:32 . 2005-03-31 20:0471680----a-wc:\windows\system32\iesetup.dll
    2009-03-07 20:31 . 2005-03-31 20:0434816----a-wc:\windows\system32\imgutil.dll
    2009-03-07 20:31 . 2005-03-31 20:0448128----a-wc:\windows\system32\mshtmler.dll
    2009-03-07 20:31 . 2005-03-31 20:0445568----a-wc:\windows\system32\mshta.exe
    2009-03-07 20:22 . 2005-03-31 20:04156160----a-wc:\windows\system32\msls31.dll
    2009-03-06 14:22 . 2005-03-31 20:04284160----a-wc:\windows\system32\pdh.dll
    2009-03-03 15:59 . 2009-03-02 01:29--------d-----wc:\program files\Common Files\Logitech
    2009-03-02 03:04 . 2009-03-02 03:04--------d-----wc:\program files\Common Files\LogiShrd
    2009-03-02 03:04 . 2009-03-02 03:04--------d-----wc:\documents and settings\All Users\Application Data\Logishrd
    2009-03-02 03:04 . 2009-03-02 03:04--------d-----wc:\documents and settings\All Users\Application Data\Logitech
    2009-03-02 03:04 . 2009-03-02 01:27--------d-----wc:\program files\Logitech
    2009-03-02 01:50 . 2009-03-02 01:28183----a-wC:\LogiSetup.log
    2009-03-02 01:29 . 2009-03-02 01:29--------d-----wc:\program files\Windows Media Components
    2009-02-09 12:10 . 2005-03-31 20:04729088----a-wc:\windows\system32\lsasrv.dll
    2009-02-09 12:10 . 2005-03-31 20:04401408----a-wc:\windows\system32\rpcss.dll
    2009-02-09 12:10 . 2005-03-31 20:04714752----a-wc:\windows\system32\ntdll.dll
    2009-02-09 12:10 . 2005-03-31 20:04617472----a-wc:\windows\system32\advapi32.dll
    2009-02-09 11:13 . 2005-03-31 20:041846784----a-wc:\windows\system32\win32k.sys
    2009-02-07 11:02 . 2004-08-03 22:592066048----a-wc:\windows\system32\ntkrnlpa.exe
    2009-02-06 11:11 . 2005-03-31 20:04110592----a-wc:\windows\system32\services.exe
    2009-02-06 11:08 . 2005-03-31 20:042189056----a-wc:\windows\system32\ntoskrnl.exe
    2009-02-06 10:39 . 2005-03-31 20:0435328----a-wc:\windows\system32\sc.exe
    2009-02-03 19:59 . 2005-03-31 20:0456832----a-wc:\windows\system32\secur32.dll
    2009-01-28 12:13 . 2009-01-28 12:1332328----a-wc:\documents and settings\Steven\Application Data\GDIPFONTCACHEV1.DAT
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
    "ManyCam"="c:\program files\ManyCam 2.3\ManyCam.exe" [2008-10-14 1791272]
    "SpeedItUpEX"="c:\program files\SpeedItUpFree\SpeedItUp.exe" [2009-04-24 2274816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-01 344064]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "PowerS"="c:\windows\PowerS.exe" [2001-08-04 159800]
    "Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2004-12-10 139264]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-29 4620288]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-10-29 86016]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
    "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
    "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
    "BigDog303"="c:\windows\VM303_STI.EXE" [2005-10-25 61440]
    "LVCOMS"="c:\program files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
    "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
    "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
    "nod32upd"="c:\program files\Eset\fc_upd.dll" [2009-04-24 3584]
    "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-22 77824]
    "LTMSG"="LTMSG.exe" - c:\windows\ltmsg.exe [2003-07-14 40960]
    "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-10-29 921600]
    "BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\EA Games\\Command and Conquer Generals\\patchget.dat"=

    R3 SunkFilt6;Alcor Micro Corp - 6360;

    S0 SI3112r;ATI-437A Serial ATA Controller;c:\windows\system32\DRIVERS\SI3112r.sys [2004-08-28 97920]
    S2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
    S3 CXTuner;Conexant TVTuner;c:\windows\system32\drivers\CXTuner.sys [2004-04-07 28127]
    S3 CXVideo;Conexant Capture;c:\windows\system32\drivers\CXVCap.sys [2004-04-07 100092]
    S3 CXXBar;Conexant Crossbar;c:\windows\system32\drivers\CXXBar.sys [2004-04-07 8301]
    S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
    S3 SunkFilt62;Alcor Micro Corp - 6362;c:\windows\System32\Drivers\sunkfilt62.sys [2004-07-23 46536]


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
    c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-24 c:\windows\Tasks\User_Feed_Synchronization-{7E8807C1-9A2A-4268-91BD-AD92DAF46F7A}.job
    - c:\windows\system32\msfeedssync.exe [2006-10-17 20:31]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
    HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
    HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    HKLM-Run-farstone - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = https://reg.vugames.com/home.do?sku=71608&src=WREG
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Steven\Start Menu\Programs\IMVU\Run IMVU.lnk
    DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-25 07:35
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)?0?[emailprotected]??

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(516)
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(6920)
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\windows\system32\nview.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\OneX.DLL
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\nvwddi.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    c:\windows\system32\rundll32.exe
    c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
    c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
    .
    **************************************************************************
    .
    COMPLETION time: 2009-04-24 7:38 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-04-24 23:38

    Pre-Run: 166,826,389,504 bytes free
    Post-Run: 167,150,800,896 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    305--- E O F ---2009-04-24 21:41
    Go to Start > Run and type notepad.exe then click OK

    Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

    Code: [Select]REGEDIT4

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    .
    Locate fixme.reg on your Desktop and double-click it.

    Answer Yes when prompted to merge with the Registry.

    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

    Delete the fixme.reg from the Desktop.

    ----------

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    How is the computer running now?everything is WORKING fine now, and a little faster may i add. thanks a lot for your help. at least my wife wont be angry why i stayed up all night! Sounds good.

    Torrents/P2P/Warez...whatever you call it is always a big risk. You could be giving away your identity by using them. Then I'm sure she would really be mad!

    Final suggestions.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

    3676.

    Solve : system error NvCpl.dll?

    Answer»

    I use Windows Vista version 6. days ago I got the message of system error Rundll
    NvCpl.dll " impossible to find the module"
    It appears at the end of the beginning of the first session. Nero Vision , Scanner, Photoshop, are not working; Internet, Epson print, and other programm seems to work well.
    I try three programs antispyware but it doesn't work althought some infections were cancelled, but the principle on remain inside my computer
    I add a scan log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9.55.56, on 28/04/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot MODE: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    C:\Windows\ehome\ehtray.exe
    C:\Users\Utente\AppData\Local\eqcay.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Acer\Acer VCM\AcerVCM.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Users\Utente\AppData\Local\Temp\RtkBtMnt.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
    C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
    C:\Program Files\Acer\Acer VCM\acp2HID.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://it.rd.yahoo.com/customize/ycomp/defaults/sp/*http://it.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.repubblica.it/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://it.intl.acer.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://it.intl.acer.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://it.rd.yahoo.com/customize/ycomp/defaults/su/*http://it.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll (file missing)
    O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\FlyNet\CnxDslTb.exe"
    O4 - HKLM\..\Run: [Skytel] Skytel.exe
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [EPSON Stylus DX9400F Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICFE.EXE /FU "C:\Windows\TEMP\E_S4EAE.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [eqcay] "c:\users\utente\appdata\local\eqcay.exe" eqcay
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
    O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Startup: Sommario di OneNote.onetoc2
    O4 - Global Startup: Acer VCM.lnk = ?
    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{51C44EDD-80DB-4903-AA02-59DC61693114}: NameServer = 193.70.152.15 193.70.152.25
    O17 - HKLM\System\CCS\Services\Tcpip\..\{94855534-3589-4CF9-B477-24660C1520A9}: NameServer = 192.133.28.1,192.133.28.7
    O18 - PROTOCOL: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
    O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 10743 bytes



    someone could help me ? thanks a lot

    3677.

    Solve : I thought Spybot Search & Destroy wasn't good anymore??

    Answer»

    Lifehacker LIKES it, usually lifehacker's GOT good stuff but I wonder http://lifehacker.com/5231837/hive-five-winner-for-best-malware-removal-tool-spybot-search--destroyTrusted YES but by far not the most powerful anymore. Malwarebytes and SUPERANTISPYWARE by far.I thought people said SUPERAntiSpyware had problems? Something like false positives? not sure .... but a problem NONETHELESS .... I fully support SUPERAntiSpyware and am even giving away a free lifetime license for the pro version on my blog. See here http://evilfantasy.wordpress.com/2009/04/28/free-superantispyware-pro-giveaway/

    3678.

    Solve : Anything Wrong??

    Answer»

    I noticed a few days ago Yahoo IM took FOREVER to load....also noticed that Adobe Acrobat froze when searching document...i looked quickly and saw something like KGB Keylogger?....but thought I would come to you for help

    Yahoo Messenger Version 9.0.0.2152 (NOTE....... all the time i was posting logs Yahoo didn't come up)
    Adobe Acrobat Version 8.1.3

    Computer Dell GX620 Running Windows XP Home Version 2002 Service Pack 3
    Intel Pentium D CPU 2.80GHZ 3.5G Ram Intel 82945G Express Chipset Family

    I followed your TUTORIAL step by step

    SAS picked up nothing

    MBAM Log:

    Malwarebytes' Anti-Malware 1.36
    Database version: 2046
    Windows 5.1.2600 Service Pack 3

    4/26/2009 4:53:50 PM
    mbam-log-2009-04-26 (16-53-50).txt

    Scan type: Quick Scan
    Objects scanned: 95530
    Time elapsed: 8 minute(s), 20 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Java is V6 Update 13...should be latest (I checked)

    HJT Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:20:39 PM, on 4/26/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Windows Media Player\WMPNetwk.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\AccuWeatherDesktop\AccuWeatherDesktop.exe
    C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    C:\Program Files\ShortKeys2\shortkey.exe
    C:\Program Files\Qlock\qlock.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\JRIVER~1\MEDIAC~2\MEDIAC~1.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ams-server*
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: TW_BrowserHook - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - (no file)
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
    O4 - HKCU\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART
    O4 - HKCU\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
    O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe" (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User '?')
    O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')
    O4 - S-1-5-21-515941520-1664358963-1588231850-1006 Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe (User '?')
    O4 - Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe
    O4 - Global Startup: AccuWeather.com® Desktop.lnk = ?
    O4 - Global Startup: PrintKey-Pro.lnk = ?
    O4 - Global Startup: QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\Poker.exe (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
    O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
    O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
    O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL,avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Update Service (gupdate1c9949bd8522a78) (gupdate1c9949bd8522a78) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

    --
    End of file - 19096 bytes

    Thanks for your help!!!


    you should have posted the sas log and let an expert tell you its clear , harryThanks,

    Here's the SAS log and a new hjt Log.

    SAS

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/27/2009 at 06:05 PM

    Application Version : 4.26.1000

    Core Rules Database Version : 3864
    Trace Rules Database Version: 1815

    Scan type : Complete Scan
    Total Scan Time : 01:49:30

    Memory items scanned : 783
    Memory threats detected : 0
    Registry items scanned : 7810
    Registry threats detected : 0
    File items scanned : 108073
    File threats detected : 0

    HJT Log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:23:50 PM, on 4/27/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Windows Media Player\WMPNetwk.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\AccuWeatherDesktop\AccuWeatherDesktop.exe
    C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    C:\Program Files\ShortKeys2\shortkey.exe
    C:\Program Files\Qlock\qlock.exe
    C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\JRIVER~1\MEDIAC~2\MEDIAC~1.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ams-server*
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: TW_BrowserHook - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - (no file)
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
    O4 - HKCU\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART
    O4 - HKCU\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe" (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User '?')
    O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')
    O4 - S-1-5-21-515941520-1664358963-1588231850-1006 Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe (User '?')
    O4 - Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe
    O4 - Global Startup: AccuWeather.com® Desktop.lnk = ?
    O4 - Global Startup: PrintKey-Pro.lnk = ?
    O4 - Global Startup: QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\Poker.exe (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
    O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
    O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
    O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL,avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    O23 - Service: Google Update Service (gupdate1c9949bd8522a78) (gupdate1c9949bd8522a78) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

    --
    End of file - 18919 bytes
    Thanks again
    Disable Ad-Aware as it may interfere with repairs

    • Click the Settings button, AUTO Scans tab, and under Scan on Ad-Aware startup
    • Be sure both selections for No automated scan are checked (green).
    • Then click Save and close Ad-Aware.
    .
    ----------

    Open HijackThis and select Do a system scan only

    Vista users right click on HijackThis and select Run as Administrator. (you will receive a UAC prompt, please allow it)

    Place a check mark next to the following entries: (if there)

    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    • R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: TW_BrowserHook - {1E1B2879-88FF-11D2-8D96-FFFFAC95951F} - (no file)
    • O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    • O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - (no file)
    • O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    How is the computer running?Looks Pretty Good

    YIM still takes 5 minutes to appear?

