Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3801.

Solve : Redirected Google links?

Answer»

I am running Windows Vista and I use GOOGLE Chrome. More often than not, when I click on a link on a Google search, it will redirect me to a random website for about half a second, then another one with the search results of my original search on another website. For example, when I search "Sins of a Solar Empire: Diplomacy beta", then click on one of the links, it redirects me to "http://sopranoclarinet.com/result.php?Keywords=Sins+of+a+Solar+Empire:+Diplomacy&r=19a62d05d0c76434e38e49a4a1ecec8b19e5d049d86ffbd91fc1205cb0a9d7edc0dd9aa83a2b3ed1e84eee14de24d78c&Submit=Go", then it directs me to "http://www.lowpriceshopper.com/about-solar/shop?rf=llp". When I hit the "back" button, the browser will either show some "generic" website like "www.Corporatehousingproviders.org" or a site that will say "your page is loading" and then will direct me back to the site that I was on before pressing the "back" button. These problems can be AVOIDED by right-clicking the link on the Google search and OPENING it in a new tab. For the most part, the "major" sites such as Google, Yahoo, Miniclip, Wikipedia, etc. are fine, but the "SMALLER", lesser known sites are affected. I have McAfee (the one Comcast gives out for free) and I have run two full scans, both of which have come back negative. Please advise.Click here, follow the directions and post the logs.Here are the logs

[Saving space, attachment deleted by admin]re-run the mbam and remove anything that COMES up and post a clean log

the mbam log says no action taken

please post the sas log as well

3802.

Solve : Atapi.sys infected by a Trojan Horse Packed.Protector.C?

Answer»

Try this.

Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:

  • Click on Start > Run and type sfc /scannow then press ENTER (note the space between scf and /scannow)
    • Let this run undisturbed until the window with the blue progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %SYSTEMROOT%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.Didn't solve it.I'm not sure whats wrong. Have you tried a repair install? http://www.michaelstevenstech.com/XPrepairinstall.htmCould it be hardware problem then? My fan is running on high-speed and in Everest my CPU heat is 75-80 degrees CELSIUS in safe-mod.That is very possible.

I'm pretty sure we removed the malware but the damage it did may be more than we can see. You may need to reinstall.Alright. Well thanks a lot for the help! It might take some days till I get it REINSTALLED.
3803.

Solve : Can a virus remain on a graphics card if the card is used in another PC??

Answer»

Hi. I'm ASKING this question for a friend. I think he is running XP. He would like to use a graphics CARD from an old, infected PC. Can a virus REMAIN on the card?
Thanks for you help, I'm NEW and it looks like you have a great forum. Viruses do not transfer themselves to video cards. YES, you can use it.Thanks Allen!

3804.

Solve : Request Help for trojan removal - Combofix Log interpretation?

Answer»

Cannot run Viruseffect remover:
" says system administrator has set polices to prevent its installation"Try OTL please.Sorry about that. It is hard to KNOW if ONE program is dependent upon the first running successfully. I will assume they are independent in the future unless stated otherwise.
Logs attached:

[Saving space, attachment deleted by admin]Quote from: Jhavey on January 05, 2010, 07:30:53 PM

It is hard to know if one program is dependent upon the first running successfully.

They usually are but if one won't run then we're forced to try the next.

Good news. I don't see anything wrong.

Bad news. I don't see anything wrong....

Try Dial-a-fix.

Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the one in the BACKGROUND labeled Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 BOXES under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
.
How is the computer now?During install it Stated "Installer unable to determine your version of Internet explorer, some DLL registrations will be skipped" I ran it anyways.

received Multiple error messages #127: for the following files:
iesetup.dll
imgutil.dll
inserg.dll
pngfild.dll
webcheck.dll
inshtml.dll
msrating.dll
occache.dll

After reboot to normal windows mode still no permissions to run programs or startup notifications bar.
Nothing changed that can be detected.
I ran Avast boot time scan this morning and it showed no infections.

Ever since post reply #9 where I attempted to run ESET I have had the issue with the lack permissions and the missing start up notifications bar.

In post replay #28 I asked you if we could address this and you did not respond but instead had me run another program.

I ASK NOW ....

Is it possible that we have cleaned the machine in this process and what is left is some configurations that got screwed up in the process?
Can we now directly address why I am not getting permissions in the normal run mode and why the start up notification bar is missing?

or do you still feel we need to run more checks for infections?I have searched on my own attempting to fix the configurations but I have had no luck. Any suggestions before I NUKEIT ?Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:
  • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    • Let this run UNDISTURBED until the window with the blue progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.Thanks for sticking with me.

Not sure I understood the proper procedure for running it. It never wanted to go to the CD drive for the file.

I tried as you said and it did not run. Did open a window but then hangs, no progress bar indicator. Tried this multiple times.

I read up on this SFC and found where it should be located. "D" is my CD drive.
I then tried d:\i386\sfc \scannow and that did not work. Guess cause file there is marked as SFC.EX_

I then found that I have two copies of this file on my c drive. One in c:\i386\ and another in c:\windows\system32\

When I point a full path the c:\386 version a window opens too quick to read and closes again.

I checked in the registry and the CurrentVersion\setup is pointed to C\... and not the D drive.

Any other suggestions?
It should be run with the C drive.

Post a fresh HijackThis log please.So you directed me to insert the CD just in case the SFC.exe file was not present on the C drive then?
I am attaching a new hijack log.



[Saving space, attachment deleted by admin]I have not been overly impressed with the help I received here. Realizing that you offer help on your own time and for free I do want to Thank you for trying.
I am Nukin it now!There is only so much we can do...
3805.

Solve : my computer crashed?

Answer»

I have toshiba satalite laptop A25-s3072. recently while working on my laptop it crashed and shut down. After five minutes when I power up the computer I got the following message:
A problem has been detected and window has been shut down to prevent damage to your computer.


Disable or uninstall any anti-virus, disc de frangementation or back-up utilities. Check your hard drive configuration and check for any updated DRIVER corruption and then restart your computer.

Technical INFORMATION:
STOP: 0x00000024,(0x00190203, 0x85FDC5B8, 0x c 0000102, 0x 00000000)

I really do not know how to clear this fault. Any one can please help me to get out of this trouble?
Where you blocking the vent?? (like putting it on a bed) if you do that you blocking ventilation to cool off your cpu. if you do that your cpu BECOMES overheated and your computer will shut off to prevent a fire or damage to your computer. next time go to a flat surface so your computer can have ventilation.this should be in the hardware FORUM

3806.

Solve : Best subscription Anti-Virus?

Answer»

I have tried several free anti-virus programs and have found that most of them just don't cut the mustard.
I prefer ONE that you make a one-time PAYMENT and can use it on as many computers as you want to, but if you have to pay a MINIMUM yearly subscription, that's okay, too. PCW rated 5 AV programs from best to worst-
G-Data, Symantic Norton AV 2010, Kapersky AV 2010, Bit Defender AV 2010, and Panda AV Pro 2010. Users NEARLY 2-1 didn't like G-Data.
I used Avg for many years and it didn't catch all problems. Then I went to AVIRA. When working on other people's computers, I've found Norton AV a bear to remove. Plus, they want to keep charging on your credit card. Any feedback on NOD?I never tried NOD, but I have Kaspersky and I think its the best subscription Internet Security Suite and I never had any problems with Kaspersky and my PC still has high performance and no viruses.

3807.

Solve : Avast boot scan/ files corrupted?

Answer»

Just finished BOOT scan USING avast there was multiple items show up saying files corrupted, the items were registry items is this something to be worried about. Also is there a way to post logs from avast of the boot scan that i can post here?

Thanks Bunafireman825Welcome the COMPUTER Hope MESSAGE boards.

I have noticed you have not followed the guidelines SET by Evilfantasy. Please follow the guidelines he has posted Here. After you have done them, a malware removal specialist such as Evilfantasy or CBMatt Will come shortly to assist you.

3808.

Solve : Windows Defender Help!?

Answer»

I have Windows Defender and Norton 360, everytime I load the computer Windows Defender says: Windows Defender is not on, would you like to turn it on? So I have to do that everytime.

Is there a way for it to just stay on!?!I may be able to sort this problem out. You will need to follow the simple steps below:

1. Go to start
2. Go to All PROGRAMS
3. Click the startup folder (This is the folder that will startup programs on startup)
4. Now that you have taken note of where the startup folder is find the windows defender icon
5. Click and DRAG the icon into "Startup" (In step 1, 2 and 3.)

The program will now start on startup, if there is any PROBLEMS, PLEASE contact me back.


3809.

Solve : What is a good Viruse protection??

Answer»

link removed , what was wrong with it , i took wot out I prefer AVAST.I'll have to give it a try. Has anyone had trouble getting AVG completely off their pc?Here's the AVG removal tool.

http://www.avg.com/download-toolsAvast here also....
Thanks Karnac.On my main PC I use Kaspersky Internet Security and Avast Home on all the others.

Cameron GrayQuote from: camerongray on August 09, 2009, 05:46:17 AM

On my main PC I use Kaspersky Internet Security and Avast Home on all the others.

Cameron Gray

I wonder if you could advise me then - have used avg in the past, but prefer Avast. I had pondered trying Avira but not tried it yet. My bank are offering Kaspersky (AV only) for free so I wondered whether you FELT it was better, faster & less resource hungry?

cheersi have tried avg , macafee , norton and have kept with avira I would say, if you have one antivirus software that you like and it is doing well and updates at least once every 24 hours and has realtime protection, then just stay with it.

Kaspersky is a good AV as well, but considering it's free, I'd still go with Avast because it has the antimalware/antispyware components that the free version of Kaspersky OFFERED by your bank does not include. You'd have to pay for a subscription to GET all the other stuff.thanks for that...

the version of kaspersky offered is http://www.kaspersky.co.uk/kaspersky_internet_security which i believe does include antimalware / antispyware.

avast is ok, but sometimes I feel it is slow. Since the suite offered by my bank includes a firewall too I wonder if my system MAY be improved (no longer run avast & zone alarm).yeah but however, is your bank offering the KAV for life? You'll have to pay for a subscription/key when it expires if you want to continue using it after it expires.well they've renewed it the last few years, but i guess i will cross that bridge when i come to itQuote from: Helpmeh on August 05, 2009, 04:29:33 PM
I suggest staying away from Norton (personal experience: very slow and resource greedy).
i agree with that
norton takes processing power
and sometimes not even idle power too
McAfee.. However it slows down your computer if you don't have the correct mimimum requirements... AVG is the 2nd best.
3810.

Solve : What's the best operating system??

Answer» HEY! What operating SYSTEM do YOU like the most? Have a little vote, my best one is:

WINDOWS XP On a good day Operating System Poll #150 Initialized.I THINK XP is the best because the hundreds of other polls on this forum say so; without GIVING any reasons to back up their decision.
3811.

Solve : Got a program that keeps wanting to in stall when turning on the computer?

Answer»

Every time i turn on my machine i get this program that WANTS to install looks like a EXE that has been download
off of firefire fox i am not GOING to install its more annoying than anything anyone GOT any ideas on how to get rid of this little annoying problem I got windows vista HOME basic on this machineWhat is the program?

3812.

Solve : Run other programs while doing an AV scan??

Answer»

Do you know if it's ok to run other PROGRAMS while doing an AV SCAN?

3813.

Solve : Computer shut down it self?

Answer»

I have windows xp and it shut down on its own. I restarted ran for half hour then shut down again. This went on two more times and the last time it said window shutting down and cannot restart. Help Carol,

SOUNDS like a heat or power problem....how is your housekeeping?........check inside the case and blow out all the dust with a can of compressed air.......not difficult to check......UNSCREW two or three screws on the edge of the case and slide the panel back...

Maybe this should be moved to hardware.....This could possibly be a virus effecting your computer in an annoying way. Have you got internet security? Also, Karnac is correct, try blowing the dust out of the computer, as SOMETIMES it can clog THING's up. There are also other suggestions, such as power supply problems, your power supply could be SHORTING out, it can be loads of things..

Question: Does it just cut out? Or says "Windows is shutting down" ?The computer shut down twice with no warning. The computer came up again then shut down with windows saying windows shutting down. When the computer shut down the second time I was running a virus scan. When I tried to restart the power only lasted 3 seconds never came .

3814.

Solve : CyberDefender. Is this a Scam??

Answer»

but NEVER pay for questionable software
if it SEEMS fishy dont use it
i am not an expert in viruses and SPYWARE but i dont recommed using it
There are many websites/companies who MAKE GOOD or legitimate softwares/fixes but just charge way more than necessary to fix it.

3815.

Solve : Need help with malware?

Answer»

I've read the info page and thus far have run Avast, which found three or four trojans. Before coming here I had already tried to run SUPERantispyware (already on my machine) and couldn't. I uninstalled but was unable to reinstall from the site. I was able to download from Cnet but I cannot install it. I have also run Windows Defender and the regular version of Ccleaner which I already had on. I wanted to double check if I need to specifically download the CC slim version, if I am able to download. At the moment I cannot access most antispyware related sites.

I am pretty sure I'm dealing with ad.doubleclick.net issues as ads on websites are being switched to the inappropriate kinds and my dh had vulgar pop ups to deal with. Never had the latter kinds of problems before. Comp is running slow and sometimes freezing up.

Since I cannot download SAS, do I just continue down the list and see what I am able to do?

TIA for your help!Just make note of what happens and continue on with the next step....I've completed steps 1 and 2.

Couldn't complete 3 or 4. I was able to download from alternative download sites but they wouldn't install - got Microsoft message "SUPERantispyware has encountered a problem and needs to close" and the same for Malwarebytes.

I completed step 5, although I forgot to close my browser. Am I okay or should I reinstall?

That brings me to step 6, Hijack This. The directions SAY to run this after the other steps have been completed. Since they can't be completed, should I just go ahead and run Hijack This and post the log?Mbam renamer


Try the renamer download for Malwarbytes.

http://kixhelp.com/wr/files/mb/randmbam.exe

The randmbam.exe will try to create random names and shortcuts for Malwarebytes Anti Malware (MBAM) if you have it installed already.

If it installs then use this link to download the updates.

Download Malwarebytes' Anti-Malware Database - GT500.org

Just download it to the desktop and run the exe then run Malwarebytes


You can try download SAS in safe mode or try renaming the file to sniper.exe and see if you can run it that way........if you can't then just go on to HJT and see if you can run it.............Ok, I was able to get SAS and Malwarebytes logs. Had to get a go-around download and run from SAS support. It made it through but froze as I clicked to quarantine. The renamer worked for Malwarebytes and I was able to complete the scan. Followed the directions for HijackThis. It took several tries because it either froze or the comp restarted, but I got the log. I'll post all three below.

Although some trojans have been detected and quarantined, the comp is still running slow or freezing, and I am still dealing with inappropriate pop ups and switched ads on websites. Two other things I forgot to mention: my Seagate external hard drive has stopped functioning in all this, with a message that it cannot find any drives; and neither the disk fragmentor or the chkdsk is operational.

Thanks so much for the help thus far. Hope you can help me figure the rest out.

SAS:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/17/2009 at 11:22 PM

Application Version : 4.26.1006

Core Rules Database Version : 3966
Trace Rules Database Version: 1906

Scan type : Complete Scan
Total Scan Time : 01:02:22

Memory items scanned : 619
Memory threats detected : 0
Registry items scanned : 6439
Registry threats detected : 4
File items scanned : 33962
File threats detected : 3

Trojan.Unknown Origin
HKU\.DEFAULT\Software\ColdWare
HKU\S-1-5-18\Software\ColdWare

Trojan.DNS-Changer (Hi-Jacked DNS)
HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{0A9A4FEC-465F-4421-8F47-4242C1C17886}#NAMESERVER
HKLM\SYSTEM\CONTROLSET003\SERVICES\TCPIP\PARAMETERS\INTERFACES\{0A9A4FEC-465F-4421-8F47-4242C1C17886}#NAMESERVER

Adware.Tracking Cookie
C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][2].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][1].txt
C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][1].txt



MALWAREBYTES:

Malwarebytes' Anti-Malware 1.39
Database version: 2454
Windows 5.1.2600 Service Pack 2

7/18/2009 12:51:06 AM
mbam-log-2009-07-18 (00-51-06).txt

Scan type: Quick Scan
Objects scanned: 155866
Time elapsed: 6 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1720a2b8-5386-4d8a-8527-260871b6c7b5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1720a2b8-5386-4d8a-8527-260871b6c7b5} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\niguwufosa (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\c:\WINDOWS\system32\memman.vxd (Rogue.sysCleanerPro) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.109,85.255.112.192 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.109,85.255.112.192 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.109,85.255.112.192 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\memman.vxd (Rogue.sysCleanerPro) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.


HIJACKTHIS:

Logfile of Trend Micro HijackThis

v2.0.2
Scan saved at 1:50:02 AM, on

7/18/2009
Platform: Windows XP SP2 (WinNT

5.01.2600)
MSIE: Internet Explorer v7.00

(7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows

Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil

Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program

Files\ContentWatch\Internet

Protection\cwsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\zHotkey.exe
C:\Program

Files\CyberLink\PowerDVD\PDVDSe

rv.exe
C:\Program Files\Digital Media

READER\shwiconem.exe
C:\Program Files\Common

Files\Microsoft Shared\Works

Shared\WkUFind.exe
C:\Program Files\Windows

Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\as

hDisp.exe
C:\Documents and Settings\All

Users\common\dll\netdr\msdtc.exe
C:\Program

Files\MEDIC\bin\sprtcmd.exe
C:\WINDOWS\system32\WTClient.ex

e
C:\WINDOWS\system32\rundll32.exe
C:\Program

Files\Seagate\Basics\Basics

Status\MaxMenuMgrBasics.exe
C:\Program

Files\ScanSoft\OmniPageSE4\Opwar

eSE4.exe
C:\Program

Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\a-squared

Free\a2service.exe
C:\Program

Files\QuickTime\QTTask.exe
C:\Program

Files\iTunes\iTunesHelper.exe
C:\Program

Files\ContentWatch\Internet

Protection\cwtray.exe
C:\Program

Files\Java\jre6\bin\jusched.exe
C:\Program

Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware

Terminator\SpywareTerminatorUpdat

e.exe
C:\Program Files\Common

Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceServi

ce.exe
C:\Program

Files\Seagate\Basics\Service\SyncS

ervicesBasics.exe
C:\Program

Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New

Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware

Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.

exe
C:\WINDOWS\System32\Drivers\WT

SRV.EXE
C:\Program

Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program

Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WISPTIS.EX

E
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend

Micro\HijackThis\sniper.exe

R1 -

HKCU\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/custo

mize/ycomp_wave/defaults/sb/*http://

www.yahoo.com/search/ie.html
R1 -

HKCU\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/custo

mize/ycomp_wave/defaults/sp/*http://

www.yahoo.com
R0 -

HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.crosswalk.com/homeschoo

l
R1 -

HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=

69157
R1 -

HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=

54896
R1 -

HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=

54896
R0 -

HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=

69157
R1 -

HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Road

Runner High Speed Online
R1 -

HKCU\Software\Microsoft\Windows\C

urrentVersion\Internet

Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub -

{18DF081C-E8AD-4283-A596-FA57

8C2EBDC3} - C:\Program

Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEH

elperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV

Helper -

{DBC80044-A445-435b-BC74-9C25

C1C588A9} - C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -

{E7E6F031-17CE-4C07-BC86-EAB

FE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl

ugin.dll
O2 - BHO: (no name) -

{FDD3B846-8D59-4ffb-8758-209B6

AD74ACC} - (no file)
O4 - HKLM\..\Run: [SoundMan]

SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon]

RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,Nv

Startup
O4 - HKLM\..\Run: [nwiz] nwiz.exe

/install
O4 - HKLM\..\Run: [NvMediaCenter]

RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll

,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray

Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey]

zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd]

ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl]

"C:\Program

Files\CyberLink\PowerDVD\PDVDSe

rv.exe"
O4 - HKLM\..\Run: [SunKistEM]

C:\Program Files\Digital Media

Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works

Update Detection] C:\Program

Files\Common Files\Microsoft

Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Windows

Defender] "C:\Program

Files\Windows

Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\as

hDisp.exe
O4 - HKLM\..\Run: [QuickTime]

C:\Documents and Settings\All

Users\common\dll\netdr\msdtc.exe
O4 - HKLM\..\Run: [MEDIC]

"C:\Program

Files\MEDIC\bin\sprtcmd.exe" /P

MEDIC
O4 - HKLM\..\Run: [WTClient]

WTClient.exe
O4 - HKLM\..\Run: [basicsmssmenu]

"C:\Program

Files\Seagate\Basics\Basics

Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate]

"C:\Program Files\Common

Files\Scansoft

Shared\SSBkgdUpdate\SSBkgdupda

te.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4]

"C:\Program

Files\ScanSoft\OmniPageSE4\Opwar

eSE4.exe"
O4 - HKLM\..\Run:

[CanonSolutionMenu] C:\Program

Files\Canon\SolutionMenu\CNSLMAI

N.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter]

C:\Program

Files\Canon\MyPrinter\BJMyPrt.exe

/logon
O4 - HKLM\..\Run: [Adobe Reader

Speed Launcher] "C:\Program

Files\Adobe\Reader

9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program

Files\QuickTime\QTTask.exe"

-atboottime
O4 - HKLM\..\Run: [iTunesHelper]

"C:\Program

Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cwcptray]

C:\Program

Files\ContentWatch\Internet

Protection\cwtray.exe
O4 - HKLM\..\Run:

[SunJavaUpdateSched] "C:\Program

Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS]

"C:\Program

Files\Messenger\msmsgs.exe"

/background
O4 - HKCU\..\Run: [MoneyAgent]

"C:\Program Files\Microsoft

Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run:

[SUPERAntiSpyware] C:\Program

Files\SUPERAntiSpyware\SUPERAnt

iSpyware.exe
O4 - HKCU\..\Run:

[SpywareTerminatorUpdate]

"C:\Program Files\Spyware

Terminator\SpywareTerminatorUpdat

e.exe"
O4 - HKUS\S-1-5-19\..\Run:

[niguwufosa] Rundll32.exe

"C:\WINDOWS\system32\zodavula.dll

",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run:

[niguwufosa] Rundll32.exe

"C:\WINDOWS\system32\zodavula.dll

",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run:

[DWQueuedReporting]

"c:\PROGRA~1\COMMON~1\MICRO

S~1\DW\dwtrig20.exe" -t (User

'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce:

[RunNarrator] Narrator.exe (User

'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run:

[DWQueuedReporting]

"c:\PROGRA~1\COMMON~1\MICRO

S~1\DW\dwtrig20.exe" -t (User

'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce:

[RunNarrator] Narrator.exe (User

'Default user')
O8 - Extra context menu item: &AOL

Toolbar search - res://C:\Program

Files\AOL

Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-0040

1C608501} - C:\Program

Files\Java\jre6\bin\npjpi160_14.dll
O9 - Extra 'Tools' menuitem: Sun Java

Console -

{08B0E5C0-4FCB-11CF-AAA5-0040

1C608501} - C:\Program

Files\Java\jre6\bin\npjpi160_14.dll
O9 - Extra button: Research -

{92780B25-18CC-41C8-B9BE-3C9C

571A8263} -

C:\PROGRA~1\MICROS~3\Office12\

REFIEBAR.DLL
O9 - Extra button: Real.com -

{CD67F990-D8E9-11d2-98FE-00C0

F0318AFE} -

C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba384

96583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:

@xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba384

96583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04

F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04

F795683} - C:\Program

Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP:

c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP:

c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP:

c:\windows\system32\cwalsp.dll
O16 - DPF:

{01113300-3E00-11D2-8470-006008

9874ED} (Support.com Configuration

Class) -

http://activation.rr.com/install/downloa

ds/tgctlcm.cab
O16 - DPF:

{17492023-C23A-453E-A040-C7C5

80BBF700} (Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=

39204
O20 - AppInit_DLLs:

C:\WINDOWS\system32\wugakuwa.dl

l
O20 - Winlogon Notify:

!SASWinLogon - C:\Program

Files\SUPERAntiSpyware\SASWINL

O.dll
O23 - Service: a-squared Free

Service (a2free) - Emsi Software

GmbH - C:\Program Files\a-squared

Free\a2service.exe
O23 - Service: Apple Mobile Device -

Apple Inc. - C:\Program

Files\Common Files\Apple\Mobile

Device

Support\bin\AppleMobileDeviceServi

ce.exe
O23 - Service: avast! iAVS4 Control

Service (aswUpdSv) - ALWIL

Software - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus -

ALWIL Software - C:\Program

Files\Alwil

Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner -

ALWIL Software - C:\Program

Files\Alwil

Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner -

ALWIL Software - C:\Program

Files\Alwil

Software\Avast4\ashWebSv.exe
O23 - Service: Basics Service -

Seagate TECHNOLOGY LLC -

C:\Program

Files\Seagate\Basics\Service\SyncS

ervicesBasics.exe
O23 - Service: Bonjour Service -

Apple Inc. - C:\Program

Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera

Access Library 8 (CCALib8) - Canon

Inc. - C:\Program

Files\Canon\CAL\CALMAIN.exe
O23 - Service: ContentWatch

(CwAltaService20) - ContentWatch,

Inc. - C:\Program

Files\ContentWatch\Internet

Protection\cwsvc.exe
O23 - Service: InstallDriver Table

Manager (IDriverT) - Macrovision

Corporation - C:\Program

Files\Common

Files\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: iPod Service - Apple

Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun

Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver

Service (NVSvc) - NVIDIA

Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New

Boundary Technologies, Inc. -

C:\Program Files\Common Files\New

Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Spyware Terminator

Realtime Shield Service (sp_rssrv) -

Crawler.com - C:\Program

Files\Spyware

Terminator\sp_rsser.exe
O23 - Service: SecuROM User

Access Service (V7) (UserAccess7) -

Unknown owner -

C:\WINDOWS\system32\UAService7.

exe
O23 - Service: WinTab Service

(WinTabService) - Tablet Driver -

C:\WINDOWS\System32\Drivers\WT

SRV.EXE

--
End of file - 11037 bytes

I forgot to mention that I was unable to update SAS or Malwarebytes. I was able to access updates for HijackThis.Good job getting the required logs......Evilfantasy will be along to review them....be patient....it's a summer weekend.you need to go to seagate ( seagate for windows ) sort out your machine download and let it scan the pc


http://www.seagate.com/www/en-us/support/downloads/seatools

go to below and download smart defrag

http://www.iobit.com/Download The Comedian to your desktop.

* Double click the program to run it.
* It will do a series of tasks and tell you when each one is FINISHED.
* You will be prompted to press any key after each step
* When it is done it will close and exit itself automatically.
* You can delete The_Comedian.exe once it is finished.
.
----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixThanks for getting back to me!

I downloaded and ran The Comedian but on Step 4 it said it could not create a restore point. Should I still proceed to Combofix? Also, I wasn't sure when it asked about CREATING registry back ups kept for 30 days; I checked ok. Yes just continue on please.Here's the ComboFix log. Couldn't run it as ComboFix so I tried the renaming to Combo-Fix and that worked.

ComboFix 09-07-23.04 - Owner 07/24/2009 17:21.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.43 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090723-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-2212892535-3016890555-2903492491-1003
c:\windows\desktop
c:\windows\desktop\EA Hot Titles!.exe
c:\windows\Installer\132159e.msp
c:\windows\Installer\acbac.msi
c:\windows\system32\drivers\ESQULxuwyltfqxuuwpdqbpnobodpqqtjkbmup.sys
c:\windows\system32\ESQULabwwxiqpeltobirvvjmldunqkeqbrgai.dll
c:\windows\system32\ESQULrbhtkbljbmtclcvtqjoetiwlrtsrtena.dll
c:\windows\system32\ESQULzcounter
c:\windows\system32\MabryObj.dll
c:\windows\system32\skinboxer43.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ESQULserv.sys
-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.