    HJT Log after fix

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:50:06 PM, on 4/27/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\AccuWeatherDesktop\AccuWeatherDesktop.exe
    C:\Program Files\Windows Media Player\WMPNetwk.exe
    C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe
    C:\Program Files\ShortKeys2\shortkey.exe
    C:\Program Files\Qlock\qlock.exe
    C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ams-server*
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s
    O4 - HKCU\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART
    O4 - HKCU\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" -s (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [MRC] "C:\Program Files\PC Tune-Up\PCTuneUp.exe" /MBRSTART (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe" (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (User '?')
    O4 - HKUS\S-1-5-21-515941520-1664358963-1588231850-1006\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User '?')
    O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')
    O4 - S-1-5-21-515941520-1664358963-1588231850-1006 Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe (User '?')
    O4 - Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe
    O4 - Global Startup: AccuWeather.com® Desktop.lnk = ?
    O4 - Global Startup: PrintKey-Pro.lnk = ?
    O4 - Global Startup: QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe
    O4 - Global Startup: ShortKeys 2.lnk = C:\Program Files\ShortKeys2\shortkey.exe
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\Poker.exe (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
    O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
    O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
    O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} (Jolly Bear Games Player) - http://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
    O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL,avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Update Service (gupdate1c9949bd8522a78) (gupdate1c9949bd8522a78) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

    --
    End of file - 17830 bytes
    Do you know what these are?

    Quote
    O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User '?')

    O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')

    no idea!Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixEnclosed are ComboFix and HJT logs


    [attachment deleted by admin]Disable Ad-Aware as it may interfere with repairs

    • Click the Settings button, Auto Scans tab, and under Scan on Ad-Aware startup
    • Be sure both selections for No automated scan are checked (green).
    • Then click Save and close Ad-Aware.
    .
    ----------

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    • O4 - HKUS\S-1-5-18\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User '?')
    • O4 - HKUS\.DEFAULT\..\RunOnce: [{91120000-0012-0000-0000-0000000FF1CE}] C:\WINDOWS\system32\cmd.exe /C del "C:\Documents and Settings\All Users\Application Data\Microsoft Help\Rgstrtn.lck" /Q /A:H (User 'Default user')
    .
    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis.

    ----------

    Go to Start > Run and type notepad.exe then click OK

    Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

    Code: [Select]REGEDIT4

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "{91120000-0012-0000-0000-0000000FF1CE}"=-
    Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

    Delete the fixme.reg from the Desktop.

    ----------

    Use the ESET Online Antivirus Scanner

    This scanner requires Internet Explorer

    1. Check the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the activex CONTROL to install
    4. Click Start
    5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
    6. Click Scan
    7. Wait for the scan to finish
    8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here are the eset scan log and new hjt log.

    The fixme DID work

    [attachment deleted by admin]
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      How is the computer running now?
    Here's hoping? I will have to live with slow Yahoo I guess.

    latest hjt log attached. Thank you for your help!!! ^5

    [attachment deleted by admin]

    Check out my blog for a chance for a free lifetime subscription to SUPERAntiSpyware Pro. http://evilfantasy.wordpress.com/2009/04/28/free-superantispyware-pro-giveaway/

    You can cut down on some of your startups. Might help with the speed issues.

    StartupLite
    • Download StartupLite by MalwareBytes to your Desktop.
    • Doubleclick StartupLite.exe to launch the program.
    • Ensure the Disable box is checked.
    • Click Continue.
    • A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
    • Re-start your computer.
    .
    ----------

    I would also recommend that you Defrag the computer.

    You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

    Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.

    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    3679.

    Solve : computer shut off in middle of search now won't start up?

    Answer»

    My sister-in-law was doing search for a new car and all of a sudden her computer shut off and we can not GET it to boot back up TRIED to go in thru safe mode but it just locks up can not select anything. Can some one give me some help please I thought about trying to reformat hard drive but thought I'd seek your help and advice first. she has avast antivirus on computer but said it has been doing funny THINGS for the last week and running very slow.
    thank you for your time.A virus would make it run sow. But if if cn not turn on it must be a hardware or mechanicla problem. Maybe the switch is broken?
    You do mean that the screen will not light up?
    Or the computer starts, but Windows will not show up?sorry about that, it will turn on but locks up tried to go into save mode but locks up when it comes to the screen that U can select to go into safe mode.

    3680.

    Solve : 'Error loading dll32' message?

    Answer»

    Still not fixed....I installed Firefox to see if I could connect to the Internet that WAY but it does not work either.Download and run WinSockFix.
    This is a two step process that will Back up the Registry and Reset the Winsock Stack.

    • Double click on WinsockXPFix.exe to open.
    • On the Winsock and TCP Repair Utility screen, click "ReG-Backup"
    • On the ERDNT Welcome screen, click "OK".
    • On the Backup to: screen, click "OK".
    • On the Folder does not exist question screen click "Yes".
    • You will see a status screen as your registry is being backed up.
    • On the Registry backup is complete! screen, click "OK" and you will go back to the main window.
    • On the Winsock and TCP Repair Utility screen, click "Fix".
    • On the Apply the VB_Winsock fix? screen click "Yes".
    • The screen will display a status message "repair completed please reboot."
    • On the Repair Completed screen click "OK" to reboot your computer.
    • If your computer was not using DHCP, you will need to reconfigure TCP/IP.
    • Hopefully you should have connectivity restored.
    .
    Note: Resetting the Winsock in SP2 might remove third-party LSPs and RESTORES Winsock to factory default setting. Existing programs that uses their own LSPs may need to be REINSTALLED. Example: Google Desktop Search.I still can't connect through IE or Firefox.

    I ALSO got the following errors while running WinSockFix:

    ERROR Saving file C:\ERDNT\SECURITY!
    " " SOFTWARE!
    " " SYSTEM!
    " " DEFAULT!
    " " SAM!

    C:\ERDNT\Users\S-1-5-21-3581506895-2163411867-2876842818-1006\ntuser.dat!
    C:\ERDNT\Users\S-1-5-21-3581506895-2163411867-2876842818-1006_Classes\UsrClass.dat!


    3681.

    Solve : Search engine results redirected?

    Answer»

    here it is

    [attachment deleted by admin]You should uninstall either Avast or McAfee. Two antivirus is never suggested. Leads to too many problems.

    Scan with Panda ActiveScan 2.0

    This scanner REQUIRES Internet Explorer

    • Once you are on the Panda site click the Scan your PC now button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Select the appropriate Yes or No to receiving marketing information
    • Click the Free Online Scan button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    .
    Post the contents of the ActiveScan report in your next reply.For some reason, i am unable to uninstall Avast. Everytime i click on the "Uninstall" button in Add/Remove Programs, nothing happens, the screen stays the same, and Avast doesnt get removed.



    [attachment deleted by admin]Use the avast! uninstall UTILITY. http://www.avast.com/eng/avast-uninstall-utility.html

    ---

    Clearing Java Cache

    Go to Start > Control Panel and double-click the Java Icon
    • On the General tab, under Temporary Internet Files, click the SETTINGS button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      • Applications
      • Applets Trace and Log Files
    • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
    • Click OK to leave the Temporary Files Window
    • Click OK to leave the Java Control Panel.
    .
    ----------

    Download RegASSASSIN.exe to the desktop.

    Open RegAssassin and copy the Registry Key in the Code box below.

    Code: [Select]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{965e6b07-6832-4738-bdbe-25f226ba2ab0}
      Now paste it in RegAssassins window and click
    Delete.

    ----------

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Download ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    Download OTCleanIt.exe and save it to your Desktop.
    • Double-click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it yourself.
    .
    Important: Restart the computer before continuing.

    ----------

    How is the computer running now?
    well, i did everything on your list, and my computer was running fine. everything was back to normal

    But just yesterday, when i restarted my computer, i kept getting this error message ("lsass.exe - Application Error") and Windows would not load.
    I even tried running in safe mode. But Windows will not load, and i keep getting that error message.So it's ran fine for a week or so and now it won't boot?Quote from: evilfantasy on April 28, 2009, 10:11:52 AM
    So it's ran fine for a week or so and now it won't boot?
    Yea, pretty much.is there anything that can be done?
    What happens when you try to start the computer?this is all that happens:
    i start my computer
    the microsoft windows loading screen pops up
    it then switches to a black screen with an error message that pops up reading: "lsass.exe application error"
    the application failed to initialize properly (0xc0000005). click ok to terminate the application.

    and if you click ok it goes AWAY and just stays at a black screenhttp://www.updatexp.com/0xC0000005.html
    3682.

    Solve : Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp]?

    Answer»

    This is why my first and only suggestion when I see virut is to reformat and reinstall. Until then you can never be sure if the computer is clean or not.

    Stay away from warez. It only takes one click and it's all over...Virut ADDS one or more iFrame tags to any html file it finds to redirect users to an exploit site.

    Edit any html file on the INFECTED computer and you'll see something like this at the bottom:

    Code: [Select]<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah
    Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.

    The most damning property of Virut is that it is polymorphic- it changes slightly with each replication, allowing some of the files infected to elude scanners. So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.

    Trying to remove Virut is an EFFORT in futility, which is why evilfantasy and virtually every other malware expert who has experience with this infection will tell you that your only option is to reformat and reinstall, and to be careful what you transfer from your previous installation.

    But feel free to keep trying. You'll just end up learning the hard way like I did.
    Great post astrosoup and WELCOME to CH. Quote from: evilfantasy on April 23, 2009, 12:58:19 PM

    Great post astrosoup and welcome to CH.
    That site is known to give you Bloodhound.Exploit.196, is blocked by google and is rated extremely poorly on WOT...(link from googling http://ZieF.pl/rc/ that link doesn't go to the site for safety reasons)

    For more information go to http://www.google.com/safebrowsing/diagnostic?site=http://zief.pl/rc/&hl=en

    Visiting a site that has been injected with the iframe code while currently using the NoScript addon for firefox will not affect you as NoScript BLOCKS iframes. But going to the actual website will infect you...I wonder if viewing the page source will get me infected...It's definitely a nasty site. Does a LOT of damage. http://www.threatexpert.com/report.aspx?md5=71eb4db6da3338655c1ec3cb48489d03
    Quote from: astrosoup on April 23, 2009, 12:54:04 PM
    So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.
    Like I said, I did not perform a reinstall and deleted all the files from the previous system. The current system is a fresh install and I previously formated the current system partition. All I did I kept other files, which were not infected according to kaspersky tool.

    Quote from: astrosoup on April 23, 2009, 12:54:04 PM
    Virut adds one or more iFrame tags to any html file it finds to redirect users to an exploit site.

    Edit any html file on the infected computer and you'll see something like this at the bottom:

    Code: [Select]<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah
    Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.
    The iFrame problem, mentioned in an earlier post, happened on my wife's computer, while browsing. It was not a web file on the computer and avast blocked access to that page. That computer was not infected and I scanned it just in case [no sign of virut found, like I said].

    Quote from: astrosoup on April 23, 2009, 12:54:04 PM
    But feel free to keep trying. You'll just end up learning the hard way like I did
    If I get it again, from the files I have on my computer, I will let you know. But I'm not ready to throw all I have as long as I don't have a reason just yet. I would delete infected files, but not those found not to be infected. Maybe I'm wrong, maybe not. I'll see and let u know.
    3683.

    Solve : Things taking forever to open.?

    Answer»

    I have no idea whats going on. I turned my computer on this afternoon, and it started fine, *censored* hen I tried to open firefox and it took about 10 minutes to open. Same with internet explorer. Even task manager takes forever to open. I am current going through the malware removal guide. Could it be SOMETHING else? I mean once it is open it isn't slow.

    Quad core 2.3ghz

    500gb HDD (404 free)

    4 GB ram

    win xpWhat's the list on Task Manager?What do you mean?What is being shown(Everything in the list of proccesses) on Task Man.How do I post this?PrntScrn

    and also post a HijackThis Log.Well, it has quite a few processes(48) for prnt scrn.