2009-07-24 18:56 . 2009-07-24 18:57--------d-----w-c:\program files\ERUNT
2009-07-22 01:15 . 2009-07-22 01:15--------d-----w-c:\documents and settings\Owner\Application Data\IObit
2009-07-22 01:15 . 2009-07-22 01:15--------d-----w-c:\program files\IObit
2009-07-18 05:06 . 2009-07-18 05:06--------d-----w-c:\program files\Trend Micro
2009-07-18 04:38 . 2009-07-18 04:38--------d-----w-c:\documents and settings\Owner\Application Data\Malwarebytes
2009-07-18 02:13 . 2009-07-18 02:13--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-07-18 00:55 . 2009-07-18 00:55142592----a-w-c:\windows\system32\drivers\sp_rsdrv2.sys
2009-07-18 00:54 . 2009-07-24 20:37--------d-----w-c:\documents and settings\Owner\Application Data\Spyware Terminator
2009-07-18 00:54 . 2009-07-24 18:46--------d-----w-c:\docume~1\ALLUSE~1\APPLIC~1\Spyware Terminator
2009-07-18 00:54 . 2009-07-18 00:59--------d-----w-c:\program files\Spyware Terminator
2009-07-17 21:31 . 2009-07-17 21:32--------d-----w-c:\program files\a-squared Free
2009-07-17 13:17 . 2009-07-17 13:17410984----a-w-c:\windows\system32\deploytk.dll
2009-07-17 13:12 . 2009-07-17 13:12152576----a-w-c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-17 12:59 . 2009-07-13 17:3638160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-17 12:59 . 2009-07-17 12:59--------d-----w-c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-07-17 12:59 . 2009-07-18 04:38--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-07-17 12:59 . 2009-07-13 17:3619096----a-w-c:\windows\system32\drivers\mbam.sys
2009-07-11 03:02 . 2009-07-11 03:02--------d-----w-c:\documents and settings\Owner\ContentWatch
2009-07-07 01:49 . 2009-07-07 01:497639----a-w-c:\windows\extend.dat
2009-07-05 20:43 . 2004-08-04 02:585504-c--a-w-c:\windows\system32\dllcache\mstee.sys
2009-07-05 20:43 . 2004-08-04 02:585504----a-w-c:\windows\system32\drivers\MSTEE.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 19:45 . 2007-01-30 15:13--------d-----w-c:\program files\Mozilla Thunderbird
2009-07-23 15:57 . 2005-01-08 20:3439514----a-w-c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-07-22 00:36 . 2008-05-28 11:47--------d-----w-c:\program files\SUPERAntiSpyware
2009-07-17 13:39 . 2004-10-01 15:45--------d-----w-c:\program files\Java
2009-07-16 11:31 . 2004-10-01 16:04--------d-----w-c:\docume~1\ALLUSE~1\APPLIC~1\Viewpoint
2009-07-10 21:36 . 2009-07-10 21:34--------d-----w-c:\program files\ContentWatch
2009-07-10 21:20 . 2007-12-04 14:25--------d-----w-c:\program files\Internet Content Filter
2009-07-10 19:33 . 2008-07-02 18:3034----a-w-c:\documents and settings\Owner\jagex_runescape_preferences.dat
2009-07-07 23:04 . 2008-10-14 21:54139776----a-w-c:\documents and settings\Gabe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-06 01:46 . 2008-10-15 12:33139776----a-w-c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-03 00:29 . 2007-10-22 23:51139776----a-w-c:\documents and settings\Sarah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 00:03 . 2007-10-12 03:10139776----a-w-c:\documents and settings\Matt\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 18:54 . 2009-06-11 22:09--------d-----w-c:\documents and settings\Owner\Application Data\vlc
2009-06-26 00:28 . 2005-01-08 20:34139776----a-w-c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 19:13 . 2004-10-01 15:35--------d--h--w-c:\program files\InstallShield Installation Information
2009-06-25 15:46 . 2007-10-30 16:34--------d-----w-c:\documents and settings\Owner\Application Data\gtk-2.0
2009-06-19 02:18 . 2009-06-25 16:0916980----a-w-c:\windows\Fonts\electroh.ttf
2009-06-16 14:55 . 2004-01-02 08:06119808----a-w-c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-01-02 08:0382432----a-w-c:\windows\system32\fontsub.dll
2009-06-11 22:10 . 2009-01-05 22:52--------d-----w-c:\program files\Graboid
2009-06-11 22:03 . 2009-06-11 22:03--------d-----w-c:\program files\Mozilla ActiveX Control v1.7.12
2009-06-11 03:49 . 2009-06-11 03:49--------d-----w-c:\program files\iTunes
2009-06-11 03:49 . 2009-06-11 03:49--------d-----w-c:\program files\iPod
2009-06-11 03:49 . 2009-01-16 06:52--------d-----w-c:\program files\Common Files\Apple
2009-06-11 03:46 . 2009-06-11 03:45--------d-----w-c:\program files\QuickTime
2009-06-11 03:40 . 2009-01-16 06:52--------d-----w-c:\docume~1\ALLUSE~1\APPLIC~1\Apple
2009-06-08 15:32 . 2009-07-10 21:34247616----a-w-c:\windows\system32\wxIE.dll
2009-06-08 15:32 . 2009-07-10 21:341859584----a-w-c:\windows\system32\AltaRecovery.exe
2009-06-08 15:12 . 2009-07-10 21:34666624----a-w-c:\windows\system32\cwalsp.dll
2009-06-08 14:52 . 2009-07-10 21:3481920----a-w-c:\windows\system32\wxcode_msw28u_wxjson_CW.dll
2009-06-08 14:52 . 2009-07-10 21:34991232----a-w-c:\windows\system32\wxcode_msw28u_wxcurl_CW.dll
2009-06-08 14:50 . 2009-07-10 21:34975872----a-w-c:\windows\system32\libxml2_CW.dll
2009-06-08 14:46 . 2009-05-19 17:13151552----a-w-c:\windows\system32\libexpat.dll
2009-06-08 14:27 . 2009-07-10 21:34524288----a-w-c:\windows\system32\wxmsw28u_xrc_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:34499712----a-w-c:\windows\system32\wxmsw28u_html_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:342904064----a-w-c:\windows\system32\wxmsw28u_core_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:34110592----a-w-c:\windows\system32\wxmsw28u_media_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:34712704----a-w-c:\windows\system32\wxmsw28u_adv_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:34135168----a-w-c:\windows\system32\wxbase28u_xml_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:34135168----a-w-c:\windows\system32\wxbase28u_net_vc_CW.dll
2009-06-08 14:27 . 2009-07-10 21:341232896----a-w-c:\windows\system32\wxbase28u_vc_CW.dll
2009-06-05 15:42 . 2009-03-20 01:482060288----a-w-c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2009-01-16 06:5239424----a-w-c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:27 . 2004-01-02 08:061290752----a-w-c:\windows\system32\quartz.dll
2009-05-27 21:43 . 2009-05-27 21:43--------d-----w-c:\program files\Unity
2009-05-07 15:44 . 2004-01-02 08:04344064----a-w-c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-01-02 08:06827392----a-w-c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-01-02 08:0378336----a-w-c:\windows\system32\ieencode.dll
2009-07-24 18:46 . 2009-03-09 18:10134648----a-w-c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-01-24 18:44 . 2009-01-24 18:448--sh--r-c:\windows\system32\B3590867F3.sys
2009-04-12 16:20 . 2009-01-12 16:205696--sha-w-c:\windows\system32\bahegope.exe
2009-01-25 04:14 . 2009-01-24 18:44848--sha-w-c:\windows\system32\KGyGaAvL.sys
2009-04-11 22:08 . 2009-01-11 22:085696--sha-w-c:\windows\system32\yewukulu.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-19 200704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-07-18 3055616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-03-04 2904064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-03-04 46080]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-03-11 135168]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime"="c:\documents and settings\All Users\common\dll\netdr\msdtc.exe" [2007-12-27 466944]
"MEDIC"="c:\program files\MEDIC\bin\sprtcmd.exe" [2006-12-27 192512]
"basicsmssmenu"="c:\program files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe" [2007-10-09 169328]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"cwcptray"="c:\program files\ContentWatch\Internet Protection\cwtray.exe" [2009-06-08 351040]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-17 148888]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-08-15 57344]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-03-04 782336]
"nForce Tray Options"="sstray.exe" - c:\windows\system32\sstray.exe [2003-09-03 73728]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2004-05-18 543232]
"ShowWnd"="ShowWnd.exe" - c:\windows\ShowWnd.exe [2003-09-19 36864]
"WTClient"="WTClient.exe" - c:\windows\system32\WTClient.exe [2007-04-11 40960]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-27 434528]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2006-10-04 53760]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Microsoft Games\\Motocross Madness 2\\MCM2.ICD"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\k9-webprotection.exe"=
"c:\\Program Files\\ZyDAS Technology Corporation\\ZyDAS_802.11g_Utility\\ZDWlan.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/4/2008 6:13 AM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [7/17/2009 8:55 PM 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/4/2008 6:13 AM 20560]
R2 CwAltaService20;ContentWatch;c:\program files\ContentWatch\Internet Protection\cwsvc.exe [7/10/2009 5:34 PM 2072384]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [3/7/2008 1:53 PM 20608]
S3 mr97310c;CIF Dual-Mode Camera;c:\windows\system32\drivers\mr97310c.sys [7/5/2009 4:42 PM 107904]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.crosswalk.com/homeschool
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
LSP: c:\windows\system32\cwalsp.dll
Trusted Zone: christianbook.com Trusted Zone: christianbook.com https\dlm
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\ne8x1sqs.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.conservapedia.com/Main_Page
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ne8x1sqs.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ne8x1sqs.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-24 17:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\_av_proI.tm~a03680\stamp.tmp 10 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3388798203-652253650-2994196867-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3388798203-652253650-2994196867-1003\Software\YourCompanyName\YourProductName\Version*]
"VersionData"=hex:0d,3b,25,66,19,03,6e,fd,4f,a8,a2,fa,9d,e1,52,c2,8a,f9,01,99,
85,ff,f4,59,07,45,91,f9,29,b3,aa,34,31,2b,f2,f4,e1,09,ad,08,4c,48,f7,d3,42,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(628)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'lsass.exe'(684)
c:\windows\system32\cwalsp.dll
c:\windows\system32\wxbase28u_vc_CW.dll

- - - - - - - > 'explorer.exe'(3504)
c:\windows\system32\nview.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\drivers\WTSrv.exe
c:\windows\system32\WISPTIS.EXE
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-07-24 18:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-24 22:04

Pre-Run: 75,996,536,832 bytes free
Post-Run: 76,592,431,104 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

279--- E O F ---2009-07-23 15:28
Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the Desktop.

----------

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combo-fix /u in the runbox
* Make sure there's a space between Combo-fix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the ESET Online Antivirus Scanner

This scanner requires Internet Explorer

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.I think I uninstalled Windows Messenger. I followed the directions and chose the appropriate box. On the desktop I found only the icon for the zip file, so I deleted that. I had the save file box pop up several more times. Not sure why. I just clicked them off and restarted the comp. The Windows Messenger icon is gone and a search for it yielded nothing, so here's hoping.

I haven't been able to uninstall Combo-fix. When I try to run Combo-fix /u, I get a message that the file can't be found. When I try to uninstall Combofix /u, I get the prompt to run combofix.exe. I did check C: for Combofix and Combo-fix files and folders and they are still there. I'm checking back to see how to proceed.

3816.

Solve : Windows will not load?

Answer»

I recently installed Nortons 360 on my home computer. I received a NOTICE that I had a upgrade to Nortons 2009 which I received. When the program removed my old Nortons and restarted my computer I received a message that Windows could not start because PART was missing. After much trial and error I finally got the computer up using my start up CD. Each time I contacted Nortons and they tried to work the issue a reboot of the system yielded the same message as before. Now my system will not restart even using the start up CD. I now get the message "Window could not CONFIGURE one or more system components. To install Windows, restart the computer and reinstall." Any help would be greatly appreciated. Also I have not tried a total restart from the CD since there is material that I would rather not loose.go to tools , internet options , advanced , reset internet explorer options , reset , and follow through

read what it will do before you start , this will put your pc back to factory settings but take

nothing you need outXP? If so, boot to the XP CD and choose the SECOND repair OPTION and do a repair install.Quote from: harry 48 on August 18, 2009, 01:53:10 PM

go to tools , internet options , advanced , reset internet explorer options , reset , and follow through

read what it will do before you start , this will put your pc back to factory settings but take

nothing you need out
Harry, how is resetting Internet Explorer going to put his computer back to factory settings?Quote from: SuperDave on August 18, 2009, 05:40:56 PM
Harry, how is resetting Internet Explorer going to put his computer back to factory settings?
That's exactly what I'm wondering too. sorry it puts windows back to when you got it , am i wrong in saying this because this is what i got out of the reading when i do it twice a yearQuote from: harry 48 on August 19, 2009, 12:45:40 PM
sorry it puts windows back to when you got it , am i wrong in saying this because this is what i got out of the reading when i do it twice a year
No, it resets Internet Explorer to the default settings - nothing else.ok , i'll go read it Quote from: harry 48 on August 19, 2009, 01:11:12 PM
ok , i'll go read it
Please copy and paste the thing you read. Quote from: Helpmeh on August 19, 2009, 04:06:15 PM
Please copy and paste the thing you read.
I really don't think there's any point, do you? Clearly he simply didn't understand what he was reading, wouldn't you say?there is more after that but do not want to start it

[attachment deleted by admin]I'm not sure what part of that you think refers to the OS as opposed to Internet Explorer, but it certainly seems clear to me.Quote from: ADG on August 19, 2009, 04:23:52 PM
I'm not sure what part of that you think refers to the OS as opposed to Internet Explorer, but it certainly seems clear to me.
Same here. Either harry reads the hidden text that makes up the background of that message box or he read it wrong. Sorry. ok i must have read it wrong
3817.

Solve : BIOS Virus?

Answer»

What is a BIOS Virus?
Are they preventable? (besides having an AV scanner)
Are they common, or were they at one time?
Are new computers exposed to them?
What damage do they cause?
Is it difficult to make a program or malicious code that can access the BIOS?