    But here you go...



    and hjt is ATTACHED...

    [attachment deleted by admin]

    3684.

    Solve : Win32:Patched-CK [Trj]?

    Answer»

    Go back to http://virscan.org/ and click Browse then locate and scan the file. Post the results back here.again the same message "error: can't find upload file"Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:

    • Double-click on drweb-cureit.exe and then click Start
    • An information notice will appear, click OK.
    • This starts a short scan that will scan the files currently running in memory.
    • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
    • If or when something is found, click the Yes button when it asks you if you want to cure it.
    .
    • Once the short scan has finished, Click Settings > Change Settings
    • Under the Scanning tab UNcheck Heuristic analysis and click OK
    • Back at the main window, SELECT the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
    • Click Yes to all if it asks if you want to cure/move any file(s).
    • When the scan is done.
    • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
    • Save the DrWeb.csv report to your Desktop.
    • Exit Dr.Web Cureit.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    .
    * After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
    * Copy and paste that log in the next replyeverything works great
    no more avast alerts!!
    Dr.Web cured C:\windows\system32\services.exe file.
    i forget to Save report list, sorry

    Thank you for all of your great help.

    That was a tricky one. Glad it worked.

    Set a New Restore Point to prevent possible reinfection from an OLD one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    Check out my blog for a chance for a free lifetime subscription to SUPERAntiSpyware Pro. http://evilfantasy.wordpress.com/2009/04/28/free-superantispyware-pro-giveaway/

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla BASED browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    3685.

    Solve : Removing Antivirus?

    Answer»

    I have been reading various posts here that reccomend having only one antivirus installed & I mentioned this to my son. He has 4 different ones installed on his Compaq XP so I suggested he remove all but one. He is afraid to remove them because there are a lot of quarantined files. He showed me the Norton quarantined FILE & it was huge.

    What happens to the quarantined files when you remove the program? Can you list the four PROGRAMS?

    Norton Anti Virus (expired), Spy Bot S&D, Advanced System Care 3, Webroot Firewall & CC Cleaner. After looking at his list, I'm not so sure these would all fall into the same category.

    To get a new antivirus (which he needs) he would have to at least get rid of the Norton that has expired, but with all those quaranteened files, he's afraid it will crash. He purchased the computer second hand & there are no cd's to repair a crash. That is why I was asking what happens to the quaranteened files.Those will all work together.

    There is no good reason to keep quarantined files. All you can do with them is restore them and re-infect the computer. Uninstalling Norton will not crash the computer and I'm wondering why he thinks it will?

    Also an outdated antivirus is almost like not having any at all. It's very risky.

    First download a new antivirus. Do not install it yet!

    These are all free and are very good. Personally I use Avast Home Edition.

    Remember to only install one antivirus!

    1) Avast! Home Free Edition
    2) AVG Free Edition
    3) Avira AntiVir Personal

    ----------

    To completely remove Norton/Symantec go to add remove programs and UNINSTALL anything with Norton, Symantec or Live Update in the name.

    Download the Norton Removal Tool (SymNRT) to your Desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.

    • Go to your desktop and double click on the removal tool and then click Setup.
    • Once open Click Next
    • Accept the license agreement and click Next
    • Type in the letters/numbers that you see into the text box then click Next.
    • Then click Next and the tool will start running.
    • Once finished restart the PC.
    • Delete Nortonremoval tool from your Desktop.
    .
    ----------

    Now before going online install the new antivirus.He was afraid removing the program might delete necessary files the quaranteened files were attached to. That seems logical to me as well since the antivirus program imlpies just that when it suggests quaranteening files. I'm glad to learn it won't. I'll print your INSTRUCTIONS out for him.

    Thank You!Quote
    He was afraid removing the program might delete necessary files the quaranteened files were attached to.

    I understand the reasoning but if I may clarify. When an antivirus finds for example an important System File that is infected by malware it will "strip" the malicious code from it and then restore the cleaned file back to it's proper location. If it can not be cleaned it will either go ahead and quarantine it or leave it in PLACE then give you a warning of whatever action was taken. Once quarantined they can not be accessed by any program other than the antivirus to either restore them or remove them completely.

    The rule of thumb with quarantined files is leave them quarantined for a few days. If the computer is still running good then empty the quarantine.
    3686.

    Solve : "Unread mail message?"?

    Answer»

    The problem:

    At the log in screen, next to my account name, it says I have 1 unopned mail message. I suspect something is wrong. Posted are my 3 logs. Also, the remove hardware icon appears at the BOTTOM right hand corner of the START tool bar, even though NOTHING is plugged into the USB ports.

    Any ideas?

    Thanks!

    [attachment deleted by admin]Quote from: mareze2 on April 18, 2009, 09:33:16 PM

    The problem:

    At the log in screen, next to my account name, it says I have 1 unopned mail message. I suspect something is wrong. Posted are my 3 logs. Also, the remove hardware icon appears at the bottom right hand corner of the start tool bar, even though nothing is plugged into the USB ports.

    Any ideas?

    Thanks!
    That used to happen to me when I set my windows live messenger to start automatically...I would get an email (my old email and MSN were the same) and it would tell me at the log in screen. This shouldn't be a VIRUS problem, but I will let the experts LOOK at the logs.Thanks for the comment, but I'm not running windows live messenger.

    Waiting for the experts to get back to me...........
    3687.

    Solve : 'Bad Image' problems.?

    Answer»

    Whenever I start up the computer or it tries to run a program, before it runs I ALWAYS get a pop-up saying:
    The application of DLL C:\WINDOWS\system32\vopeside.dll is not a valid Windows image. Please check this against your installation diskette.

    I'm running Windows XP. It's a Dell Inspiron laptop (if that helps.)

    I'm attaching the logs and copy and pasting them below.
    _______________________________________ __________
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/18/2009 at 11:06 PM

    Application Version : 4.26.1000

    Core RULES Database Version : 3852
    Trace Rules Database Version: 1805

    Scan type : Complete Scan
    Total Scan Time : 01:31:10

    MEMORY items scanned : 727
    Memory threats detected : 0
    Registry items scanned : 5993
    Registry threats detected : 7
    File items scanned : 90275
    File threats detected : 45

    Unclassified.Unknown Origin
    HKU\S-1-5-21-4254542993-1360710644-2665431577-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{74CD40EA-EF77-4BAD-808A-B5982DA73F20}

    Adware.Tracking Cookie
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Blake\Cookies\[emailprotected][1].txt

    Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\contim
    HKLM\SOFTWARE\Microsoft\contim#SysShell
    HKLM\SOFTWARE\Microsoft\rdfa
    HKLM\SOFTWARE\Microsoft\rdfa#F
    HKLM\SOFTWARE\Microsoft\rdfa#N

    Rogue.Component/Trace
    HKU\S-1-5-21-4254542993-1360710644-2665431577-1006\Software\Microsoft\FIAS4057

    Malware.Installer-Pkg/Gen
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{651956B7-1969-42AA-9453-E0B813019D54}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{989E4C3B-B2C9-4486-9A09-D5A8F953837C}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C0A0AA4D-C79B-48CA-8843-2B02B626C9E6}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE

    Adware.Vundo/Variant-EmpiaA
    C:\WINDOWS\SYSTEM32\DAGIHAMA.DLL
    C:\WINDOWS\SYSTEM32\FIGOVAFA.DLL
    C:\WINDOWS\SYSTEM32\HIHATOFO.DLL
    C:\WINDOWS\SYSTEM32\RETOSETI.DLL

    Trace.Known Threat Sources
    C:\Documents and Settings\Blake\Local Settings\Temporary Internet Files\Content.IE5\28XRIA9B\l.s.bg1z[1].gif
    C:\Documents and Settings\Blake\Local Settings\Temporary Internet Files\Content.IE5\150GXJRB\favicon[2].ico
    C:\Documents and Settings\Blake\Local Settings\Temporary Internet Files\Content.IE5\WYDP5EX1\l.s.bg2z[1].gif
    _______________________________________ ________________
    Malwarebytes' Anti-Malware 1.36
    Database version: 2006
    Windows 5.1.2600 Service Pack 3

    4/18/2009 11:38:21 PM
    mbam-log-2009-04-18 (23-38-21).txt

    Scan type: Quick Scan
    Objects scanned: 71874
    Time elapsed: 6 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 3
    Registry Keys Infected: 8
    Registry Values Infected: 2
    Registry Data Items Infected: 1
    Folders Infected: 2
    Files Infected: 8

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\migisibi.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\smart.dll (Spyware.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\LoveFly.dll (Spyware.Agent) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ede0037-cb89-48a7-8689-3b8f8a276e0a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{4ede0037-cb89-48a7-8689-3b8f8a276e0a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Fly (Spyware.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Love (Spyware.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\new_drv (Rootkit.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3cd65faa (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zumorewavi (Trojan.Vundo.H) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    C:\WINDOWS\bdir (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\bdir\ffmiu (Trojan.Downloader) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\migisibi.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\ibisigim.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kokihove.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\hivopigi.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\newoyiju.exe (Trojan.Vundo.V) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\smart.dll (Spyware.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\LoveFly.dll (Spyware.Agent) -> Delete on reboot.
    C:\WINDOWS\2473343.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
    _______________________________________ ____
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:55:07 PM, on 4/18/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\System32\GEARSec.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Norton Ghost\Agent\GhostTray.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
    C:\Program Files\Lexmark 3300 Series\lxccmon.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    C:\Program Files\NetWaiting\netWaiting.exe
    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\lxcccoms.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Trend Micro\HijackThis\sniper.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bungie.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Programs\RegCon.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,[emailprotected]
    O4 - HKLM\..\Run: [lxccmon.exe] "C:\Program Files\Lexmark 3300 Series\lxccmon.exe"
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: RESEARCH - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\suvopomu.dll C:\WINDOWS\system32\vopeside.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 14432 bytes
    _______________________________________ __


    [attachment deleted by ADMIN]Hello drillkid31.

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    • O1 - Hosts: 82.98.231.89 url.adtrgt.com
    • O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\suvopomu.dll C:\WINDOWS\system32\vopeside.dll
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixHere's the log.
    _______________________________________
    ComboFix 09-04-19.05 - Blake 04/19/2009 15:03.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.538 [GMT -4:00]
    Running from: c:\documents and settings\Blake\Desktop\ComboFix.exe
    AV: Trend Micro PC-cillin Internet Security *On-access scanning disabled* (Updated)
    FW: Trend Micro PC-cillin Internet Security (Firewall) *disabled*
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\1272046.exe
    c:\windows\22868312.exe
    c:\windows\system32\disk.dll
    c:\windows\system32\hanugupi.dll
    c:\windows\system32\robotihu.dll
    c:\windows\system32\vopeside.dll
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
    .