A bit questioning today - Zylstra555http://www.google.com/search?hl=en&q=BIOS+virus

I don't think so.You're probably thinking of a BOOT sector virus...not as common as they used to be but are going through a resurgence as the newest batch of malicious idiots are cutting their chops in the malware world.
They are particularly hard to get rid of and usually need a floppy based AV to sniff them out and remove them or a complete low-level FORMAT and re-partitioning of a HDD in extreme cases.Quote

You're probably thinking of a boot sector virus...not as common as they used to be but are going through a resurgence as the newest batch of malicious idiots are cutting their chops in the malware world.
They are particularly hard to get rid of and usually need a floppy based AV to sniff them out and remove them or a complete low-level format and re-partitioning of a HDD in extreme cases.
No, not thinking of an MBR virus.
(Easy fix for those since I had a problem with a Windows 3.0 instalation disk at one point:
fdisk /mbr
re-writes the Master Boot Record. It can even clear a program like Lilo, so it can be problamatic)
After my research, (From GX1_Man's link to Google), I found out that they do exist, and that they can be quite dammaging.
I had an uncle who said at one time a long time ago that he had a BIOS virus, and I wanted to do more research on it some day. (now I know)
The BIOS are infected through the BIOS Updates (which, on many BIOS chips, can be dissabled to prevent such a virus)

Quote from: Zylstra on March 07, 2007, 02:15:36 PM
No, not thinking of an MBR virus.
(Easy fix for those since I had a problem with a Windows 3.0 instalation disk at one point:
fdisk /mbr
re-writes the Master Boot Record. It can even clear a program like Lilo, so it can be problamatic)
After my research, (From GX1_Man's link to Google), I found out that they do exist, and that they can be quite dammaging.
I had an uncle who said at one time a long time ago that he had a BIOS virus, and I wanted to do more research on it some day. (now I know)
The BIOS are infected through the BIOS Updates (which, on many BIOS chips, can be dissabled to prevent such a virus)



Does a rootkit stop an MBR virus, or scan for it?
If not, can Avast or Panda scan ONLY the MBR. I'm the guy with the cross partition deal. So, I FIGURE I'd hide partitions, but since the MBR will still be vulnerable I would scan for that before SWITCHING from dirter to clean partion (OS installs) and boot from CD to do the scan. I woudn't get lazy then, hopefully, and blow it off cuz I don't have to do a whole scan _
then dont update the bios
i have never heard of a bios virus
3818.

Solve : What are these files??

Answer»

I was doing some general cleanup on my computer and happened to come across some unusual files. I'm HOPING someone here can maybe help me find out what they are and if I should DELETE them. I'm on WinXP, by the way. The files are:

ÝÃÄ›Ò3113›.sys
(located in C:\Documents and Settings\All Users\Application Data)

PFP120JCM.{PB
PFP120JPR.{PB
(both located in C:\Documents and Settings\[my name]\Application Data)

Any help at all would be appreciated. Thanks!I'm having trouble find any actual info on the .{PB files. Most people who have them are infected, but it doesn't mean that they are malicious. Could just a coincidence. All I know is that I don't have any such files. In fact, although I have plenty of folders in Application Data, I don't have any stray files. The first file...well, I can find nothing at all about it.

Unless anyone can give some insight, I would suggest uploading/scanning them (individually) at VirusTotal. Post back with the results.I know of only ONE other instance of that first file coming up and no idea about the other two.

I don't like the look of any.

CBMatt ... I suggest you get the OP to d/l AVG AS, unhide HIDDEN Files & Folders, run a scan in safe mode then post a HJT v1.99 log from normal mode.


OJYou could also make a temporary directory and MOVE, not copy the files there for the time being.
If they are needed by any programs you are running the error message will tell you which program uses/needs these files.
After a few weeks or so if it is running fine with no hiccups i would say they are safe to delete...The only page I could find about that first file was this:
http://forums.spybot.info/showthread.php?t=11301&page=2

Even then, no one who replied to that user seems to have noticed it or thought it unusual. It seems very strange to me though, especially with a filename like that. It was marked as hidden, too--it wasn't until I turned on "show hidden files and folders" that I came across it.DLoad all the updates for your current protection apps and re-boot into safemode and run all your scans just to be safe...Have you tried uploading them to VirusTotal? And go ahead and follow along with the suggestions of oddjob and patio. Download AVG Anti-Spyware and update it to the latest definitions. Reboot in Safe Mode and unhide all of your hidden folders (click here if you don't know how). Then go ahead and run a complete system-wide scan. It's time-consuming, but it's worth the effort.I know that this is a really really old thread;

but since no one actually answered it with any info on the files
and I was directed here from a Google search for the files

I thought I would answer, just in case anyone else ever was looking for info on these files
as I was in the past 24 hours:

the two files:
- PFP120JCM.{PB
- PFP120JPR.{PB

Located in
- C:\Documents and Settings\User Name\Application Data\

are files wholly related to WordPerfect12 and nothing else*

it's easy to test it:

a> open windows exploder and navigate to the profile that is currently logged on,
- ie. Administrator
- C:\Documents and Settings\Administrator\Application Data
b> delete the two files
c> open Word Perfect
d> switch back to Windows Exploder
e> the two files will be there again with the current date & time

* if the system has never had Word Perfect 12 installed then there may be a problem with the file names being hi-jacked by malware

3819.

Solve : Sysvxd.exe?

Answer»

I had the Sysvxd.exe virus. I followed all the steps and have the 3 logs attached below. Those programs may have DELETED it, but I just want to make sure that EVERYTHING is gone so I won't have this problem again. Thank you so much for your help.

I do still have the "common" window that opens at startup.

[attachment deleted by admin]Looks LIKE everything was removed. Just a few things left to do.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O18 - Filter hijack: text/html - {f5b9c876-c1dc-47cb-8f1d-f03f74cef11e} - C:\WINDOWS\system32\mst122.dll

Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
  • Viewpoint Experience Technology
.
----------

Disable/Enable the System Restore Utility to flush old infected restore points

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to TURN off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Awesome. Thanks so much. I know where I'll be coming back to if I have any more computer problems. Your welcome.

Safe SURFING...Deleting again....


3820.

Solve : anti virus/anti spyware programs?

Answer»

My computer seems to have slowed down considerably in the past few weeks. The question I have is in regards to ANTI Virus/Anti Spyware programs.

I am currently using AVG 8.5 for my ANTIVIRUS, and for the spyware programs I am using Spyware Blaster/Super ANTISPYWARE/Spybot Search & Destroy/Malwarebytes Antimalware.

My question is this...........are the free programs sufficient, or are the programs available for purchase able to do a better job of detection?

My OS is Windows XP Home.

If anybody has any feedback, I would appreciate it, or if there are any tips on speeding up my computer that would be great too!

Thanks,

Jim The free programs are sufficient..... Only run one antivirus program, one firewall, and use a couple of good antispyware programs and alternate their usage as no program will catch all threats.

Couple of good articles.....

http://evilfantasy.wordpress.com/2008/05/24/slow-computer-it-may-not-be-malware/

http://www.malwareremoval.com/tutorials/runningslowly.phpOne AV in conjunction with Spyware Blaster, MalwareBytes & Super AntiSpyware should be fine (though AVG may not be the best AV). More important, however, is "smart computing" (know where you go on the internet, what emails to open and not, etc).Thanks ADG,

What would you recommend for a AV?As a free program I GUESS Avast or Avira are pretty good. I use Kaspersky on all my systems (not cheap, but I trust it / them IMPLICITLY)

3821.

Solve : Cannot go online in safe mode.?

Answer»

Quote

like, literally, 7 years ago and not since then. Should I uninstall avast since I cannot find a place to uninstal MCAFEE?
Download this removal tool. It should get rid of all TRACES of McAfee.
Quote
how can I make sure of that?
You can check the Winsock file by USING this SYSTEM File Checker. You will probably need your OS Disc.somehow removing mcafee fixed it. thanks!
3822.

Solve : What are these programs for??

Answer»

I opened regedit and went to HKEY_LOCAL_MACHINE. Then went to SOFTWARE. Then I found these programs: C07ft5Y, Codec tweak tool, divxnetworks, gemplus, S3R521, Schlumberger, x-avcsd. Can anyone explain what are these programs for? Thank you very much.Codec tweak tool --> do you have klite codec pack or something?

Divxnetwork --> do you have divx codec or divx codec bundle or some other codec pack that installs for your the divx codec?

x-avscd --> this should have came as part of the avira antivirus software installation.

C07ft5Y--> seems to be coming from a copy protection software or something ... not too sure

gemplus --> does this registry entry contain the subkeys: Cryptography, SmartCards and GemSAFE which are stuff related to smart cards? It´s a part of the standard installation of XP

Sclumberger --> Should be for smart cards, even if you don't use one ... but it is installed by default in Windows XP. See this link]http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_sc_use_sctypes.mspx]link for more help on that.

S3R521--> this I don't know but it seems ok.

You probably want to run Hijack this software and have a malware specialist of this forum to check that your computer is clean. Would be good to know if whether your computer is sick or not.







I know something that has info on all those. GOOGLE. Spending 5 minutes can save you hours waiting on a forum. C07ft5Y is made by SecuROM.Quote from: BC_Programmer on August 25, 2009, 10:41:54 PM

C07ft5Y is made by SecuROM.

oh SecuROM. Thank you. Hi, 2x3i5x, helpmeh, BC_programmer: thank you very much for your really helpful answers. I am sorry for wasting your time. Next time i should search on google first before asking.
To 2x3i5x : oh, i see. Yes, i think i've just found the programs you mentioned. I'm gonna to follow your ADVICES for sure. Thank you.Hi, again. i've just searched c07ft5y on google several minutes ago. And i only found one link for the keyword: c07ft5y. The link was home.no/nootrreok/c07ft5y.html. I followed the link and came accross this message: warning!!! Your computer contains various SIGNS of viruses and malware programs presence. Your system requires immediate anti viruses check! System security will perform a quick and free scanning of your PC for viruses and malicious programs. My question: is this c07ft5y safe enough to dwell in my registry? Or should i delete it? I know little about computer and I'm just a bit paranoia with this c07ft5y (sorry). Thank you very much. only one hit? I got several thousand:

http://www.google.ca/#hl=en&source=hp&q=C07ft5Y&btnG=Google+Search&meta=&aq=f&oq=C07ft5Y&fp=a1047c2a76fad57b

Quote from: BC_Programmer on August 26, 2009, 05:41:15 AM
only one hit? I got several thousand:

http://www.google.ca/#hl=en&source=hp&q=C07ft5Y&btnG=Google+Search&meta=&aq=f&oq=C07ft5Y&fp=a1047c2a76fad57b


yeah, it seems you pinpointed further than me. I'll try it once again myself. Thank you.but... regarding the key;

I was actually curious about that key myself, some time ago. it's been present on my XP desktop, as well as Vista laptop and new desktop build running vista.

In my case I have several keys underneath it reflecting the games I have installed that use that copy-protection technology, Age of empires 2, quake 4, Halo... etc.

while the name they chose CERTAINLY raises an eyebrow, looking past the name, it's really just a few morsels of irrelevant data- nothing to be concerned about. Again- I was quite curious about the key myself, and in fact ran Registry Monitor to find out what was accessing the key, to discover it was accessed when I played some of my games. After much investigation about the games that did and did not TRIGGER the discovery I discovered each game that did access the mystery key had the "secuROM" copy protection.

Of course if I had simply done a google search I would have discovered that quite quickly, but I guess I like the thrill of the chase

Quote from: BC_Programmer on August 26, 2009, 07:38:26 AM
but... regarding the key;

I was actually curious about that key myself, some time ago. it's been present on my XP desktop, as well as Vista laptop and new desktop build running vista.

In my case I have several keys underneath it reflecting the games I have installed that use that copy-protection technology, Age of empires 2, quake 4, Halo... etc.

while the name they chose certainly raises an eyebrow, looking past the name, it's really just a few morsels of irrelevant data- nothing to be concerned about. Again- I was quite curious about the key myself, and in fact ran Registry Monitor to find out what was accessing the key, to discover it was accessed when I played some of my games. After much investigation about the games that did and did not trigger the discovery I discovered each game that did access the mystery key had the "secuROM" copy protection.

Of course if I had simply done a google search I would have discovered that quite quickly, but I guess I like the thrill of the chase


oh, i see. Thank you for explain this to me. So i no longer need to worry about this 'lovely key' hehe. Thank you very much. I think I was asking a silly question. Shame on me.
3823.

Solve : Rootkit-pakes.M?

Answer»

Hi,

This is my first post and am desperate for advice regarding the removal of the Rootkit-pakes.M.

OK first things first, the history.

I've just started the standalone again having not used it for months. Got it all cleaned up and had it running nice n fast. On 16 Aug I went to the site FMportals.com and AVG 8.5 flashed up with a warning that the site was dangerous. Before I could do anything it appeared that I had been attacked/downloaded the trojan unwittingly.

I actually figured it had been a false alarm until starting the PC on 17 Aug, when AVG Resident shield flagged up the rootkit sitting at the following filepath:

C://WINDOWS//system32/drivers/ntfs.sys

This was also accompanied by a couple of other related FILES, opening a back door. AVG was able to get rid of these files but not the rootkit. (cont)I then tried ccleaner before stumbling upon your wesbite.

I have now followed your step by step guide and will attach the logs.

What concerns me though is that none of the logs makes mention of the rootkit-pakes.M trojan BUT have found several others including win98.exe and a couple more.

All your help and advice will be most greatfuly received!

Here come the logs...SAS Log

[attachment deleted by admin]MBam Log and Sniper Log

[attachment deleted by admin]Also, just how dangerous is this rootkit and what are the consequences of leaving it in place?Leem, your HJT log looks quite clean. The two scans you ran before cleaned up some infections. Here is some information about rootkits and there are also some tools you can use to scan your machine. I also noticed that you have no Firewall running on your computer. You should activate the Windows Firewall or BETTER yet, download one of these free third-party firewalls which are superior to the Windows Firewall found here. Personally, I prefer ZoneAlarm. You should keep SAS and MBAM on your computer and run them weekly but you should also add programs such as Spybot S&D, Ad-Aware, and SpywareBlaster to protect against malware and spyware. They're all free. Wait a few days to see if the resident specialists have any other things for you to do. If not, try these tips. Oops, almost forgot. You should download and install Service Pack 3 which will give you additional protection.Hi Superdave,

Many thanks for all of you advice. I had previously been told that running Windows firewall alone was sufficient and had gotten rid of my Zonealarm. I have no idea how the windows firewall got turned off though...

Anyway. I did as you said and added Commodo, which so far seems a little less INTRUSIVE then Zonealarm, so I'm happy there on all counts.

I am keeping the SAS and MBAM to complement AVG 8.5, as well as running CCleaner. The big difference that cleaned the virus though was the Windows SP. It seems that when it installed it uninstalled the infected old drivers (which have now been CCleaned!)

So again, many, many thanks :-D

I currently run AVG. I also now have sas and MBAM. Do the spybot/adaware/spywareblaster programme slow the machine down much? Why so many programmes that seemingly serev the same function? Or do they all do something alightly different?Quote

I currently run AVG. I also now have sas and MBAM. Do the spybot/adaware/spywareblaster programme slow the machine down much? Why so many programmes that seemingly serev the same function? Or do they all do something alightly different?
I'm currently running SpywareBlaster, Spybot S&D and Threatfire as well as Avast AV and there is no SLOWNESS in my computer. Evil once told me that a layered approach was the best way to protect against Viruses and infections. When it comes to AV, 2 is not often better than one. If you find 2 free ones that truly are compatible with each other, tell me!Right. Only one AV at a time but for spyware & malware you can run as many as you want. Plus a good firewall that blocks outgoing as well as incoming.I had the same problem
Tried Spybot and Malwarebytes. Neither could clean it up.
Tried going back to a restore point (Start -> Accessories -> System Tools -> System Restore). Did not work for me.

Finally went to microsoft for help. They SUGGESTED I run the scanner at onecare.live.com. Seems to have worked so far....


3824.

Solve : Screensavers are trying to take over my pc.?

Answer»

My boyfriend wanted a stupid fireplace screensaver because we have our pc conntected to our tv. Well he downloaded something CALLED 'Relevant Knowledge' that was attached to one of the downloads and I did some research and found out its malware.

I have an eMachine T3418 and service pack 2.
I use Panda Cloud Antivirus but I just installed it after this problem.
I've had this pc for years and never had a problem but believe me I will always have some sort of protection now.

Some helpful things may be :

I tried going to add/remove programs and uninstalling the program obviously to no avail and everytime I turn on my computer I have a error dialog box that says

c:\program files\relevantknowledge\rlls.dll uninstal.exe

it won't go away no matter how many times I press OK.

I tried moving the screensaver files he downloaded into the recycle bin and the empty recycle bin link disappears and when I manually right click to delete it says delete "WINDOWS" and then says it's invalid.

lastly, everytime I follow every step to download CCleaner, SAS, MBAM, I click run once installed and I get the hourglass for a second then nothing happens for each. I can't uninstall and reinstall because it errors and says in use. When I use hijack this everything is successful until I open TRY and open the log and it just does the same thing... nothing. User error? Help please!

Thanks in advance.


Try run the antimalware programs in safe mode.....you might have to rename them.

That's nasty malware and evilfantasy may have to open the magic toolbox to straighten things out.SAS still would not work saying because I was in safe mode and my installer couldn't be found or something but...

HJT did and so did MBAM ; Results are here.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:52 AM, on 8/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\relevantknowledge\rlvknlg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp147.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Program Files\SeekappSrch\seekappsrch.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\PROGRA~1\Freeze.com\Living Beaches Full\UNINSTAL.EXE
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Documents and Settings\Cassaundra\Desktop\SUPERAntiSpyware.exe
C:\Documents and Settings\Cassaundra\Desktop\SUPERAntiSpyware.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Freeze.com\TROPIC~1\UNINSTAL.EXE
C:\Documents and Settings\Cassaundra\Desktop\SUPERAntiSpyware(2).exe
C:\Documents and Settings\Cassaundra\Desktop\mbam-setup.exe
C:\Documents and Settings\Cassaundra\Desktop\mbam-setup.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: RelevantKnowledge - c:\program files\relevantknowledge\rlls.dll
O23 - Service: NanoServiceMain - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SeekappSrch Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp147.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 4684 bytes


_______________________________________ __________


Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 2 (Safe Mode)

8/22/2009 11:55:57 AM
mbam-log-2009-08-22 (11-55-45).txt

Scan type: Quick Scan
Objects scanned: 86000
Time elapsed: 6 minute(s), 41 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry KEYS Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 3
Files Infected: 13

Memory Processes Infected:
c:\program files\relevantknowledge\rlvknlg.exe (Spyware.Marketscore) -> No action taken.

Memory Modules Infected:
c:\program files\relevantknowledge\rlls.dll (Spyware.Marketscore) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\relevantknowledge (Spyware.Marketscore) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\components (Spyware.Marketscore) -> No action taken.

Files Infected:
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.Marketscore) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.Marketscore) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\Support.lnk (Spyware.Marketscore) -> No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\chrome.manifest (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\install.rdf (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rloci.bin (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rlph.dll (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\rlxf.dll (Spyware.Marketscore) -> No action taken.
C:\Program Files\RelevantKnowledge\components\rlxg.dll (Spyware.Marketscore) -> No action taken.
after going into safe mode I figured it out myself.
now I feel slow for making a big deal about it when it really was as easy as deleting a few files.

thanks for your help otherwise though =)

computer it back in action.Just to be on the safe side you might want to go ahead and let one of the specialist have a look over things to make sure it is completely gone.yeah feel free, I feel skeptical myself but the pop ups are gone + error messages.
but if you guys think of anything else lmk and i'll try it out.You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
  • Viewpoint Experience Technology
.
----------

Download, update and run a-squared Free edition

At the main menu, click Scan Now, there will be 4 options, choose Deep Scan and then click Scan

* If malware is found, click the button Remove Selected Malware
* If malware is found, select all found and click Quarantine selected objects
* Click Save Report. Save the report to somewhere convenient, such as your desktop
* Add the report as an attachment in your next post.

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.Here are the logs from each as requested.

a-squared Free - Version 4.5
Last update: 8/22/2009 4:33:11 PM

Scan settings:

Scan type: Deep Scan
Objects: Memory, Traces, Cookies, C:\, H:\
Scan archives: On
Heuristics: Off
ADS Scan: On

Scan start:8/22/2009 4:33:38 PM

c:\program files\bittorrent detected: Trace.Directory.Bittorrent 5.0!A2
c:\documents and settings\all users\start menu\programs\bittorrent detected: Trace.Directory.Bittorrent 5.0!A2
c:\program files\bittorrent\bittorrent.exe detected: Trace.File.Bittorrent 5.0!A2
c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnk detected: Trace.File.Bittorrent 5.0!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638815625005 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265000 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265003 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638822921000 detected: Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638869593001 detected: Trace.TrackingCookie.aol.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249490816828004 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249495168656001 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305500000 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305625000 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718000 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718005 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530306593000 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687000 detected: Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687001 detected: Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530390140000 detected: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249563719765000 detected: Trace.TrackingCookie.www.buy!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750000 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750001 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750002 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356828006 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572358843000 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359015005 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562003 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562006 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572412890000 detected: Trace.TrackingCookie.ads.bridgetrack.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249577188921001 detected: Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249691875265000 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249854774312006 detected: Trace.TrackingCookie.tag.contextweb.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858553140010 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858699531002 detected: Trace.TrackingCookie.www.burstnet.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858720656000 detected: Trace.TrackingCookie.www.burstbeacon.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249861032687003 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249863405953000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891109006 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187004 detected: Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187005 detected: Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091281000 detected: Trace.TrackingCookie.sales.liveperson.n et!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091328000 detected: Trace.TrackingCookie.sales.liveperson.n et!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187000 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187001 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187002 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187003 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187004 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249918138984000 detected: Trace.TrackingCookie.cms!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036490437000 detected: Trace.TrackingCookie.www.googleadservic es.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265000 detected: Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265001 detected: Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038191609000 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193281003 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193296003 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656001 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656002 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812000 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812002 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812003 detected: Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093000 detected: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093001 detected: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043656718000 detected: Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044174796004 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859000 detected: Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859001 detected: Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859002 detected: Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578000 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578001 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044401125000 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250050142031000 detected: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051116765004 detected: Trace.TrackingCookie.media!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937000 detected: Trace.TrackingCookie.stat.onestat!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937001 detected: Trace.TrackingCookie.stat.onestat!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966718000 detected: Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966890000 detected: Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250536247968000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475593000 detected: Trace.TrackingCookie.webtrends!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475750000 detected: Trace.TrackingCookie.webtrends!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111375000 detected: Trace.TrackingCookie.cookie.monster.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111578000 detected: Trace.TrackingCookie.ads.monster.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539939859001 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794469125004 detected: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794472687002 detected: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794696281000 detected: Trace.TrackingCookie.statse.webtrendsli ve!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250795144796000 detected: Trace.TrackingCookie.ad1.clickhype.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250802085875001 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250806725546000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250863260875002 detected: Trace.TrackingCookie.click.cashengines. com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001 detected: Trace.TrackingCookie.am1.activemeter.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250868467203000 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734002 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734004 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914156890000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000 detected: Trace.TrackingCookie.m.webtrends.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000 detected: Trace.TrackingCookie.www.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250972724359003 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekapp.dll detected: Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekappsrch.exe detected: Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekapp.dll detected: Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekappsrch.exe detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001402.dll detected: Gen.Trojan!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001404.dll detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005109.dll detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005110.dll detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005113.dll detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005115.exe detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005148.dll detected: Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005149.exe detected: Adware.PremiumO!IK
C:\WINDOWS\Temp\SEE165.tmp\upgrade.exe/seekapp.dll detected: Gen.AdWare!IK
C:\WINDOWS\Temp\SEE51.tmp\upgrade.exe/seekapp.dll detected: Gen.AdWare!IK

Scanned

Files: 74292
Traces: 628846
Cookies: 1441
Processes: 25

Found

Files: 14
Traces: 4
Cookies: 102
Processes: 0
Registry keys: 0

Scan end:8/22/2009 5:15:03 PM
Scan time:0:41:25

C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005149.exeQuarantined Adware.PremiumO!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001402.dllQuarantined Gen.Trojan!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekapp.dllQuarantined Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekappsrch.exeQuarantined Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekapp.dllQuarantined Gen.AdWare!IK
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekappsrch.exeQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001404.dllQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005109.dllQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005110.dllQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005113.dllQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005115.exeQuarantined Gen.AdWare!IK
C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005148.dllQuarantined Gen.AdWare!IK
C:\WINDOWS\Temp\SEE165.tmp\upgrade.exe/seekapp.dllQuarantined Gen.AdWare!IK
C:\WINDOWS\Temp\SEE51.tmp\upgrade.exe/seekapp.dllQuarantined Gen.AdWare!IK
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000Quarantined Trace.TrackingCookie.www.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000Quarantined Trace.TrackingCookie.m.webtrends.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001Quarantined Trace.TrackingCookie.am1.activemeter.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250863260875002Quarantined Trace.TrackingCookie.click.cashengines. com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250795144796000Quarantined Trace.TrackingCookie.ad1.clickhype.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794696281000Quarantined Trace.TrackingCookie.statse.webtrendsli ve!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111578000Quarantined Trace.TrackingCookie.ads.monster.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111375000Quarantined Trace.TrackingCookie.cookie.monster.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475593000Quarantined Trace.TrackingCookie.webtrends!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475750000Quarantined Trace.TrackingCookie.webtrends!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966718000Quarantined Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966890000Quarantined Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937000Quarantined Trace.TrackingCookie.stat.onestat!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937001Quarantined Trace.TrackingCookie.stat.onestat!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051116765004Quarantined Trace.TrackingCookie.media!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578000Quarantined Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578001Quarantined Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044401125000Quarantined Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250868467203000Quarantined Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093000Quarantined Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093001Quarantined Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250050142031000Quarantined Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794469125004Quarantined Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794472687002Quarantined Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038191609000Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193281003Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193296003Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656001Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656002Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812000Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812002Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812003Quarantined Trace.TrackingCookie.about.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036490437000Quarantined Trace.TrackingCookie.www.googleadservic es.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249918138984000Quarantined Trace.TrackingCookie.cms!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091281000Quarantined Trace.TrackingCookie.sales.liveperson.n et!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091328000Quarantined Trace.TrackingCookie.sales.liveperson.n et!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187004Quarantined Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187005Quarantined Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859000Quarantined Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859001Quarantined Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859002Quarantined Trace.TrackingCookie.trafficmp.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858720656000Quarantined Trace.TrackingCookie.www.burstbeacon.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858699531002Quarantined Trace.TrackingCookie.www.burstnet.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249854774312006Quarantined Trace.TrackingCookie.tag.contextweb.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249577188921001Quarantined Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043656718000Quarantined Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572412890000Quarantined Trace.TrackingCookie.ads.bridgetrack.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572358843000Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187000Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187001Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187002Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187003Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187004Quarantined Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750000Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750001Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750002Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356828006Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359015005Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562003Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562006Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891109006Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044174796004Quarantined Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249563719765000Quarantined Trace.TrackingCookie.www.buy!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687000Quarantined Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687001Quarantined Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265000Quarantined Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265001Quarantined Trace.TrackingCookie.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305500000Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305625000Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718000Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718005Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530306593000Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530390140000Quarantined Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249495168656001Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249861032687003Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249863405953000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250536247968000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250806725546000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734002Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734004Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914156890000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250972724359003Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638869593001Quarantined Trace.TrackingCookie.aol.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638822921000Quarantined Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638815625005Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265000Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265003Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249490816828004Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249691875265000Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858553140010Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539939859001Quarantined Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250802085875001Quarantined Trace.TrackingCookie.myspace.com!A2
c:\program files\bittorrent\bittorrent.exeQuarantined Trace.File.Bittorrent 5.0!A2
c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnkQuarantined Trace.File.Bittorrent 5.0!A2
c:\program files\bittorrentQuarantined Trace.Directory.Bittorrent 5.0!A2
c:\documents and settings\all users\start menu\programs\bittorrentQuarantined Trace.Directory.Bittorrent 5.0!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000Quarantined Trace.TrackingCookie.www.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000Quarantined Trace.TrackingCookie.m.webtrends.com!A2
C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001Quarantined Trace.TrackingCookie.am1.activemeter.co m!A2

Quarantined

Files: 14
Traces: 4
Cookies: 95

_______________________________________ _________


DDS (Ver_09-07-30.01) - NTFSx86
Run by Cassaundra at 17:20:16.85 on Sat 08/22/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.64 [GMT -4:00]

AV: Panda Cloud Antivirus *On-access scanning enabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp147.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Program Files\SeekappSrch\seekappsrch.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\a-squared Free\a2free.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Cassaundra\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [PSUNMain] "c:\program files\panda security\panda cloud antivirus\PSUNMain.exe" /Traybar
StartupFolder: c:\docume~1\cassau~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\cassau~1\applic~1\mozilla\firefox\profiles\23gmjj1q.default\
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default _setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2009-6-23 114056]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-8-22 1864824]
R2 NanoServiceMain;NanoServiceMain;c:\program files\panda security\panda cloud antivirus\PSANHost.exe [2009-4-23 95488]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2009-6-23 136072]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2009-6-4 92552]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2009-6-4 98184]
R2 SeekappSrch Service;SeekappSrch Service;c:\documents and settings\all users\application data\seekappsrch\seekapp147.exe [2009-8-14 54760]
S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2009-7-26 26488]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]