    2009-04-19 14:14 . 2009-04-19 14:14410984----a-wc:\windows\system32\deploytk.dll
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\documents and settings\Blake\Application Data\Malwarebytes
    2009-04-19 03:30 . 2009-04-06 19:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-04-19 03:30 . 2009-04-06 19:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\program files\SUPERAntiSpyware
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\documents and settings\Blake\Application Data\SUPERAntiSpyware.com
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\program files\Common Files\Wise Installation Wizard
    2009-04-18 03:46 . 2009-04-18 14:331409589--sh--wc:\windows\system32\ofotahih.ini
    2009-04-15 21:24 . 2009-03-06 14:22284160------wc:\windows\system32\dllcache\pdh.dll
    2009-04-15 21:24 . 2009-02-06 10:3935328------wc:\windows\system32\dllcache\sc.exe
    2009-04-15 21:24 . 2009-02-09 12:10473600------wc:\windows\system32\dllcache\fastprox.dll
    2009-04-15 21:24 . 2009-02-09 12:10453120------wc:\windows\system32\dllcache\wmiprvsd.dll
    2009-04-15 21:24 . 2009-02-09 12:10401408------wc:\windows\system32\dllcache\rpcss.dll
    2009-04-15 21:24 . 2009-02-06 11:11110592------wc:\windows\system32\dllcache\services.exe
    2009-04-15 21:24 . 2009-02-06 10:10227840------wc:\windows\system32\dllcache\wmiprvse.exe
    2009-04-15 21:24 . 2009-02-09 12:10729088------wc:\windows\system32\dllcache\lsasrv.dll
    2009-04-15 21:24 . 2009-02-09 12:10714752------wc:\windows\system32\dllcache\ntdll.dll
    2009-04-15 21:24 . 2009-02-09 12:10617472------wc:\windows\system32\dllcache\advapi32.dll
    2009-04-15 21:23 . 2008-05-03 11:552560------wc:\windows\system32\xpsp4res.dll
    2009-04-15 21:23 . 2009-03-27 06:581203922------wc:\windows\system32\dllcache\sysmain.sdb
    2009-04-15 21:23 . 2008-04-21 12:08215552------wc:\windows\system32\dllcache\wordpad.exe
    2009-03-25 23:15 . 2009-03-25 23:15--------d-----wc:\program files\7-Zip
    2009-03-21 14:06 . 2009-03-21 14:06989696------wc:\windows\system32\dllcache\kernel32.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-19 19:09 . 2008-04-26 00:53--------d-----wc:\program files\Steam
    2009-04-19 14:14 . 2006-08-09 12:32--------d-----wc:\program files\Java
    2009-04-19 03:48 . 2006-08-09 12:51--------d-----wc:\program files\Trend Micro
    2009-04-19 01:22 . 2008-05-17 02:57--------d-----wc:\program files\CCleaner
    2009-04-19 01:03 . 2008-08-08 20:05--------d-----wc:\program files\ƒeƒCƒ‹ƒY ƒIƒu ƒ”ƒFƒXƒyƒŠƒA
    2009-04-19 00:59 . 2007-07-16 20:06--------d-----wc:\program files\LimeWire
    2009-04-19 00:57 . 2006-08-09 12:47--------d-----wc:\program files\WildTangent
    2009-04-19 00:56 . 2006-08-09 12:43--------d-----wc:\documents and settings\All Users\Application Data\Viewpoint
    2009-04-18 03:49 . 2006-08-09 12:53--------d-----wc:\program files\Google
    2009-04-17 19:31 . 2009-03-18 00:08--------d-----wc:\program files\Lx_cats
    2009-04-15 19:31 . 2009-03-22 20:17600----a-wC:\lxcc.log
    2009-04-13 00:09 . 2009-02-16 22:33--------d-----wc:\documents and settings\Blake\Application Data\U3
    2009-04-12 22:28 . 2009-03-19 21:342100----a-wC:\lxccscan.log
    2009-03-23 00:44 . 2006-08-27 23:303766--sha-wc:\windows\system32\KGyGaAvL.sys
    2009-03-19 23:12 . 2006-08-17 20:0454944----a-wc:\documents and settings\Blake\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-03-19 23:10 . 2008-05-31 20:37--------d-----wc:\program files\Windows Live
    2009-03-19 23:09 . 2009-03-19 23:09--------d-----wc:\program files\Microsoft Sync Framework
    2009-03-19 23:07 . 2009-03-19 23:07--------d-----wc:\program files\Microsoft
    2009-03-19 23:07 . 2009-03-19 23:07--------d-----wc:\program files\Windows Live SkyDrive
    2009-03-19 23:03 . 2009-03-19 23:03--------d-----wc:\program files\Common Files\Windows Live
    2009-03-18 22:58 . 2009-03-18 22:58--------d-----wc:\documents and settings\Blake\Application Data\FaxCtr
    2009-03-18 00:17 . 2009-03-18 00:12--------d-----wc:\program files\Abbyy FineReader 6.0 Sprint
    2009-03-18 00:11 . 2009-03-18 00:09--------d-----wc:\program files\Lexmark Fax Solutions
    2009-03-18 00:10 . 2009-03-18 00:10--------d-----wc:\documents and settings\All Users\Application Data\FaxCtr
    2009-03-18 00:09 . 2009-03-18 00:09--------d-----wc:\program files\Lexmark_3300 Series
    2009-03-18 00:09 . 2009-03-18 00:06--------d-----wc:\program files\Lexmark 3300 Series
    2009-03-18 00:08 . 2009-03-18 00:06517----a-wC:\LXCCINST.csv
    2009-03-18 00:06 . 2009-03-18 00:06242----a-wC:\CDFE.log
    2009-03-18 00:06 . 2009-03-18 00:060----a-wC:\lxccfire.csv
    2009-03-08 21:47 . 2009-03-08 21:47--------d-----wc:\program files\Enterbrain
    2009-03-06 14:22 . 2004-08-10 17:51284160----a-wc:\windows\system32\pdh.dll
    2009-03-03 00:18 . 2006-08-09 12:33826368----a-wc:\windows\system32\dllcache\wininet.dll
    2009-03-03 00:18 . 2004-08-10 17:51826368----a-wc:\windows\system32\wininet.dll
    2009-02-28 04:54 . 2006-10-17 17:04636072------wc:\windows\system32\dllcache\iexplore.exe
    2009-02-27 01:43 . 2008-11-13 18:13--------d-----wc:\program files\Microsoft Silverlight
    2009-02-20 10:20 . 2007-05-09 20:2013824------wc:\windows\system32\dllcache\ieudinit.exe
    2009-02-20 10:20 . 2006-11-07 08:2670656------wc:\windows\system32\dllcache\ie4uinit.exe
    2009-02-20 05:14 . 2006-11-07 08:25161792------wc:\windows\system32\dllcache\ieakui.dll
    2009-02-09 12:10 . 2004-08-10 17:51729088----a-wc:\windows\system32\lsasrv.dll
    2009-02-09 12:10 . 2004-08-10 17:51401408----a-wc:\windows\system32\rpcss.dll
    2009-02-09 12:10 . 2004-08-10 17:51714752----a-wc:\windows\system32\ntdll.dll
    2009-02-09 12:10 . 2004-08-10 17:50617472----a-wc:\windows\system32\advapi32.dll
    2009-02-09 11:13 . 2008-10-15 19:441846784------wc:\windows\system32\dllcache\win32k.sys
    2009-02-09 11:13 . 2004-08-10 17:511846784----a-wc:\windows\system32\win32k.sys
    2009-02-07 23:02 . 2008-10-15 19:442066048------wc:\windows\system32\dllcache\ntkrnlpa.exe
    2009-02-07 23:02 . 2004-08-04 03:592066048----a-wc:\windows\system32\ntkrnlpa.exe
    2009-02-06 22:52 . 2009-02-06 22:5249504----a-wc:\windows\system32\sirenacm.dll
    2009-02-06 11:11 . 2004-08-10 17:51110592----a-wc:\windows\system32\services.exe
    2009-02-06 11:08 . 2008-10-15 19:442189056------wc:\windows\system32\dllcache\ntoskrnl.exe
    2009-02-06 11:08 . 2004-08-10 17:512189056----a-wc:\windows\system32\ntoskrnl.exe
    2009-02-06 11:06 . 2008-10-15 19:442145280------wc:\windows\system32\dllcache\ntkrnlmp.exe
    2009-02-06 10:39 . 2004-08-10 17:5135328----a-wc:\windows\system32\sc.exe
    2009-02-06 10:32 . 2008-10-15 19:442023936------wc:\windows\system32\dllcache\ntkrpamp.exe
    2009-02-03 19:59 . 2009-02-03 19:5956832------wc:\windows\system32\dllcache\secur32.dll
    2009-02-03 19:59 . 2004-08-10 17:5156832----a-wc:\windows\system32\secur32.dll
    2008-11-13 18:25 . 2008-11-13 18:25123408----a-wc:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2008-04-08 21:41 . 2008-04-08 21:41128----a-wc:\documents and settings\Blake\Local Settings\Application Data\fusioncache.dat
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\bayopuge.dll.tmp
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\napigowu.dll.tmp
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\suvopomu.dll.tmp
    2008-10-06 00:21 . 2008-10-06 00:2132768--sha-wc:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100520081006\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
    "OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "Steam"="c:\program files\Steam\Steam.exe" [2008-10-08 1410296]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
    "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-12-18 3321856]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-12-13 58992]
    "Norton Ghost 10.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2005-12-07 1537696]
    "pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-09 169984]
    "MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 110592]
    "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 8192]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 148888]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "SAClient"="c:\program files\Insight\BBClient\Programs\RegCon.exe" [2004-11-17 299008]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
    "LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
    "lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-02-21 192512]
    "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-01-20 299008]
    "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

    c:\documents and settings\Blake\Start Menu\Programs\Startup\
    MEMonitor.lnk - c:\program files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-6-1 947544]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-9 24576]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 16:05356352----a-wc:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
    "c:\\WINDOWS\\system32\\lxcccoms.exe"=
    "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxccPSWX.EXE"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Digital Line Detect\\DLG.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "135:TCP"= 135:TCP:TCP Port 135
    "5000:TCP"= 5000:TCP:TCP Port 5000
    "5001:TCP"= 5001:TCP:TCP Port 5001
    "5002:TCP"= 5002:TCP:TCP Port 5002
    "5003:TCP"= 5003:TCP:TCP Port 5003
    "5004:TCP"= 5004:TCP:TCP Port 5004
    "5005:TCP"= 5005:TCP:TCP Port 5005
    "5006:TCP"= 5006:TCP:TCP Port 5006
    "5007:TCP"= 5007:TCP:TCP Port 5007
    "5008:TCP"= 5008:TCP:TCP Port 5008
    "5009:TCP"= 5009:TCP:TCP Port 5009
    "5010:TCP"= 5010:TCP:TCP Port 5010
    "5011:TCP"= 5011:TCP:TCP Port 5011
    "5012:TCP"= 5012:TCP:TCP Port 5012
    "5013:TCP"= 5013:TCP:TCP Port 5013
    "5014:TCP"= 5014:TCP:TCP Port 5014
    "5015:TCP"= 5015:TCP:TCP Port 5015
    "5016:TCP"= 5016:TCP:TCP Port 5016
    "5017:TCP"= 5017:TCP:TCP Port 5017
    "5018:TCP"= 5018:TCP:TCP Port 5018
    "5019:TCP"= 5019:TCP:TCP Port 5019
    "5020:TCP"= 5020:TCP:TCP Port 5020

    R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-08-30 290889]
    R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-08-30 585792]
    R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-08-30 262215]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
    S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
    S2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2008-11-26 205328]
    S2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2008-11-26 36368]


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.bungie.net/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: musicmatch.com\online
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    FF - ProfilePath - c:\documents and settings\Blake\Application Data\Mozilla\Firefox\Profiles\j8ej9k22.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.bungie.net/

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-19 15:11
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,[emailprotected]??

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-4254542993-1360710644-2665431577-1006\Software\SecuROM\License information*]
    "datasecu"=hex:58,53,1e,b2,99,18,a0,24,08,d1,48,05,90,2f,a5,8a,20,e4,e7,01,a8,
    02,09,96,c5,19,b7,e1,7a,1b,66,9e,0a,fc,b9,ce,c3,12,49,fe,3d,b4,89,a4,4b,f8,\
    "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(964)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\System32\BCMLogon.dll

    - - - - - - - > 'explorer.exe'(5508)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\BCMWLTRY.EXE
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\gearsec.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Dell\QuickSet\NicConfigSvc.exe
    c:\program files\Norton Ghost\Agent\VProSvc.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\system32\igfxsrvc.exe
    c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
    c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
    c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    c:\windows\system32\lxcccoms.exe
    c:\windows\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Completion time: 2009-04-19 15:14 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-04-19 19:14

    Pre-Run: 10,861,535,232 bytes free
    Post-Run: 10,777,190,400 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    299--- E O F ---2009-04-19 03:46
    Looks good now.

    This will just remove the Norton antivirus leftovers. It won't touch the Norton Ghost.

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    File::
    c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe

    Folder::
    c:\program files\Common Files\Symantec Shared

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"=-
    "ccApp"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=-

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    ---

    How is the computer running now?The computer is running fine now. I appreciate the help very much. I have a small question though...

    When I was using the Trial Version of Norton Ghost, it tried to back everything up but was unable to due to 'Low Disk Space'. Whenever I turn on the computer, a little bubble on the toolbar reminds me saying there's low disc space on Drive D. Should I get rid of the program and the 'backup' or just leave it?

    Either way, here's the requested log.
    _______________________________________ ____
    ComboFix 09-04-19.05 - Blake 04/19/2009 15:49.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.522 [GMT -4:00]
    Running from: c:\documents and settings\Blake\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Blake\Desktop\CFScript.txt
    AV: Trend Micro PC-cillin Internet Security *On-access scanning disabled* (Updated)
    FW: Trend Micro PC-cillin Internet Security (Firewall) *disabled*
    * Created a new restore point

    FILE ::
    c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Common Files\Symantec Shared
    c:\program files\Common Files\Symantec Shared\ccAlert.dll
    c:\program files\Common Files\Symantec Shared\ccApp.exe
    c:\program files\Common Files\Symantec Shared\ccDec.dll
    c:\program files\Common Files\Symantec Shared\ccEmlPxy.dll
    c:\program files\Common Files\Symantec Shared\ccErrDsp.dll
    c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\program files\Common Files\Symantec Shared\ccGSE.dll
    c:\program files\Common Files\Symantec Shared\ccInst.dll
    c:\program files\Common Files\Symantec Shared\ccL30.dll
    c:\program files\Common Files\Symantec Shared\ccL35.dll
    c:\program files\Common Files\Symantec Shared\ccLgView.exe
    c:\program files\Common Files\Symantec Shared\ccLogin.dll
    c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
    c:\program files\Common Files\Symantec Shared\ccProd.dll
    c:\program files\Common Files\Symantec Shared\ccProSub.dll
    c:\program files\Common Files\Symantec Shared\ccPwd.dll
    c:\program files\Common Files\Symantec Shared\ccPwdSvc.exe
    c:\program files\Common Files\Symantec Shared\ccScan.dll
    c:\program files\Common Files\Symantec Shared\ccSet.dll
    c:\program files\Common Files\Symantec Shared\ccSetEvt.dll
    c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\program files\Common Files\Symantec Shared\ccVrTrst.dll
    c:\program files\Common Files\Symantec Shared\ccWebWnd.dll
    c:\program files\Common Files\Symantec Shared\CfgWiz.tlb
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
    c:\program files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
    c:\program files\Common Files\Symantec Shared\DefUtDCD.dll
    c:\program files\Common Files\Symantec Shared\ecmldr32.DLL
    c:\program files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
    c:\program files\Common Files\Symantec Shared\Help\CCLGVIEW.chw
    c:\program files\Common Files\Symantec Shared\Help\CPDDRM00.chm
    c:\program files\Common Files\Symantec Shared\Help\CPDDRM01.chm
    c:\program files\Common Files\Symantec Shared\Help\LUALL.CHM
    c:\program files\Common Files\Symantec Shared\IraLsClt.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\Catalog.LiveSubscribe
    c:\program files\Common Files\Symantec Shared\LiveReg\Defaults.lvr
    c:\program files\Common Files\Symantec Shared\LiveReg\iraDefA2.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\IraLrShl.exe
    c:\program files\Common Files\Symantec Shared\LiveReg\IraLsCl2.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\iraLSUI.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\IraVcLc3.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\IraVcObj.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\LRCtrl.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\LRRes.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\LSCtrl.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\LSPlugin.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\LSSupCtl.dll
    c:\program files\Common Files\Symantec Shared\LiveReg\symcsub.exe
    c:\program files\Common Files\Symantec Shared\LiveReg\VcClnUp.exe
    c:\program files\Common Files\Symantec Shared\LiveReg\VcSetup.exe
    c:\program files\Common Files\Symantec Shared\NMain.exe
    c:\program files\Common Files\Symantec Shared\SLTCHK01.dll
    c:\program files\Common Files\Symantec Shared\Symdlbrg.dll
    c:\program files\Common Files\Symantec Shared\SymLTCOM.dll
    c:\program files\Common Files\Symantec Shared\SymUIAx2.ocx
    c:\windows\system32\ofotahih.ini

    .
    ((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
    .

    2009-04-19 14:14 . 2009-04-19 14:14410984----a-wc:\windows\system32\deploytk.dll
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\documents and settings\Blake\Application Data\Malwarebytes
    2009-04-19 03:30 . 2009-04-06 19:3215504----a-wc:\windows\system32\drivers\mbam.sys
    2009-04-19 03:30 . 2009-04-06 19:3238496----a-wc:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-19 03:30 . 2009-04-19 03:30--------d-----wc:\program files\Malwarebytes' Anti-Malware
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\program files\SUPERAntiSpyware
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\documents and settings\Blake\Application Data\SUPERAntiSpyware.com
    2009-04-19 01:30 . 2009-04-19 01:30--------d-----wc:\program files\Common Files\Wise Installation Wizard
    2009-04-15 21:24 . 2009-03-06 14:22284160------wc:\windows\system32\dllcache\pdh.dll
    2009-04-15 21:24 . 2009-02-06 10:3935328------wc:\windows\system32\dllcache\sc.exe
    2009-04-15 21:24 . 2009-02-09 12:10473600------wc:\windows\system32\dllcache\fastprox.dll
    2009-04-15 21:24 . 2009-02-09 12:10453120------wc:\windows\system32\dllcache\wmiprvsd.dll
    2009-04-15 21:24 . 2009-02-09 12:10401408------wc:\windows\system32\dllcache\rpcss.dll
    2009-04-15 21:24 . 2009-02-06 11:11110592------wc:\windows\system32\dllcache\services.exe
    2009-04-15 21:24 . 2009-02-06 10:10227840------wc:\windows\system32\dllcache\wmiprvse.exe
    2009-04-15 21:24 . 2009-02-09 12:10729088------wc:\windows\system32\dllcache\lsasrv.dll
    2009-04-15 21:24 . 2009-02-09 12:10714752------wc:\windows\system32\dllcache\ntdll.dll
    2009-04-15 21:24 . 2009-02-09 12:10617472------wc:\windows\system32\dllcache\advapi32.dll
    2009-04-15 21:23 . 2008-05-03 11:552560------wc:\windows\system32\xpsp4res.dll
    2009-04-15 21:23 . 2009-03-27 06:581203922------wc:\windows\system32\dllcache\sysmain.sdb
    2009-04-15 21:23 . 2008-04-21 12:08215552------wc:\windows\system32\dllcache\wordpad.exe
    2009-03-25 23:15 . 2009-03-25 23:15--------d-----wc:\program files\7-Zip
    2009-03-21 14:06 . 2009-03-21 14:06989696------wc:\windows\system32\dllcache\kernel32.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-19 19:55 . 2008-04-26 00:53--------d-----wc:\program files\Steam
    2009-04-19 14:14 . 2006-08-09 12:32--------d-----wc:\program files\Java
    2009-04-19 03:48 . 2006-08-09 12:51--------d-----wc:\program files\Trend Micro
    2009-04-19 01:22 . 2008-05-17 02:57--------d-----wc:\program files\CCleaner
    2009-04-19 01:03 . 2008-08-08 20:05--------d-----wc:\program files\ƒeƒCƒ‹ƒY ƒIƒu ƒ”ƒFƒXƒyƒŠƒA
    2009-04-19 00:59 . 2007-07-16 20:06--------d-----wc:\program files\LimeWire
    2009-04-19 00:57 . 2006-08-09 12:47--------d-----wc:\program files\WildTangent
    2009-04-19 00:56 . 2006-08-09 12:43--------d-----wc:\documents and settings\All Users\Application Data\Viewpoint
    2009-04-18 03:49 . 2006-08-09 12:53--------d-----wc:\program files\Google
    2009-04-17 19:31 . 2009-03-18 00:08--------d-----wc:\program files\Lx_cats
    2009-04-15 19:31 . 2009-03-22 20:17600----a-wC:\lxcc.log
    2009-04-13 00:09 . 2009-02-16 22:33--------d-----wc:\documents and settings\Blake\Application Data\U3
    2009-04-12 22:28 . 2009-03-19 21:342100----a-wC:\lxccscan.log
    2009-03-23 00:44 . 2006-08-27 23:303766--sha-wc:\windows\system32\KGyGaAvL.sys
    2009-03-19 23:12 . 2006-08-17 20:0454944----a-wc:\documents and settings\Blake\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-03-19 23:10 . 2008-05-31 20:37--------d-----wc:\program files\Windows Live
    2009-03-19 23:09 . 2009-03-19 23:09--------d-----wc:\program files\Microsoft Sync Framework
    2009-03-19 23:07 . 2009-03-19 23:07--------d-----wc:\program files\Microsoft
    2009-03-19 23:07 . 2009-03-19 23:07--------d-----wc:\program files\Windows Live SkyDrive
    2009-03-19 23:03 . 2009-03-19 23:03--------d-----wc:\program files\Common Files\Windows Live
    2009-03-18 22:58 . 2009-03-18 22:58--------d-----wc:\documents and settings\Blake\Application Data\FaxCtr
    2009-03-18 00:17 . 2009-03-18 00:12--------d-----wc:\program files\Abbyy FineReader 6.0 Sprint
    2009-03-18 00:11 . 2009-03-18 00:09--------d-----wc:\program files\Lexmark Fax Solutions
    2009-03-18 00:10 . 2009-03-18 00:10--------d-----wc:\documents and settings\All Users\Application Data\FaxCtr
    2009-03-18 00:09 . 2009-03-18 00:09--------d-----wc:\program files\Lexmark_3300 Series
    2009-03-18 00:09 . 2009-03-18 00:06--------d-----wc:\program files\Lexmark 3300 Series
    2009-03-18 00:08 . 2009-03-18 00:06517----a-wC:\LXCCINST.csv
    2009-03-18 00:06 . 2009-03-18 00:06242----a-wC:\CDFE.log
    2009-03-18 00:06 . 2009-03-18 00:060----a-wC:\lxccfire.csv
    2009-03-08 21:47 . 2009-03-08 21:47--------d-----wc:\program files\Enterbrain
    2009-03-06 14:22 . 2004-08-10 17:51284160----a-wc:\windows\system32\pdh.dll
    2009-03-03 00:18 . 2006-08-09 12:33826368----a-wc:\windows\system32\dllcache\wininet.dll
    2009-03-03 00:18 . 2004-08-10 17:51826368----a-wc:\windows\system32\wininet.dll
    2009-02-28 04:54 . 2006-10-17 17:04636072------wc:\windows\system32\dllcache\iexplore.exe
    2009-02-27 01:43 . 2008-11-13 18:13--------d-----wc:\program files\Microsoft Silverlight
    2009-02-20 10:20 . 2007-05-09 20:2013824------wc:\windows\system32\dllcache\ieudinit.exe
    2009-02-20 10:20 . 2006-11-07 08:2670656------wc:\windows\system32\dllcache\ie4uinit.exe
    2009-02-20 05:14 . 2006-11-07 08:25161792------wc:\windows\system32\dllcache\ieakui.dll
    2009-02-09 12:10 . 2004-08-10 17:51729088----a-wc:\windows\system32\lsasrv.dll
    2009-02-09 12:10 . 2004-08-10 17:51401408----a-wc:\windows\system32\rpcss.dll
    2009-02-09 12:10 . 2004-08-10 17:51714752----a-wc:\windows\system32\ntdll.dll
    2009-02-09 12:10 . 2004-08-10 17:50617472----a-wc:\windows\system32\advapi32.dll
    2009-02-09 11:13 . 2008-10-15 19:441846784------wc:\windows\system32\dllcache\win32k.sys
    2009-02-09 11:13 . 2004-08-10 17:511846784----a-wc:\windows\system32\win32k.sys
    2009-02-07 23:02 . 2008-10-15 19:442066048------wc:\windows\system32\dllcache\ntkrnlpa.exe
    2009-02-07 23:02 . 2004-08-04 03:592066048----a-wc:\windows\system32\ntkrnlpa.exe
    2009-02-06 22:52 . 2009-02-06 22:5249504----a-wc:\windows\system32\sirenacm.dll
    2009-02-06 11:11 . 2004-08-10 17:51110592----a-wc:\windows\system32\services.exe
    2009-02-06 11:08 . 2008-10-15 19:442189056------wc:\windows\system32\dllcache\ntoskrnl.exe
    2009-02-06 11:08 . 2004-08-10 17:512189056----a-wc:\windows\system32\ntoskrnl.exe
    2009-02-06 11:06 . 2008-10-15 19:442145280------wc:\windows\system32\dllcache\ntkrnlmp.exe
    2009-02-06 10:39 . 2004-08-10 17:5135328----a-wc:\windows\system32\sc.exe
    2009-02-06 10:32 . 2008-10-15 19:442023936------wc:\windows\system32\dllcache\ntkrpamp.exe
    2009-02-03 19:59 . 2009-02-03 19:5956832------wc:\windows\system32\dllcache\secur32.dll
    2009-02-03 19:59 . 2004-08-10 17:5156832----a-wc:\windows\system32\secur32.dll
    2008-11-13 18:25 . 2008-11-13 18:25123408----a-wc:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2008-04-08 21:41 . 2008-04-08 21:41128----a-wc:\documents and settings\Blake\Local Settings\Application Data\fusioncache.dat
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\bayopuge.dll.tmp
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\napigowu.dll.tmp
    2009-01-18 03:40 . 2009-01-18 03:4069120--sha-wc:\windows\system32\suvopomu.dll.tmp
    2008-10-06 00:21 . 2008-10-06 00:2132768--sha-wc:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100520081006\index.dat
    .