=============== Created Last 30 ================

2009-08-22 16:44--d-----c:\docume~1\cassau~1\applic~1\BitTorrent
2009-08-22 16:25--d-----c:\program files\a-squared Free
2009-08-22 16:15142a-------c:\windows\system32\spupdsvc.inf
2009-08-22 14:19333,952-c------c:\windows\system32\dllcache\srv.sys
2009-08-22 14:18455,296-c------c:\windows\system32\dllcache\mrxsmb.sys
2009-08-22 14:181,106,944a-------c:\windows\system32\SETA9.tmp
2009-08-22 14:181,106,944-c------c:\windows\system32\dllcache\msxml3.dll
2009-08-22 14:18337,408a-------c:\windows\system32\SETA5.tmp
2009-08-22 14:18337,408-c------c:\windows\system32\dllcache\netapi32.dll
2009-08-22 14:18331,776-c------c:\windows\system32\dllcache\msadce.dll
2009-08-22 14:17691,712-c------c:\windows\system32\dllcache\inetcomm.dll
2009-08-22 14:16272,128-c------c:\windows\system32\dllcache\bthport.sys
2009-08-22 14:16203,136-c------c:\windows\system32\dllcache\rmcast.sys
2009-08-22 13:14--d-----c:\windows\system32\scripting
2009-08-22 13:14--d-----c:\windows\l2schemas
2009-08-22 13:14--d-----c:\windows\system32\en
2009-08-22 13:14--d-----c:\windows\system32\bits
2009-08-22 13:12--d-----c:\windows\ServicePackFiles
2009-08-22 13:11--d-----c:\windows\network diagnostic
2009-08-22 13:02129,045--------c:\windows\system32\drivers\cxthsfs2.cty
2009-08-22 12:49--d-----c:\windows\system32\PreInstall
2009-08-22 12:49--d-h---c:\windows\$hf_mig$
2009-08-22 12:47--ds----c:\documents and settings\cassaundra\UserData
2009-08-22 11:47--d-----c:\docume~1\cassau~1\applic~1\Malwarebytes
2009-08-22 11:47--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-22 10:28--d-----c:\program files\Trend Micro
2009-08-22 10:08--d-----c:\program files\common files\Wise Installation Wizard
2009-08-22 00:05--d-----c:\windows\system32\appmgmt
2009-08-21 10:09--d-----c:\docume~1\cassau~1\applic~1\Panda Security
2009-08-21 10:06245a-------c:\windows\system32\PSUNCpl.dat
2009-08-21 10:06--d-----c:\program files\Panda Security
2009-08-21 10:06--d-----c:\docume~1\alluse~1\applic~1\Panda Security
2009-08-21 10:05--d-----c:\program files\BitTorrent
2009-08-14 19:11--d-----c:\program files\DivX
2009-08-14 19:11--d-----c:\program files\common files\DivX Shared
2009-08-10 11:11--d-----c:\program files\SeekappSrch
2009-08-10 11:11--d-----c:\docume~1\alluse~1\applic~1\SeekappSrch
2009-08-10 10:593,255a-------c:\windows\system32\wbem\Outlook_01ca19cb36d589a0.mof
2009-08-09 20:32--d-----c:\program files\IrfanView
2009-08-06 12:21139,776a-------c:\windows\system32\CNMLM75.DLL
2009-08-06 12:218,704a-------c:\windows\system32\CNMVS75.DLL
2009-08-06 12:2190,112a-------c:\windows\system32\CNMCP75.exe
2009-08-06 12:0625,856a-------c:\windows\system32\drivers\usbprint.sys
2009-07-26 16:27--d-----c:\program files\Windows Media Connect 2
2009-07-26 16:26--d-----c:\windows\system32\LogFiles
2009-07-26 16:2626,488a-------c:\windows\system32\spupdsvc.exe
2009-07-26 16:2132,592a-------c:\windows\system32\msonpmon.dll
2009-07-26 16:17--d-----c:\program files\Microsoft Visual Studio 8
2009-07-26 16:16--d-----c:\windows\SHELLNEW
2009-07-26 16:09--d-----c:\windows\pss
2009-07-26 16:08--d-----c:\docume~1\alluse~1\applic~1\Viewpoint
2009-07-26 16:08--d-----c:\program files\common files\AOL
2009-07-26 16:08382a---h---C:\IPH.PH
2009-07-26 16:03--d-----c:\program files\CONEXANT
2009-07-26 16:00--d-----c:\program files\Realtek Sound Manager
2009-07-26 16:00--d-----c:\program files\AvRack
2009-07-26 16:00--d-----c:\program files\Realtek AC97
2009-07-26 15:5630,277a-------c:\windows\system32\nvapps.xml
2009-07-26 15:56180,224a-------c:\windows\system32\nvudisp.exe
2009-07-26 15:5615,078a-------c:\windows\system32\nvdisp.nvu
2009-07-26 15:56--d-----c:\windows\nview
2009-07-26 15:53--d-----c:\windows\system32\SoftwareDistribution
2009-07-26 15:51176,128a-------c:\windows\system32\nvuide.exe
2009-07-26 15:511,537a-------c:\windows\system32\nvide.nvu
2009-07-26 15:51176,128a-------c:\windows\system32\nvunrm.exe
2009-07-26 15:51100,480a-------c:\windows\system32\drivers\nvtcp.sys
2009-07-26 15:513,632a-------c:\windows\system32\nvnrm.nvu
2009-07-26 15:51176,128a-------c:\windows\system32\nvusmb.exe
2009-07-26 15:511,391a-------c:\windows\system32\nvsmb.nvu
2009-07-26 15:50--d-----c:\windows\system32\ReinstallBackups
2009-07-26 15:50176,128a-------c:\windows\system32\NVUNINST.EXE

==================== Find3M ====================

2009-08-22 13:1686,327a-------c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-15 21:4621,640a-------c:\windows\system32\emptyregdb.dat

============= FINISH: 17:20:45.40 ===============




_______________________________________ ____________


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 6/15/2009 9:51:20 PM
System Uptime: 8/22/2009 1:50:23 PM (4 hours ago)

Motherboard: First International Computer, Inc. | | K8MC51G
Processor: AMD Sempron(tm) Processor 3400+ | Socket 754 | 2009/201mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 145 GiB total, 136.741 GiB free.
D: is Removable
E: is Removable
F: is Removable
G: is Removable
H: is FIXED (FAT32) - 4 GiB total, 2.306 GiB free.
I: is CDROM (UDF)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 6/15/2009 9:55:21 PM - System Checkpoint
RP2: 6/15/2009 10:44:36 PM - Installed Adobe Reader 7.0
RP3: 6/17/2009 3:16:25 PM - System Checkpoint
RP4: 6/17/2009 3:22:25 PM - Installed Windows Installer KB893803v2.
RP5: 7/26/2009 4:00:02 PM - Installed Realtek AC'97 Audio
RP6: 7/26/2009 4:16:01 PM - Installed Microsoft Office Enterprise 2007
RP7: 7/26/2009 4:21:44 PM - Printer Driver Send To Microsoft OneNote Driver Installed
RP8: 7/26/2009 4:25:23 PM - Installed Windows Media Player 11
RP9: 7/26/2009 4:25:52 PM - Software Distribution Service 3.0
RP10: 8/5/2009 1:57:04 PM - System Checkpoint
RP11: 8/6/2009 12:21:51 PM - Printer Driver Canon iP1600 Installed
RP12: 8/7/2009 12:39:20 PM - System Checkpoint
RP13: 8/9/2009 6:30:33 PM - System Checkpoint
RP14: 8/9/2009 8:31:43 PM - Printer Driver Canon iP1600 Installed
RP15: 8/10/2009 11:03:05 AM - Installed walkway2paradisess
RP16: 8/11/2009 11:54:42 AM - System Checkpoint
RP17: 8/12/2009 12:54:46 PM - System Checkpoint
RP18: 8/13/2009 1:54:44 PM - System Checkpoint
RP19: 8/14/2009 4:19:26 PM - System Checkpoint
RP20: 8/15/2009 4:46:26 PM - System Checkpoint
RP21: 8/17/2009 4:41:59 PM - System Checkpoint
RP22: 8/20/2009 11:04:57 PM - System Checkpoint
RP23: 8/22/2009 12:05:31 AM - Removed walkway2paradisess
RP24: 8/22/2009 12:49:31 PM - Software Distribution Service 3.0
RP25: 8/22/2009 1:05:35 PM - Software Distribution Service 3.0
RP26: 8/22/2009 2:29:11 PM - Software Distribution Service 3.0

==== Installed Programs ======================

a-squared Free 4.5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
BitTorrent
Canon iP1600
DivX Web Player
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
IrfanView (remove only)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Mozilla Firefox (3.5.2)
MSXML 4.0
NVIDIA Drivers
Panda Cloud Antivirus
Realtek AC'97 Audio
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960225)
Seekapp 1.0 build 147
Soft Data Fax Modem with SmartCP
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC80CRTRedist - 8.0.50727.762
Visual C++ 8.0 CRT (x86) WinSXS MSM
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3

==== Event Viewer Messages From Past Week ========

8/22/2009 11:57:06 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
8/22/2009 11:47:03 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
8/22/2009 11:46:50 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips IPSec MRxSmb NetBIOS NetBT Processor PSINKNC RasAcd Rdbss Tcpip
8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
8/22/2009 11:46:50 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/22/2009 11:46:49 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/22/2009 11:46:48 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
8/17/2009 2:25:02 PM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 0040CA9200A0 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================


Thanks again! Let me know if you foud anything else..Go to Add or Remove Programs and uninstall:

Seekapp 1.0 build 147

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
SeekappSrch Service

DDS::
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

Firefox::
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

Folder::
c:\docume~1\alluse~1\applic~1\Viewpoint
C:\Documents and Settings\All Users\Application Data\SeekappSrch
C:\Program Files\SeekappSrch
c:\program files\messenger
c:\program files\viewpoint

File::
c:\windows\system32\SETA9.tmp
c:\windows\system32\SETA5.tmp

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze
ComboFix 09-08-22.06 - Cassaundra 08/22/2009 17:50.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.212 [GMT -4:00]
Running from: c:\documents and settings\Cassaundra\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cassaundra\Desktop\CFScript.txt
AV: Panda Cloud Antivirus *On-access scanning disabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393}

FILE ::
"c:\windows\system32\SETA5.tmp"
"c:\windows\system32\SETA9.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\alluse~1\applic~1\Viewpoint
c:\program files\messenger
c:\program files\messenger\custsat.dll
c:\program files\messenger\logowin.gif
c:\program files\messenger\lvback.gif
c:\program files\messenger\msgsc.dll
c:\program files\messenger\msgslang.dll
c:\program files\messenger\msmsgs.exe
c:\program files\messenger\newalert.wav
c:\program files\messenger\newemail.wav
c:\program files\messenger\online.wav
c:\program files\messenger\type.wav
c:\program files\messenger\xpmsgr.chm
c:\program files\SeekappSrch
c:\program files\SeekappSrch\SeekappSrch_deleted_\seekapp.dll
c:\program files\SeekappSrch\SeekappSrch_deleted_\seekappsrch.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\SETA5.tmp
c:\windows\system32\SETA9.tmp
H:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 )))))))))))))))))))))))))))))))
.