    ((((((((((((((((((((((((((((( [emailprotected]_19.11.10 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-04-19 19:52 . 2009-04-19 19:5216384 c:\windows\temp\Perflib_Perfdata_278.dat
    + 2004-08-10 17:51 . 2009-04-19 19:5772134 c:\windows\system32\perfc009.dat
    - 2004-08-10 17:51 . 2009-04-19 19:1172134 c:\windows\system32\perfc009.dat
    + 2004-08-10 17:51 . 2009-04-19 19:57443034 c:\windows\system32\perfh009.dat
    - 2004-08-10 17:51 . 2009-04-19 19:11443034 c:\windows\system32\perfh009.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
    "OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "Steam"="c:\program files\Steam\Steam.exe" [2008-10-08 1410296]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
    "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-12-18 3321856]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
    "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
    "Norton Ghost 10.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2005-12-07 1537696]
    "pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-09 169984]
    "MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-09-18 110592]
    "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-09-18 8192]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 148888]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "SAClient"="c:\program files\Insight\BBClient\Programs\RegCon.exe" [2004-11-17 299008]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
    "LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
    "lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-02-21 192512]
    "FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-01-20 299008]
    "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

    c:\documents and settings\Blake\Start Menu\Programs\Startup\
    MEMonitor.lnk - c:\program files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-6-1 947544]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-9 24576]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 16:05356352----a-wc:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
    "c:\\WINDOWS\\system32\\lxcccoms.exe"=
    "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxccPSWX.EXE"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Digital Line Detect\\DLG.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "135:TCP"= 135:TCP:TCP Port 135
    "5000:TCP"= 5000:TCP:TCP Port 5000
    "5001:TCP"= 5001:TCP:TCP Port 5001
    "5002:TCP"= 5002:TCP:TCP Port 5002
    "5003:TCP"= 5003:TCP:TCP Port 5003
    "5004:TCP"= 5004:TCP:TCP Port 5004
    "5005:TCP"= 5005:TCP:TCP Port 5005
    "5006:TCP"= 5006:TCP:TCP Port 5006
    "5007:TCP"= 5007:TCP:TCP Port 5007
    "5008:TCP"= 5008:TCP:TCP Port 5008
    "5009:TCP"= 5009:TCP:TCP Port 5009
    "5010:TCP"= 5010:TCP:TCP Port 5010
    "5011:TCP"= 5011:TCP:TCP Port 5011
    "5012:TCP"= 5012:TCP:TCP Port 5012
    "5013:TCP"= 5013:TCP:TCP Port 5013
    "5014:TCP"= 5014:TCP:TCP Port 5014
    "5015:TCP"= 5015:TCP:TCP Port 5015
    "5016:TCP"= 5016:TCP:TCP Port 5016
    "5017:TCP"= 5017:TCP:TCP Port 5017
    "5018:TCP"= 5018:TCP:TCP Port 5018
    "5019:TCP"= 5019:TCP:TCP Port 5019
    "5020:TCP"= 5020:TCP:TCP Port 5020

    R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-08-30 290889]
    R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-08-30 585792]
    R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-08-30 262215]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
    S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
    S2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2008-11-26 205328]
    S2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2008-11-26 36368]


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.bungie.net/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: musicmatch.com\online
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    FF - ProfilePath - c:\documents and settings\Blake\Application Data\Mozilla\Firefox\Profiles\j8ej9k22.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.bungie.net/

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-19 15:56
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,[emailprotected]??

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-4254542993-1360710644-2665431577-1006\Software\SecuROM\License information*]
    "datasecu"=hex:58,53,1e,b2,99,18,a0,24,08,d1,48,05,90,2f,a5,8a,20,e4,e7,01,a8,
    02,09,96,c5,19,b7,e1,7a,1b,66,9e,0a,fc,b9,ce,c3,12,49,fe,3d,b4,89,a4,4b,f8,\
    "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(960)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\System32\BCMLogon.dll

    - - - - - - - > 'explorer.exe'(3092)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\BCMWLTRY.EXE
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\gearsec.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Dell\QuickSet\NicConfigSvc.exe
    c:\program files\Norton Ghost\Agent\VProSvc.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\system32\igfxsrvc.exe
    c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
    c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
    c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    c:\windows\system32\lxcccoms.exe
    c:\windows\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Completion time: 2009-04-19 16:00 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-04-19 20:00
    ComboFix2.txt 2009-04-19 19:14

    Pre-Run: 10,781,216,768 bytes free
    Post-Run: 10,766,270,464 bytes free

    367--- E O F ---2009-04-19 03:46Quote
    When I was using the Trial Version of Norton Ghost, it tried to back everything up but was unable to due to 'Low Disk Space'. Whenever I turn on the computer, a little bubble on the toolbar reminds me saying there's low disc space on Drive D. Should I get rid of the program and the 'backup' or just leave it?

    Norton/Symantec is not my favorite software. As you notice their software is very RAM intensive and cause many computers more problems than they are worth.

    Are you looking for just backup files/folders or image the drive?

    -----

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete: ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    I've no idea about backup files/folders and imaging the drive. I just want to know if there's something about that I can get rid of to improve my comp, and if so how please.

    Also, thank you very much for the help with fixing my Bad Image problem.If you don't use the Norton Ghost I would uninstall it. I'm sure that would help.

    StartupLite
    • Download StartupLite by MalwareBytes to your Desktop.
    • Doubleclick StartupLite.exe to launch the program.
    • Ensure the Disable box is checked.
    • Click Continue.
    • A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
    • Re-start your computer.
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    I would also recommend that you Defrag the computer. There may be a lot of fragmented sections on the drive after cleaning the malware.

    You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

    Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Before I do that, I have Trend Micro PC-cillin Internet Security. Do I need to mess with that in anyway?

    And how would I clear out Temp files?Use CCleaner to clean temp files.

    As long as Trend Micro is turned on and up to date it should be OK.One more thing. I'm about to use CC cleaner, but it has checks in things like MS Paint. Is that bad? Is it going to delete those programs?No it won't delete the program it will just remove any log sthat the programs create. You might want to uncheck Cookies so it doesn't remove your log in information on online forums.
    3688.

    Solve : My computer is completely messed up help!!!?

    Answer»

    Hey the other day i decided to do a virus scan using AVG, it found loads of problems to do with win32/virut , i tried fixing some STUFF, buut from what i read it was hard to completely remove it, since then my computer has been incredibly slow and on start up it goes to a blue screen and does some chkdsk thing like everytime it loads up now, i did a hijack this thing and this is what i got, i really need some help sorting this out...x.x


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:04:31, on 17/04/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    c:\program Files\ThunMail\testabd.exe
    C:\WINDOWS\TEMP\lvjmcby.exe
    C:\WINDOWS\TEMP\lvjmcby.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\dhcp\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\w.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\system32\afisicx.exe
    C:\WINDOWS\system32\tdctxte.exe
    C:\WINDOWS\system32\sopidkc.exe
    C:\WINDOWS\TEMP\3962724732.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\3361\SVCHOST.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\services.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\services.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Documents and Settings\Chloe\Desktop\TrueSword5.exe
    C:\DOCUME~1\Chloe\LOCALS~1\Temp\is-6GP13.tmp\is-A7NKV.tmp
    C:\Documents and Settings\Chloe\My Documents\HiJackThis.exe
    C:\WINDOWS\system32\dncyool64.sys

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.blueyonder.co.uk/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: C:\WINDOWS\system32\zfgh83jg3.dll - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\zfgh83jg3.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [Fwefu] rundll32.exe "C:\WINDOWS\ehutuxunaka.dll",e
    O4 - HKLM\..\Run: [svchost.exe] "C:\WINDOWS\system32\3361\SVCHOST.exe"
    O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\RunServices: [Windows Recycler] zhinpl.exe
    O4 - HKLM\..\RunOnce: [svchost.exe] "C:\WINDOWS\system32\3361\SVCHOST.exe"
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Chloe\reader_s.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\Chloe\LOCALS~1\Temp\1965446390.exe
    O4 - HKUS\S-1-5-18\..\Run: [svc] c:\program Files\ThunMail\testabd.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\lvjmcby.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\lvjmcby.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\3962724732.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\WINDOWS\system32\config\systemprofile\reader_s.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [svc] c:\program Files\ThunMail\testabd.exe (User 'Default user')
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: &Search - ?p=ZZ
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Chloe\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186139904140
    O20 - AppInit_DLLs: c:\progra~1\ThunMail\testabd.dll
    O22 - SharedTaskScheduler: lkjf9873jhifjnsfi8w3fe - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\zfgh83jg3.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Dhcp server (DhcpSrv) - Unknown owner - C:\WINDOWS\dhcp\svchost.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
    O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Unknown owner - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (file missing)
    O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
    O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\WINDOWS\system32\sopidkc.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINDOWS\system32\tdctxte.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
    O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)

    --
    End of file - 10822 bytes


    please help T_T


    also... some of my programes have been delted, and when i try and goto add/remove programes. i get this 'c:\WINDOWS\system32\rundll32.exe' this is very frustratign please helpHello cwozzle.

    I can't say I have good news and I suggest you read this closely.

    The logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

    There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. Trying to FIX this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information.

    Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

    If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace!

    Do not back up to another machine, as it may become compromised. Burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.

    I suggest running at LEAST 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.

    -) Dr.Web CureIt!
    -) AVG Win32/Virut Removal Tool
    -) Symantwc W32.Virut Removal Tool
    -) McAfee Avert Stinger
    -) Microsoft Windows Malicious Software Removal Tool

    If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

    I strongly suggest you do the following immediately!

    Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your ACCOUNTS and/or change all of your account numbers.

    From a clean computer change all
    of your online passwords including for email, banks, financial accounts,
    PayPal, eBay, online credit card companies and any online forums or groups you belong
    to etc.

    DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.

    3689.

    Solve : Questions about FLASH COOKIES?

    Answer»

    Some people on the EBAY discussion boards were saying that ebay, and other websites, are downloading FLASH COOKIES to peoples computers without us knowing about it.

    They are also saying these flash cookies have the ABILITY to track a person's internet surfing even after we've left their website, and, even if we haven't even logged on to their website!

    Supposedly, anti-spyware programs will not detect them and even if they did we can't get rid of them even if we clean our cookies with Windows cookie cleaner.

    Is this true?

    If so, can MalwareBytes and/or CCleaner get rid of these pesky flash cookies?

    Please advise when you get a chance.

    Thanks so much!they are most likely just TRACKING cookies with the name flash cookies and yes you will most likely be able to get rid of themQuote from: unlovedwarrior on April 20, 2009, 04:45:24 AM

    they are most likely just tracking cookies with the name flash cookies and yes you will most likely be able to get rid of them

    Partly true. See here: Flash Cookies explained

    MalwareBytes does not TARGET cookies so it will not remove them. SUPERAntiSpyware does target third party tracking cookies though so I suggest that and CCleaner. Also see this CH article. How do I disable or delete Internet cookies?



    3690.

    Solve : Are they gone yet??

    Answer» GO to Start &GT; RUN and type C:\combofix.txt then click OK. It should pop up.
    3691.

    Solve : Avast! installation affecting Web mail access?

    Answer»

    Hi,

    I recently installed Avast! home edition version 4.8. Since then any web mail (such as hotmail) doesn't work on my computer. Such sites are not uploaded properly: I'm getting a "HTTP Error 404 - File or directory not found" message. I do see the log-in prompt. After putting my username and password the web page become blank.
    BTW, previously I had Kasparski which I removed prior to installing Avast!.

    I tried disabling the Internet Mail provider within Avast! (I assumed this should stop the web mail scan / service) but that didn't change anything and the problem persists.

    I've created an HJT file which I can send if this may help resolving my issue.

    Hope someone can help me!

    Many thanks,
    Vampirecharm. Try this.

    Default Security Settings

    For Internet Explorer 6 users:
    Click Start > Run > type inetcpl.cpl and press Enter. When Internet Properties comes up navigate to the Security Tab and click Default Level for the following:

    *Internet
    *Local Intranet
    *Trusted Sites
    *Restricted Sites.

    Click OK to exit.

    For Internet Explorer 7 users:
    Click Start > Run > type inetcpl.cpl and press Enter. When Internet Properties comes up, navigate to the Security Tab and simply click the "Reset all zones to default level" button. Click OK to exit.

    NOTE:
    If it's Grey then it's already at the default level.Avast install is probably currpted since I have no issues with ether version of IEI have explorer 7 and I've set security to default as per the suggestion.
    Unfortunately it didn't help

    I downloaded Avast! from it's official site...

    Would appreciate any other idea.

    Thanks!
    Guy.Did you try it again?So, web mail of interest still works when AVAST is completely uninstalled from system? I remove Avast! and the problem persists

    The problem is not only with web SERVICES such as hotmail but also some links and images in other web pages over the net don't work for me. For example, I compared how MSN.COM portal looks in my PC vs. my laptop. I attached the PC (problematic) view to my reply.
    As you may see, on my PC the the addvertisement part (flash) on the right is not identified (doesn't show). Also the JPEG at the center is static while on my laptop the JPEGs are changing.

    Seems like something in my Explorer went wrong.

    I may have cought some virus in between removing my old anti-virus and installing the new one. Or maybe Avast! interfered with my security settings (altough I already set everything to default as evilfantasy suggested) or with my Explorer settings (??).

    Don't know what to do...


    Vampirecharm.


    [attachment deleted by admin]Avast mail scanning has nothing to do with webmail.

    JPEGs aren't animated, GIFs are - untick "Do Not Show Animations" in Internet Explorer/Tools/Options/Advanced, and while you're there try reseting IE entirely to see if that helps - click the button at the bottom of the dialogue box.

    The absence of content where the advert should be could be down to a faulty or missing Flash plugin (which could also be responsible for the non-animated images).
    Download Flash Uninstaller and latest installer from Adobe. Read this troubleshooting FAQ; http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_15511&sliceId=2
    Close all browsers and browser windows. Run uninstaller, run installer, reboot.

    The whole set of issues could be related to MTU problems. How do you connect to the 'net? Cable, ADSL, wired or wireless etc etc
    That doesn't entirely explain why it started after removing Kaspersky, but both scan incoming web-traffic and may have their own settings that interfere. Can you do a restore to before this happened?Before I run the un-installer I checked whether I could run the installer USING my explorer as it is now.
    Guess what? - I can't.

    When I try, nothing happens. I'm not getting the message: "This site might require the following ActiveX control: 'Adobe Flash Player installer' from 'Adobe systems incorporated'...
    And nothing else happens.

    Therefore I haven't uninstalled it..

    I'm THINKING maybe I need to re-install my Explorer. What do you think? if so, what is the best way to do that?

    I don't know how to restore to before this has happened.

    Thanks.It just seems that you need that if its all.Post the HJT file....the problem may surface there.(squall_01 - I'm afraid I couldn't understand your reply. Would appreciate if you elaborated...).

    Below is the HJT result.

    In parallel I learned that I have some some addons disabled... when looking in my explorer to Tools > Manage Addons > Enable or Disable Addons.
    Examples for such disabled objects are: Skype, Google Toolbar, Sun Java Console, Windows Messanger, and many others.
    These couldn't have been disabled before I installed Avast! since I know I've used them...
    so I enabled most (not all) but most of the symptoms persist:
    I now do see the Google toolbar but still have the same problems as before, such as:
    - No access to the hotmail site, with the same error message as before
    - MSN.com shows a contant JPEG instead of dynamic/changing objects plus the advertisement area is EMPTY (both symptoms still exist when comparing to my lap-top view)
    - In a maps site I can't see the map. The site seems to keep trying loading it without success
    Maybe I should enable ALL objects? or maybe I have some objects missing?
    I'd appreciate checking both parallel directions of addons and the HJT.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:02:14, on 20/04/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\CNYHKey.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ynet.co.il/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://kazaa.vmule.com/homepage.html
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: עוזר הכניסה של Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
    O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - STARTUP: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
    O9 - Extra button: VC Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\VCPOKE~1\client.exe
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {F6A553B1-4B5F-4974-866F-98C1D1EBD3DE} (CitrixTCSX Control) - https://tlvportal2.amdocs.com/prx/00...PubAppsTCS.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 11032 bytes
    Quote from: vampirecharm on April 26, 2009, 05:02:12 PM

    "This site might require the following ActiveX control: 'Adobe Flash Player installer' from 'Adobe systems incorporated'...
    And nothing else happens.



    Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

    • Open the folder and run Dial-a-fix.exe
    • 2 windows will open. Close the one in the background labeled Restrictive Policies
    • Check the box in section 1, Empty temp folders.
    • Check the box in section 2, Fix Windows Installer.
    • Check the box in section 3, Fix Windows Update.
    • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
    • Check all boxes in section 5, labeled Registration Center.
    • Click Go
    • OK any error messages if received, but write them down and post them here.
    • Restart the computer when done.
    .
    - Next in Dial-a-fix click the hammer icon.

    - Select Repair/reinstall IE and click Go

    If at any time you are prompted for the XP CD, insert it
    Make note of any error messages and post them here

    Reboot when complete and let me know if there's any change.
    3692.

    Solve : Got a Virus (maybe a trojan?) Help Appreciated?

    Answer»

    Hello Folks, thanks for looking at my problems!

    I followed the Malware Removal Steps guide step by step and want to follow up with my 3 logs and a description of the problem.

    Basically today I was surfing, had not gone to any odd sites recently and no odd downloads, and had AVG Free (fully updated) and TeaTimer running. TeaTimer started freaking out with some virus obviously trying to change my registry again and again. AVG then picked up on what was going on and asked me if I wanted to fix the infected files, but when I did that, then it said more files were being infected (I assume they were files being infected, although I really don't know how it works). I turned off the computer, disconnected it from the internet, and found your website on my other computer. I have not plugged it back into the web since but also haven't had the same problem as before except for 2 random notifications by AVG that something was wrong.

    Thanks for reading. I figure its better to be more detailed than less.

    Also, I have Windows XP Home Edition w/ SP3.

    Thank you for your time. Its greatly appreciated!

    Here are my 3 scans:

    ========================================================

    MBAM LOG


    Malwarebytes' Anti-Malware 1.36
    Database version: 2016
    Windows 5.1.2600 Service Pack 3

    4/20/2009 8:14:00 PM
    mbam-log-2009-04-20 (20-14-00).txt

    Scan type: Quick Scan
    Objects scanned: 80154
    Time elapsed: 4 minute(s), 6 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 8
    Registry Values Infected: 1
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96a4be9d-de5f-413f-86ae-02a621d6d99f} (Trojan.Vundo.H) -&GT; Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{96a4be9d-de5f-413f-86ae-02a621d6d99f} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\sai.instantiator (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\sai.instantiator.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nitujuyuki (Trojan.Vundo.H) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    =============================================

    SUPER ANTI SPY



    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/20/2009 at 07:37 PM

    Application Version : 4.26.1000

    Core Rules Database Version : 3853
    Trace Rules Database Version: 1805

    Scan type : COMPLETE Scan
    Total Scan Time : 02:11:24

    Memory items scanned : 372
    Memory threats detected : 2
    Registry items scanned : 5529
    Registry threats detected : 6
    File items scanned : 99200
    File threats detected : 7

    Adware.Vundo/Variant-EC
    C:\WINDOWS\SYSTEM32\LARAGUJI.DLL
    C:\WINDOWS\SYSTEM32\LARAGUJI.DLL
    C:\WINDOWS\SYSTEM32\NOKANOZA.DLL
    C:\WINDOWS\SYSTEM32\NOKANOZA.DLL

    Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\contim
    HKLM\SOFTWARE\Microsoft\contim#SysShell
    HKLM\SOFTWARE\Microsoft\rdfa
    HKLM\SOFTWARE\Microsoft\rdfa#F
    HKLM\SOFTWARE\Microsoft\rdfa#N

    Rogue.Component/Trace
    HKU\S-1-5-21-2696987157-2951269213-3466700681-1007\Software\Microsoft\FIAS4057

    Adware.180solutions/Seekmo/Zango
    C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS\NPSAIDETECT.DLL
    C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS\NPSAIX.DLL

    Adware.Vundo/Variant
    C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\BACKUPS\BACKUP-20090420-143502-882.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP937\A0158237.DLL

    Adware.SeekSuggest
    C:\WINDOWS\JESTERTB.DLL


    ==============================

    HIJACK THIS



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:25:38 PM, on 4/20/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\X3watch\x3watch.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [x3watch] C:\Program Files\X3watch\x3watch.exe
    O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [nitujuyuki] Rundll32.exe "C:\WINDOWS\system32\nokanoza.dll",s (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [nitujuyuki] Rundll32.exe "C:\WINDOWS\system32\nokanoza.dll",s (User 'NETWORK SERVICE')
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\laraguji.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG Free8 WATCHDOG (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick STARTER (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

    --
    End of file - 3327 bytes

    3693.

    Solve : I can't start my Product Recovery DVD!?!?

    Answer»

    I was having virus/malware problems on my Toshiba Satellite M30 and used my product recovery DVD to return my comp to its factory settings... It was working great until I downloaded AVG antivirus... I ran a full computer scan and it registered all my NECESSARY executable files as corrupted, including explorer.exe... So i shut down my computer, and when i turned it back on, it boots up and only shows my desktop background... No icons, No taskbar.. nothing.. Even in safe MODE nothing boots up.. When i use the task manager to try and run: explorer.exe, it says that the file cannot be found.. So i tried to put my Recovery DVD back in to start all over again, but now I can't seem to get the DVD started... It does not recognize that there is a disc in the D: drive... If anyone can spare some information or suggestions, please let me know!!!!!! Thanks!!!!!Have you tried BOOTING from the recovery DVD? You may need to tell the laptop to boot off DVD by holding down a Function key (F10?) immediately after power-on then choose "boot from DVD/CD"yeah.. i pressed F8 after boot up to get the start-up menu.. but there's no option to boot DVD/CD.. any other ideas???When you first turn your computer on, before windows loads, you will see a message that says to press a certain key to enter setup. Pay attention, as the message may flash very quickly. It is usually an Fkey or esc or DEL. Tap this key as the computer starts up - before windows starts to load.

    This will take you into BIOS. You use the arrow keys to navigate through BIOS.

    In BIOS you want to look for Boot order or Boot sequence or maybe even just Boot. You want to set your CD drive as the first boot device. You usually use the plus and minus keys to move your devices around in the boot order.

    Once you have your CD drive set as the first boot device, place the CD in the master CD drive. Now exit setup and SAVE changes (F10).

    The computer will now reboot. You may see a message that says: "Press any key to boot to CD". Just keep tapping the space bar as the computer is starting back up (before windows loads).

    Good luck!

    3694.

    Solve : Is my computer clean of Spyware/Adware/Malware now??

    Answer» LATELY,,i've been aware of my computers speed..and i followed some simple instructions on a POST on how to REMOVE the 'wares'(spy/ad/mal)on my computer..well,my LOGS are attached..is it clean or what?needs more cleaning?

    [attachment deleted by admin]
    3695.

    Solve : Trojan Rootkit problem?

    Answer»

    Hello

    With RESPECT to the testfiles , yes I had created it for some perl program,
    all three were created by me, it is not at all important so I can delete them if you PERCEIVE any ISSUE with these files

    C:\test4
    C:\test3
    C:\test1

    These two belong to different user profiles and was created previously not by me. Lisa was the previous
    sys admin so hopefully this tmp file is clean .

    c:\documents and settings\lisa\Start Menu\Programs\Startup\
    prf1DE.tmp [2004-8-11 84]

    c:\documents and settings\ranjitha.INFORSENSE\Start Menu\Programs\Startup\
    prf32E.tmp [2004-8-11 84]

    Thank you
    Regards
    dsgk
    Quote

    C:\test4
    C:\test3
    C:\test1

    These are fine as long as you know what they are.

    Quote
    c:\documents and settings\lisa\Start Menu\Programs\Startup\
    prf1DE.tmp [2004-8-11 84]

    c:\documents and settings\ranjitha.INFORSENSE\Start Menu\Programs\Startup\
    prf32E.tmp [2004-8-11 84]

    Would you like to remove these? I don't think they should stay if they aren't being used.Hi

    Thank you, sure I will delete those tmp files.

    Thanks a lot for your timely help and wonderful support, before you helped me
    out I was really STUCK, frustrated.

    Have a great day !