2009-08-22 20:25 . 2009-08-22 21:36--------d-----w-c:\program files\a-squared Free
2009-08-22 18:19 . 2008-12-11 10:57333952-c----w-c:\windows\system32\dllcache\srv.sys
2009-08-22 18:18 . 2008-10-24 11:21455296-c----w-c:\windows\system32\dllcache\mrxsmb.sys
2009-08-22 18:18 . 2008-09-04 17:151106944-c----w-c:\windows\system32\dllcache\msxml3.dll
2009-08-22 18:18 . 2008-10-15 16:34337408-c----w-c:\windows\system32\dllcache\netapi32.dll
2009-08-22 18:18 . 2008-05-01 14:33331776-c----w-c:\windows\system32\dllcache\msadce.dll
2009-08-22 18:17 . 2008-04-11 19:04691712-c----w-c:\windows\system32\dllcache\inetcomm.dll
2009-08-22 18:16 . 2008-06-13 11:05272128-c----w-c:\windows\system32\dllcache\bthport.sys
2009-08-22 18:16 . 2008-05-08 14:02203136-c----w-c:\windows\system32\dllcache\rmcast.sys
2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\scripting
2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\l2schemas
2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\en
2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\bits
2009-08-22 17:12 . 2009-08-22 17:12--------d-----w-c:\windows\ServicePackFiles
2009-08-22 17:01 . 2004-08-04 02:2973216------w-c:\windows\system32\drivers\atintuxx.sys
2009-08-22 16:49 . 2009-08-22 18:31--------d--h--w-c:\windows\$hf_mig$
2009-08-22 16:47 . 2009-08-22 16:47--------d-s---w-c:\documents and settings\Cassaundra\UserData
2009-08-22 15:47 . 2009-08-22 15:47--------d-----w-c:\documents and settings\Cassaundra\Application Data\Malwarebytes
2009-08-22 15:47 . 2009-08-22 15:47--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 14:28 . 2009-08-22 14:28--------d-----w-c:\program files\Trend Micro
2009-08-22 14:08 . 2009-08-22 14:08--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-08-21 14:09 . 2009-08-21 14:09--------d-----w-c:\documents and settings\Cassaundra\Application Data\Panda Security
2009-08-21 14:06 . 2009-08-21 14:06245----a-w-c:\windows\system32\PSUNCpl.dat
2009-08-21 14:06 . 2009-08-21 14:06--------d-----w-c:\program files\Panda Security
2009-08-21 14:06 . 2009-08-21 14:06--------d-----w-c:\documents and settings\All Users\Application Data\Panda Security
2009-08-14 23:11 . 2009-08-14 23:11--------d-----w-c:\program files\DivX
2009-08-14 23:11 . 2009-08-14 23:11--------d-----w-c:\program files\Common Files\DivX Shared
2009-08-12 02:39 . 2004-08-04 06:5625600----a-w-c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-08-10 00:32 . 2009-08-10 00:32--------d-----w-c:\program files\IrfanView
2009-08-06 16:23 . 2006-07-11 09:0090624----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMlr75.dll
2009-08-06 16:23 . 2006-07-11 09:0069632----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMsr75.dll
2009-08-06 16:23 . 2006-07-11 09:0054272----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMlr75.dll
2009-08-06 16:23 . 2006-07-11 09:0040448----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMsr75.dll
2009-08-06 16:23 . 2006-07-11 09:00254464----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMur75.dll
2009-08-06 16:23 . 2006-07-11 09:00192512----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMur75.dll
2009-08-06 16:06 . 2008-04-13 18:4725856----a-w-c:\windows\system32\drivers\usbprint.sys
2009-07-26 20:27 . 2009-07-26 20:27--------d-----w-c:\program files\Windows Media Connect 2
2009-07-26 20:26 . 2009-07-26 20:26--------d-----w-c:\windows\system32\drivers\UMDF
2009-07-26 20:26 . 2009-07-26 20:26--------d-----w-c:\windows\system32\LogFiles
2009-07-26 20:26 . 2007-08-11 00:4626488----a-w-c:\windows\system32\spupdsvc.exe
2009-07-26 20:21 . 2006-10-27 02:5632592----a-w-c:\windows\system32\msonpmon.dll
2009-07-26 20:20 . 2009-07-26 20:20--------d-----w-c:\program files\Microsoft Works
2009-07-26 20:20 . 2009-07-26 20:20--------d-----w-c:\program files\MSBuild
2009-07-26 20:19 . 2009-07-26 20:19--------d-----w-c:\program files\Microsoft.NET
2009-07-26 20:17 . 2009-07-26 20:17--------d-----w-c:\program files\Microsoft Visual Studio 8
2009-07-26 20:16 . 2009-07-26 20:20--------d-----w-c:\windows\SHELLNEW
2009-07-26 20:16 . 2009-07-26 20:16--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\Microsoft Help
2009-07-26 20:16 . 2009-07-26 20:22--------d-----w-c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-26 20:16 . 2009-07-26 20:16--------d--h--r-C:\MSOCache
2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\AOL
2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\All Users\Application Data\AOL OCP
2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\All Users\Application Data\AOL
2009-07-26 20:08 . 2009-08-22 17:23--------d-----w-c:\program files\Common Files\AOL
2009-07-26 20:06 . 2009-07-26 20:060----a-w-c:\windows\nsreg.dat
2009-07-26 20:06 . 2009-07-26 20:06--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\Mozilla
2009-07-26 20:03 . 2009-07-26 20:03--------d-----w-c:\program files\CONEXANT
2009-07-26 19:56 . 2009-07-26 20:04--------d-----w-c:\windows\nview
2009-07-26 19:56 . 2005-09-18 15:32180224----a-w-c:\windows\system32\nvudisp.exe
2009-07-26 19:51 . 2005-09-09 20:51176128----a-w-c:\windows\system32\nvuide.exe
2009-07-26 19:51 . 2005-09-09 20:51176128----a-w-c:\windows\system32\nvunrm.exe
2009-07-26 19:51 . 2005-07-30 02:10100480----a-w-c:\windows\system32\drivers\nvtcp.sys
2009-07-26 19:51 . 2005-09-09 22:51176128----a-w-c:\windows\system32\nvusmb.exe
2009-07-26 19:50 . 2005-09-09 20:51176128----a-w-c:\windows\system32\NVUNINST.EXE
2009-07-26 19:50 . 2009-07-26 19:50--------d-----w-c:\program files\Common Files\InstallShield
2009-07-26 19:47 . 2006-05-24 01:04110592----a-w-c:\documents and settings\Cassaundra\Application Data\U3\temp\cleanup.exe
2009-07-26 19:46 . 2009-07-26 19:49--------d-----w-c:\documents and settings\Cassaundra\Application Data\U3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 17:16 . 2009-06-16 01:4886327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-06 16:21 . 2009-08-06 16:21--------d--h--w-c:\documents and settings\All Users\Application Data\CanonBJ
2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\Realtek Sound Manager
2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\AvRack
2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\Realtek AC97
2009-07-26 20:00 . 2009-07-26 20:00--------d--h--w-c:\program files\InstallShield Installation Information
2009-06-23 14:04 . 2009-06-23 14:04136072----a-w-c:\windows\system32\drivers\PSINAflt.sys
2009-06-23 14:04 . 2009-06-23 14:04114056----a-w-c:\windows\system32\drivers\PSINKNC.sys
2009-06-16 01:55 . 2009-06-16 01:5512328----a-w-c:\documents and settings\Cassaundra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 01:46 . 2009-06-16 01:4621640----a-w-c:\windows\system32\emptyregdb.dat
2009-06-04 20:16 . 2009-06-04 20:1698184----a-w-c:\windows\system32\drivers\PSINProc.sys
2009-06-04 20:16 . 2009-06-04 20:1692552----a-w-c:\windows\system32\drivers\PSINFile.sys
2009-05-01 21:02 . 2009-05-01 21:021044480----a-w-c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02200704----a-w-c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Malware Icon]
@="{E309578C-8EDE-4731-99FA-6810B408B1BC}"
[HKEY_CLASSES_ROOT\CLSID\{E309578C-8EDE-4731-99FA-6810B408B1BC}]
2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Pending Delete Icon]
@="{1D0B2E83-D473-4E1F-B213-AA7BC759DE20}"
[HKEY_CLASSES_ROOT\CLSID\{1D0B2E83-D473-4E1F-B213-AA7BC759DE20}]
2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Suspect Icon]
@="{B26DA910-F1DE-426A-8282-5B55958E11B6}"
[HKEY_CLASSES_ROOT\CLSID\{B26DA910-F1DE-426A-8282-5B55958E11B6}]
2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2009-06-04 353536]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-09-18 1519616]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-12-15 577536]

c:\documents and settings\Cassaundra\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [6/23/2009 10:04 AM 114056]
R2 NanoServiceMain;NanoServiceMain;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [4/23/2009 8:14 PM 95488]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [6/23/2009 10:04 AM 136072]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [6/4/2009 4:16 PM 92552]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [6/4/2009 4:16 PM 98184]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default _setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-22 17:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3004)
c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-08-22 17:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-22 21:58

Pre-Run: 146,827,730,944 bytes free
Post-Run: 147,095,777,280 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /TUTag=1CVMII /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=1CVMII-BAK

253
Looks a lot better. Is the computer running OK now?

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

3825.

Solve : vulnerabilities?

Answer»

I checked my SECURITY centre and my Windows is already up to date. Java still failed to be installed, with the same message.
The Adobe file, AdbeRdr910-en-US.exe, also failed to be installed for the same reason: Error 1606 - could not access network location %APPDATA%\.Can you create a new user account and try to download/install Java from it?

This way we will know if it's the computer itself or just your account.I created a new user account but had the same result with Java. Installation still failed with the same message: could not access network location %APPDATA%/.I'm out of ideas.

Maybe try to scan your computer for faulty FILES.

  • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    • Let this run undisturbed until the window with the BLUE progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.I ran sfc and the result is:"Windows RESOURCE Protection did not find any integrity violation".
Java still failed to be installed.

Would you recommend "System Restore"? I have been able to update both Adobe and Java in April 2009.It's worth a try.I wanted to go back to April 2009, but the restore points shown in System Restore only go back to 5/8/2009. Is there any way I can go back to April 2009?If it isn't there then no you can't.Sorry to report that System Restore couldn't solve the problem either. Though I'm still out on a limb, i want to thank you very much for the trouble and time you took. Is it going to have to be the final drastic measure of product recovery for my computer?why didnt you remove it from the control panel
i think because you just deleted it
now it wont install
You can try POSTING in the Computer Help section. Someone there will have some ideas.Ok. I'll post it in Computer Help section.
3826.

Solve : Trojan Horse Clicker ZGZ Infected file too large for archives?

Answer»

Hello: I use an XP service pack 3 and I have the free AVG Anti-virus completely updated. After updating I did a scan and found two infected files, both infected with Trojan Horse Clicker.ZGZ When I try to REMOVE the infected files, I GET the message from AVG: "Moved OBJECT is bigger than the ARCHIVE size limit" and so it doesn't remove the infected file. What can I do to get RID of this?

What's a little strange, though, is that when I click on "take me to the file" I come up with a file that is two years old. I've done many virus checks in the last two years. Why wasn't this picked up? Is this spurious or a real threat?

Thanks
Dr. D. Again!virues can modify the timestamp
Drd, why not visit this link ,follow the directions and post the three logs. Then we can determine what the problem is.

3827.

Solve : Running Windows Vista Firewall in Tandem with Comodo?

Answer»

Hi,

Having received your great advice the other day I HAVER thoroughly cleaned all my computers at home - and they're all running like new.

All that is, except the NEW one!!!!

I've begun to deep clean it and, am at the stage where I have just added Comodo. As the title suggests, the laptop is new and has vista. The firewall with this seems pretty competant and interjects every time u click to DOWNLOAD SOMETHING, breathe out of place or scratch your arse!!!!

Is it necessary/efficient to run another firewall such as Commodo or Zonealarm - or is the WHOLE idea of Vista to be self sufficient?Quote

Is it necessary/efficient to run another firewall such as Commodo or Zonealarm - or is the whole idea of Vista to be self sufficient?
No. You should only have one firewall running on your PC. Stick with Comodo, and TURN off Windows Firewall.
3828.

Solve : Debilitating typing/clicking errors?

Answer»

I had posted a topic in the the Windows XP section of the forum previously, but nothing suggested seemed to clear up my problem, so I was told to post here.

What I'm dealing with basically is a few issues, mainly unwanted capitilization of text occuring randomly which is accompanied by other problems including
- INABILITY to send messages on MSN
- inability to click on a single file, as a single click will now highlight/open many files unintentionally
- problems with selecting text, as large blocks will be selected from a single click
- clicking on a link that should just open a new PAGE in the current browser window, now cause an entire new window to open

These are some very frustrating problems, and make it hard to do anything when they appear. It's not the keyboard, as it's happened on more than one. No hotplugging. I regularly run AVG and Spybot. I just started running CCLEANER. I even tried a standard System Recover and no change.

The problem usually occurs after my PC has been actively running while I'm using it for an hour or so. I dl'ed SPEEDFAN and noticed that my GPU, Temp 1 and 2 and Core appear with a 'fire' icon when the problems occur.

I performed all the scans suggested in the sticky and have them attacked in a .txt file.

[attachment deleted by admin]

3829.

Solve : computer acting funny and lots of ads-do i have spyware??

Answer»

i will remove one after this is fixed
doesnt seem to conflictI assure you they DO conflict. Anyway, get rid of MCAFEE - it's really the worst out there.Quote from: smeezekitty on August 23, 2009, 03:47:05 PM

i will remove one after this is fixed
doesnt seem to conflict

Yes they do conflict. At the very LEAST they are interupting each others processes to scan what the other is doing.

Do what ADG suggests there, get rid of McAfee.here is my avira log
Code: [Select]

Avira AntiVir Personal
Report file DATE: Sunday, August 23, 2009 11:05

Scanning for 1651917 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows Vista
Windows version : (Service Pack 1) [6.0.6001]
Boot mode : Normally booted
Username : SYSTEM
Computer name : JOHN-PC

Version information:
BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 21:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 18:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 19:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 18:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 20:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 17:21:42
ANTIVIR2.VDF : 7.1.5.146 3087360 Bytes 8/21/2009 00:36:58
ANTIVIR3.VDF : 7.1.5.149 9728 Bytes 8/21/2009 00:36:59
Engineversion : 8.2.1.3
AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 21:31:50
AESCRIPT.DLL : 8.1.2.25 459130 Bytes 8/23/2009 00:37:12
AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 17:59:39
AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 17:59:39
AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 21:31:50
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 17:59:39
AEHEUR.DLL : 8.1.0.155 1921400 Bytes 8/23/2009 00:37:10
AEHELP.DLL : 8.1.6.0 233846 Bytes 8/23/2009 00:37:03
AEGEN.DLL : 8.1.1.57 356725 Bytes 8/23/2009 00:37:01
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 22:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 17:59:39
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 22:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 16:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 18:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 22:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 18:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 23:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 18:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 23:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 16:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 18:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 23:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 18:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot SECTORS........................: C:, D:, M:, O:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +JOKE,

Start of the scan: Sunday, August 23, 2009 11:05

Starting search for hidden objects.
'222294' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'speedfan.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process '3DMark03.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sdclt.exe' - '1' Module(s) have been scanned
Scan process 'mcupdate.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'mcuimgr.exe' - '1' Module(s) have been scanned
Scan process 'McNASvc.exe' - '1' Module(s) have been scanned
Scan process 'mcsysmon.exe' - '1' Module(s) have been scanned
Scan process 'RtkBtMnt.exe' - '1' Module(s) have been scanned
Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
Scan process 'winThrottle.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'igfxext.exe' - '1' Module(s) have been scanned
Scan process 'BTTray.exe' - '1' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
Scan process 'vivaty.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'MC.exe' - '1' Module(s) have been scanned
Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'winampa.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'ApMsgFwd.exe' - '1' Module(s) have been scanned
Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned
Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
Scan process 'Apoint.exe' - '1' Module(s) have been scanned
Scan process 'BkupTray.exe' - '1' Module(s) have been scanned
Scan process 'LManager.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'mcagent.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'mcmscsvc.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'XAudio.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sqlwriter.exe' - '1' Module(s) have been scanned
Scan process 'sqlbrowser.exe' - '1' Module(s) have been scanned
Scan process 'PsiService_2.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SchedulerSvc.exe' - '1' Module(s) have been scanned
Scan process 'BackupSvc.exe' - '1' Module(s) have been scanned
Scan process 'SMSvcHost.exe' - '1' Module(s) have been scanned
Scan process 'sqlservr.exe' - '1' Module(s) have been scanned
Scan process 'msksrver.exe' - '1' Module(s) have been scanned
Scan process 'MpfSrv.exe' - '1' Module(s) have been scanned
Scan process 'MobilityService.exe' - '1' Module(s) have been scanned
Scan process 'Mcshield.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'McProxy.exe' - '1' Module(s) have been scanned
Scan process 'McSACore.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned
Scan process 'ETService.exe' - '1' Module(s) have been scanned
Scan process 'Agentsvc.exe' - '1' Module(s) have been scanned
Scan process 'btwdins.exe' - '1' Module(s) have been scanned
Scan process 'BcmSqlStartupSvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
98 processes with 98 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'M:\'
[INFO] No virus was found!
Boot sector 'O:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '95' files ).