    Regards
    dsgk
      OK but we aren't done yet

      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Scan with
    Panda ActiveScan 2.0

    This scanner requires Internet Explorer

    • Once you are on the Panda SITE click the Scan your PC now button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Select the appropriate Yes or No to receiving marketing information
    • Click the Free Online Scan button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    .
    Post the contents of the ActiveScan report in your next reply.
    3696.

    Solve : sysvxd problem and logs?

    Answer»

    Thanks in advance for your help. I have an sysvxd message similar to other posters. "C:\Windows\sysvxd.exe The NTVDM CPU has encountered an illegal instruction. etc." When this message pops up, I click 'Close" to terminate the activity. I then go to the Windows folder and delete the sysvxd.exe file. But after I reboot the laptop, the message appears again. I recently had syscho.exe and syssvc.exe, which I removed with the help of a website. I am sorry, I do not remember the website or the steps TAKEN. I have taken the steps as directed in the malware removal guide. And I am ATTACHING the logs as requested. This issue is on a company laptop which is not connected to a company Intranet. But I do have installed on my company laptop: a] corporate Symantec Antivirus, B] Cisco Clean Access Agent, c] HP ProtectTools Security Manager, d] HP Mobile Data Protection, e] Altris Client Service. I do not know if these applications are activated [except for the Symantec Antivirus which is activated]. Also I access our company's web based sales data bases [ACT! and Sales Logox] VIA Citrus interface. Thanks again. Sincerely, redvolvo.

    [ATTACHMENT deleted by admin]

    3697.

    Solve : Not sure what this is...?

    Answer»

    Your thinking one step ahead of me now Thanks for the logs.

    You need to update and run MBAM again. That is v1.35 and we are in v1.36 now so it is way out of date. I should have caught that with the last MBAM scan so I screwed up.

    Please Run Malwarebytes' Anti-Malware.

    • Click the Update tab.
    • Click Check for Updates
    • If an update is found, it will download and install.
    • Click the Scanner tab.
    • Select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy & Paste the entire report in your next reply along with a fresh HijackThis log.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Also run a new HijackThis scan once MBAM is done and the computer restarted and post that log as well.

    Ok Here they are!

    [attachment deleted by admin]You have restarted the computer after running MBAM right?

    Looking at the HJT log now...yeah i restarted itOK let's do this.

    Go to Start > Run and type Notepad.exe then click OK.

    Copy and paste the following text within the code box into the new Notepad file.

    Code: [Select]@ECHO OFF
    sc stop "0269351237706498"
    sc delete "0269351237706498"
    exit
    In Notepad select File and Save as
    Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files.

    Next double click fixservice.bat to run it.
    A black box should open and close after a short time, this is normal.
    Do not continue until the black box has closed
    Delete fixservice.bat from the Desktop.

    ----------

    Right click HijackThis and choose 'Run as Administrator'

    Select Do a system scan only

    Place a check mark next to the following entries: (if there)

    • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    • O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    • O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Be sure to download a new copy of ComboFix.

    Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily DISABLE your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Right click combofix.exe & choose 'Run as Administrator' then follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFixOk here is the combofix log

    [attachment deleted by admin]Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    Folder::
    c:\program files\AVG

    Driver::
    0269351237706498mcinstcleanup

    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{6879BA04-D1AA-49AA-8B4A-E20EC7F116D6}"=-
    "{33811BE1-4254-4373-BA13-B480FA466F13}"=-
    "{5869D7A3-E23D-4C6F-8FB3-6C53157D4633}"=-
    "{F84052A0-E422-4AF9-A76C-7D683BE66758}"=-
    "{C0152898-C4B1-4BA6-A535-4C63B3280117}"=-
    "{184757BE-E404-44E3-AA16-9A18408571D4}"=-

    RegLockDel::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]000\AllUserSettings]
    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this INSTRUCTION carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

    Ok here is the log after that step! And my computer rebooted.

    [attachment deleted by admin]Scan with Panda ActiveScan 2.0

    This scanner requires Internet Explorer

    • Once you are on the Panda site click the Scan your PC now button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Select the appropriate Yes or No to receiving marketing information
    • Click the Free Online Scan button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a CONVENIENT location.
    .
    Post the contents of the ActiveScan report in your next reply.Ok it is scanning! Ok I did the scan but it didn't give me a log from it. It said it found nothing, but it didn't take very long to scan my computer
      • Click START then RUN
      • Now type Combofix /u in the runbox
      • Make sure there's a space between Combofix and /u
      • Then hit Enter.
      • The above procedure will:
      • Delete the following:
      • ComboFix and its associated files and folders.
      • Reset the clock settings.
      • HIDE file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      ----------

      Download
    ATF Cleaner by Atribune to your Desktop.

    Alternate download link

    Note: Vista users must use Run As Administrator
    • Under Main: Select Files to Delete choose: Select All.
    • Click the Empty Selected button.
    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      If you would like to keep your saved passwords click No at the prompt.
    • Click Exit on the Main menu to close the program.
    .
    Note that your system will run slower for a reboot or two after having used this tool so don't panic.

    ----------

    Download OTCleanIt.exe and save it to your Desktop.
    • Double-click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it yourself.
    .
    Important: Restart the computer before continuing.

    ----------

    How is the computer running now?Ok well I rebooted my computer and my documents folder is still unreadable Whatever it is it doesn't appear to be a malware issue and I am out of ideas. Try posting in the Windows forum. Someone there will have some ideas. I don't use Vista so am limited on what to try.Ok thanks anyways!
    3698.

    Solve : hijack?

    Answer»

    Malwarebytes' Anti-Malware 1.35
    Database version: 1904
    Windows 6.0.6001 Service Pack 1

    19/4/2009 10:10:25 PM
    mbam-log-2009-04-19 (22-10-25).txt

    Scan type: Quick Scan
    Objects scanned: 68759
    Time elapsed: 7 minute(s), 35 second(s)

    Memory PROCESSES Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:44:19 PM, on 18/4/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Windows\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msn.co.nz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=81&bd=Presario&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-nz.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6B76B957-B80C-4F17-BE8D-7CDE73F4E5B8}: NameServer = 210.55.12.1 210.55.12.2
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9418 bytes
    you should have put them all on your 1st post you will get told of for a double post , but then it is your fist time , harry1. Open HijackThis.
    2. Click Do a system scan only
    3. Check the boxes that correspond to the below lines.

    - O2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file)

    4. Once the above have been checked Close all web browsers and then click the Fix checked button.
    5. After fixed close Hijackthis.

    What problems are you still having?I ran scan, 02 BHO (etc) didn't show up, I thought I couldn't find it to FIX earlier?
    Only got machine last year, connection icon in notification area was wrong, very soon after that Norton was disabled, fixed by proffessional, now I'm spooked, as soon as it runs slower or a bit odd . . .
    Norton PHISHING PROTECTION always needs FIXING at the moment???
    I started looking for ways to restore speed / or simply learn if all was ok.
    Thanks.
    Should I transfer all this into other post thing - that GREENHORN title FITS oh so well Try some cleaning steps and see if it helps any.

    Download StartUp 1.3

    * Open StartUp 1.3 and you will see a list of your startups.
    * Right click any startup you do not want and choose Remove
    * Once complete choose Apply then Exit

    ----------

    Download CCleaner Slim and save it to your Desktop.
    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.
    Complete the installation then:

    • Double-click the CCleaner shortcut on the desktop to start the program.
    • Click on the Options block on the left, then choose Cookies.
      • Under Cookies to Delete, highlight any cookies you would like to retain permanently
      • Click the right arrow > to move them to the Cookies to Keep window.
      .
    • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
    • Click Cleaner on the left then Run Cleaner on the right to run the program.
    • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
    • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
    • Exit CCleaner after it has completed its process.
    .
    Note CCleaner is a 100% free tool. I suggest keeping it and running it regularly to keep your computer running smooth.

    ----------

    I would also recommend that you Defrag the computer.

    You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

    Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.Quote from: evilfantasy on April 20, 2009, 10:04:12 AM
    Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.
    OOppss,
    forgot the restart bit,
    I somehow skipped the STARTUP 1.3 part,
    CCLEANER seemed to be able to look at them,
    I stopped most,
    used the MICROSOFT (already loaded) DEFRAG - only have dial-up connection (and all it's glory )
    THANKS HEAPS,
    SEEMS to be faster to start,
    I've had to FIX PHISHING PROTECTION AGAIN - twice in 2 hours?
    Might get to update this in 12hrs,

    hope to check hijackthis repport at same time
    thanks againIf you are on dial-up and using IE8 then I would imagine surfing is slow. IE8 is slow on my cable connection. Give Firefox a try and see if surfing is any faster. I know it can not sound like fun switching browsers but 2if it is a big difference then it might be worth it.

    Quote
    OOppss,
    forgot the restart bit,

    That's OK. It just helps to make sure that the memory is clear and nothing extra is running. Helps with the speed of the defrag. Safe Mode defragging is suggested but not mandatory.Thanks, just switched thing on and is much faster. Connected without 3 ATTEMPTS also
    This thing ACTUALLY belongs to my girlfriend and doesn't really like my helpful changes.
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:44:19 PM, on 18/4/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Windows\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msn.co.nz/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sg&c=81&bd=Presario&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-nz.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6B76B957-B80C-4F17-BE8D-7CDE73F4E5B8}: NameServer = 210.55.12.1 210.55.12.2
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9418 bytes
    Thanks
    got to go

    Log looks OK.How do I know what I don't need?
    A couple of thing s show up in the process analys tool whatsit, that i don't see in the log to adjust or explore

    This should tak ecare of your unnecessary startups.

    StartupLite
    • Download StartupLite by MalwareBytes to your Desktop.
    • Doubleclick StartupLite.exe to launch the program.
    • Ensure the Disable box is checked.
    • Click Continue.
    • A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
    • Re-start your computer.
    3699.

    Solve : Spyware removal help?

    Answer»

    Hi. I want to says thanks in advance for any help.

    Before I found this site I downloaded several different spyware detection programs to scan my computer. I was trying to test them to SEE which ONE to buy but I found that each program practically found different things than the others. I can't buy them all. But some of them let me remove some things but not all.

    One of the programs I downloaded called "Exterminate It" found some files I THINK from "Vundo". I tried to find them in the system32 folder to delete but couldn't find them. (NAMED tadagagu.exe and tolodaze.dll.vir)

    Then I found this site and followed the directions. Here are my logs. I don't know if they might be SLIGHTLY misleading since I tried to delete stuff before I made the logs.

    I hope these logs tell you what you need to know. And, are the programs the directions had me use effective enough to find everything?

    [attachment deleted by admin]

    3700.

    Solve : Unable to Update?

    Answer»

    I saw that BC but then found other conflicting threads.

    Quote

    S3 ¥Õ¥Ø°ê¤¤¥Í1;¥Õ¥Ø°ê¤¤¥Í1;\??\c:\documents and settings\matthew\my documents\matt\photos\matt's pictures\other pictures\ve5 1032\nvid999.sys

    But the more I look at it the ¥Õ¥Ø°ê¤¤¥Í1 indeed makes it look malicious.that's for sure. I can imagine the calibur of a program that presents that as the default INSTALL dir

    Basically- it isn't present on my system anywhere, and I'm using a Nvidia card as well, and the name just doesn't make sense. and the install location now makes it look even more seedy.




    I foresee it being removed in the next set of instructions. Assuming of course Helpmeh doesn't know better.
    I got rid of Norton, and just finished downloading ComboFix, when I got a virus ALERT, screenshot link:
    http://img2.imageshack.us/img2/693/caalert.png
    Will run ComboFix codw now.New update: My anti-virus software says that ComboFix is infected, then deletes it...should I turn it off, download CF, then run CF?Yes turn it off.

    Temporarily disable your antivirus, and any antispyware real TIME protection before performing a scan. Click this link to see a list of SECURITY programs that should be disabled and how to disable them.Quote from: evilfantasy on April 18, 2009, 02:28:30 PM
    Yes turn it off.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
    I mean I can't run it, I can't even download it properly. But I will disable then re-download.Disable the antivirus first.Quote from: evilfantasy on April 18, 2009, 02:57:05 PM
    Disable the antivirus first.
    Currently running fine. I got something about ERU and backing up registry...Quote from: Helpmeh on April 18, 2009, 03:02:15 PM
    Currently running fine. I got something about ERU and backing up registry...
    Sorry I haven't posted in here for a while.

    It told me to download Windows Restore (I can't remember, but it pops up to choose if I want to restore my computer every time I turn it on)...and then it just crashed...

    Edit: The program is called Windows Recovery Console.