Starting the file scan:

Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\blackcat\TEST\DDTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\blackcat\TEST\SDLTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\cygnew\bin\camlp4.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\camlp4o.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\camlp4o.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\camlp4r.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\camlp4r.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\lyx.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\lyxclient.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocaml.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlbrowser.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlc.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlc.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlcp.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamldebug.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamldep.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamldep.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamldoc.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamldoc.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamllex.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamllex.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlopt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlopt.opt.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlprof.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlrun.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocamlyacc.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\ocpp.exe
[WARNING] The file could not be opened!
C:\cygnew\bin\tex2lyx.exe
[WARNING] The file could not be opened!
C:\cygnew\lib\ocaml\camlheader
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\cygnew\lib\ocaml\camlheader_ur
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\cygnew\lib\ocaml\expunge.exe
[WARNING] The file could not be opened!
C:\MinGW\bin\mklinkstub.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\Program Files\Cain\Abel.exe
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
C:\Program Files\Silicon Pixels\CPIX\CPIX16.EXE
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\tc\TCC\NONP.EXE
[DETECTION] Contains recognition pattern of the DOS/Candy DOS virus
C:\tc\TCC\PARSE.EXE
[DETECTION] Contains recognition pattern of the DOS/Candy DOS virus
C:\windows\system32\eula.txt
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\windows\system32\_joker123.bin
[DETECTION] Contains recognition pattern of the DOS/Candy DOS virus
Begin scan in 'D:\' <DATA>
D:\pagefile.sys
[WARNING] The file could not be opened!
D:\snf.exe
[DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan
D:\Bouncey ball\snf.exe
[DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan
D:\Bouncey ball\snf2.exe
[DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan
D:\devkitadv\bin\mklinkstub.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
D:\dosex\TEST\DDTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\dosex\TEST\SDLTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\doxex\TEST\DDTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\gbadev\devkitadv\bin\mklinkstub.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
D:\hx\TEST\DDTEST.EXE
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\reactos\ReactOS-0.3.9\output-i386\base\applications\network\dwnl\dwnl.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
D:\reactos\ReactOS-0.3.9\output-i386\livecd\reactos\system32\dwnl.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
Begin scan in 'M:\' <PQSERVICE>
M:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'O:\'
Quote from: SuperDave on August 21, 2009, 07:24:18 PM
Smeezekitty, you should run SuperAntispyware and Malwarebytes-Antimalware programs found here and post the logs. Also run HJT again and post the log.
3830.

Solve : My MBAM says that I have a worm, but I can't get rid of it. Any help??

Answer»

I ATTACHED my logs. I don't know if it is something I should worry about. Just THOUGHT I would GET some advice. My MBAM says I have a worm, but I think it could be wrong. Thanks in ADVANCE for any help.

[attachment deleted by admin]click start click programs click accessories click COMMAND prompt
an type del C:\Users\Public\Favorites\NginuL_na.exeThis may or may not be an issue.....evilfantasy will confirm.

http://www.malwarebytes.org/forums/index.php?showtopic=19837

3831.

Solve : Antivirus 2010,,,,,,,,,,,,,,?

Answer»

I got rid of limewire and windows messenger alsoyou have a few things that a malware expert will help you with so wait for one to get in touch please

i'm not an expert and can only help a little

you did right removing limewire

avg takes up a lot of room and tends to slow the pc , try avira or avast both free if you do ask here for avg removal tool

I had Avira on it for a while, I like the AVG better, or maybe I am just more used to it.ok you will have to wait for an expert for the rest , harryDid the Antivirus 2010 get removed?Hello 72GSX. It looks like your computer is clean. If there are no other issues, LET's do some clean-up.


Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

To turn off Windows XP System Restore:

NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
8. Restart the computer and follow the instructions in the next section to turn on System Restore.

To turn on Windows XP System Restore:

1. Click Start.
2. Right-click My Computer, and then click Properties.
3. Click the System Restore tab.
4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
5. Click Apply, and then click OK.

Looking over your log it seems you don't have any evidence of a third PARTY firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop CERTAIN cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Safe Surfing. sorry dave i did not see you on before , harry The computer that had the problems has a router card installed in it and is connected to the DSL, I have my PC and sometimes another PC hooked into the router card, A small home network I guess I would call it.

If I put a firewall on the main PC will it protect other PC's plugged into it? Or will it block the other PC's from working on line?

Tomhi tom , me again , a good QUESTION

if you have completed everything that dave asked you to do , i would ask that question in the software forum

on the home page , you will get experts there for that type of thing, harryHi, Sorry for not getting back right away. I did most everything suggested to the PC, the only problem I had was when I installed a firewall, I couldn't get it to let my other computer go on line, so for now I just removed it. It was the On line Armor that I tried. It didn't say anything about it but do I have to turn off or disable the windows firewall when adding a different one?

No more problems with the 2010 scam deal popping up and its working good again so it must not have damaged anything while it was on it.

Tomjust use windows firewall it is good 5 YEARS iv'e had it just keep windows up to date

3832.

Solve : help with security center malware?

Answer»

Morning SD,
The Scan said, No Threats Found. It did not give me an option to download a text file. I think that is really good, right? If not I can try running it again. Thank you.
-R If is said "no threats found" it look like your computer is clean. If there are no other issues, it's time for some clean-up. You can uninstall HTJ but you can keep SAS and MBAM. Update them and run them about once a week.

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will CLOSE all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to FINISH and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT WARNS you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Safe Surfing!

3833.

Solve : Re: "Your System is Infected" is virus leeching my computer - help please! :)?

Answer»

Hi, first post coming here but I had the exact same problem from a rogue anto-virus software called internet security2010, i got RID of the anti-virus with SPYWARE DOCTOR, and fixed the obviously FAKE background with the file suggested on the first page of this thread, and it worked! So I hope you can fix yours soonPlease go to this link and follow the DIRECTIONS and post the required logs.

3834.

Solve : Administrator Problem?

Answer»

HI everyone, my boyfriend and I have a computer and his sister set it up for us. She has him as the "ADMINISTRATOR" and me I guess as a regular user. She is on vacation, so I can't ask her and I know the computer has a virsus because it didn't have any protection when my bf started to use it and it is really, really slow. I brought Norton anti-virus and want to install it, but it will not let me install it because I am not the administrator. How do I make myself an administrator??? thank you. I want to install it but my bf thinks we don't need it so that is why he is not installing it, so I have to do it!You have to be an administrator to change user account rights. Sorry, but you'll have to ask your boyfriend to either install it or make you an administrator too.okay thank you I will try!That, or log in as your bf.

Alan <>< thats a good one!! he won't let me know what is password is, but I won't let him know mine

But you would think with a computer that I would be ABLE to do it, since I am set up, he doesn't think that we need the Norton because we have verizon as our computer service and he thinks they take care of everything. So if he won't set me up as administrator because I think you can have more than one admin. he will screw the computer up and then we won't have one!! the computer is acting so weird and so, I am almost positive it has a virus, First, having no antivirus I garuntee you have an infection.
Second, Verizon (the internet service) does not to anything regarding malware and viruses. To TRUST a Service Provider with your computer's security is very foolish. (no offense intended) An antivirus software is absolutely necessary.
Third, having more than one administrator accounts will not damage the computer in any way.Time for a new bf?

Alan <>< Your boyfriend is probably a nice person, but tell him to back away from his passive-agressive stance, and grant you admin. rights...or, when it all crashes, SHRUG, and say, "Hey, I'm not the administrator."

3835.

Solve : strange things happening again?

Answer»

latest update

Ok, we did the file cabinet backup according to instructions from the AOL support site and reinstalled AOL 9.0. After checking various sites it looked like the problem was resolved.

Unfortunately after about 3 hours or so, the user closed down the internet window on AOL and IE opened up a window with multiple tabs of the same page.

And to top it off when we tried to restore the file cabinet we got a message that there was not backup. The file was saved twice in the documents folder as well as once on the desktop. The backup will open up if we use File>Open on the AOL taskbar but in ORDER to get the emails back into AOL each one has to be opened and saved to pfc on the computer. There are HUNDREDS of emails!

I know these are two different problems but the latter would not be in effect without symptoms of the former.

Please, please, any thoughts to fix either are appreciated.
Reset IE's default settings: http://support.microsoft.com/kb/923737Thanks, passed the link on to the user. I will let you know how it goes.
No luck on resetting IE, it was reset but the problem with opening up multiple tabs of the same page on AOL internet closing is still happening. Very VERY annoying.Ok, fixed the file cabinet problem. The IE problem is still rearing it's ugly head. Now 2 WINDOWS open up, each with multiple tabs of the same page that was closed when using AOL to get on the internet. The only way to close the windows is to use the task manager and close AOL and then the IE windows.

I advised that she should use AOL just for her email and to use Firefox for the internet. More complicated than she wants but it should work.

And as another cherry on this sundae of busted, we can not restore to a restore point of 2 months ago. The computer goes through the motions and RESTARTS, but gives the message that it can not be restored to the date chosen. We tried May 1 and May 15 and got the same message.ok, new developments. The user was having problems with IE opening up after closing the AOL so decided to download IE8. Now the computer appears to be bricked, when the power button is pressed the fan starts, the cd and dvd drives blink but nothing else happens. Tomorrow I am heading there to either get it running or roll back to IE7.

3836.

Solve : Painfully Slow Computer?

Answer»

My friend has a computer that runs ultra slow.

*****
32-bit computer
HP PAVILION dv6700 Notebook PC, 1.0 GHZ, 4 Gigs of RAM, AMD Athlon 64 X2 Dual-Core Processor TK-57
Vista SP2
Anti-Virus: Norton 360 Premiere Edition
Spyware: Super AntiSpyware
*****
Boot up takes about 5 minutes or longer and general browsing on the computer is like we were using an old 486.

I followed the steps posted in the "Malware Removal GUIDE" thread. Attached are the logs required. Please help! THANK you!


[attachment deleted by admin]

3837.

Solve : Double the fun!?

Answer»

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and PRESSING Ctrl+C

Code: [Select]KillAll::

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"=-
"57086:TCP"=-
"57086:UDP"=-

RegLockDel::
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\ProxyStubClsid]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0]


3. Go to the Notepad window and click Edit > Paste
4. Then click File > SAVE
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeAs requested:

ComboFix 09-06-26.02 - Dad 06/27/2009 19:56.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1007.572 [GMT -7:00]
Running from: c:\documents and settings\Dad\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dad\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
.

2009-06-28 02:02 . 2009-06-28 02:02--------d-----w-c:\windows\system32\dllcache\cache
2009-06-27 21:03 . 2009-06-27 21:03--------d--h--w-c:\windows\PIF
2009-06-27 06:55 . 2009-06-27 06:55--------d-----w-c:\documents and settings\Dad\Application Data\Malwarebytes
2009-06-27 06:50 . 2009-06-27 06:54--------d-----w-c:\program files\SUPERAntiSpyware
2009-06-27 06:27 . 2009-06-27 18:06117760----a-w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-27 06:27 . 2009-06-27 06:27--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-27 06:20 . 2009-06-27 06:20--------d-----w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com
2009-06-27 05:46 . 2009-06-27 05:46--------d-----w-c:\program files\Trend Micro
2009-06-27 05:40 . 2009-06-27 05:39410984----a-w-c:\windows\system32\deploytk.dll
2009-06-26 07:45 . 2009-03-30 17:3396104----a-w-c:\windows\system32\drivers\avipbb.sys
2009-06-26 07:45 . 2009-03-24 23:0855640----a-w-c:\windows\system32\drivers\avgntflt.sys
2009-06-26 07:45 . 2009-02-13 19:2922360----a-w-c:\windows\system32\drivers\avgntmgr.sys
2009-06-26 07:45 . 2009-02-13 19:1745416----a-w-c:\windows\system32\drivers\avgntdd.sys
2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\program files\Avira
2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\documents and settings\All Users\Application Data\Avira
2009-06-26 07:36 . 2009-06-17 18:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-26 07:36 . 2009-06-26 07:36--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-26 07:36 . 2009-06-17 18:2719096----a-w-c:\windows\system32\drivers\mbam.sys
2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\program files\iPod
2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-22 00:46 . 2009-06-22 00:46--------d-----w-c:\program files\Bonjour
2009-06-22 00:45 . 2009-06-22 00:45--------d-----w-c:\program files\QuickTime
2009-06-22 00:43 . 2009-06-22 00:43--------d-----w-c:\program files\Apple Software Update
2009-06-21 22:50 . 2009-06-21 22:50--------d-----w-c:\documents and settings\Dad\Local Settings\Application Data\AOL
2009-06-05 20:57 . 2009-06-05 20:5775048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 23:55 . 2009-04-10 18:27--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-27 06:49 . 2002-01-04 09:43--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-06-27 05:39 . 2002-01-02 07:20--------d-----w-c:\program files\Java
2009-06-27 04:41 . 2007-07-22 04:02--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 06:04 . 2007-03-25 15:4951936----a-w-c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 06:02 . 2002-01-02 07:21--------d-----w-c:\program files\OpenOffice.org 2.2
2009-06-26 05:56 . 2003-07-31 11:52--------d--h--w-c:\program files\InstallShield Installation Information
2009-06-26 05:52 . 2002-01-02 08:35--------d-----w-c:\documents and settings\Dad\Application Data\OpenOffice.org2
2009-06-26 05:52 . 2008-10-08 06:27--------d-----w-c:\documents and settings\Dad\Application Data\stickies
2009-06-26 05:20 . 2002-01-04 09:37--------d-----w-c:\program files\Common Files\Panda Software
2009-06-26 05:12 . 2008-11-25 19:33--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
2009-06-22 00:48 . 2008-09-15 04:37--------d-----w-c:\program files\Common Files\Apple
2009-06-21 22:51 . 2009-04-10 18:24--------d-----w-c:\program files\Common Files\AOL
2009-06-09 17:09 . 2007-09-17 05:02--------d-----w-c:\documents and settings\Samuel.OAKTREE3\Application Data\OpenOffice.org2
2009-05-11 22:48 . 2009-05-11 22:2034----a-w-c:\documents and settings\Samuel.OAKTREE3\jagex_runescape_preferences.dat
2009-04-10 18:29 . 2009-04-10 18:291144808----a-w-c:\documents and settings\All Users\Application Data\AOL Downloads\aimtunes\AIMTunes.exe
2008-01-15 18:50 . 2007-10-21 07:101004--sha-w-c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( [emailprotected]_01.59.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 03:02 . 2009-06-28 03:0216384 c:\windows\temp\Perflib_Perfdata_294.dat
+ 2009-06-28 02:02 . 2008-10-16 22:0951224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5682944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:5624576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5614336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-28 02:02 . 2005-06-10 23:5357856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5617408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-28 02:02 . 2004-08-04 07:5613312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-28 02:02 . 2004-08-04 05:5824576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-28 02:02 . 2004-08-04 06:0029056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-28 02:02 . 2004-08-04 07:5615360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-06-28 02:02 . 2004-08-04 07:56502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-28 02:02 . 2008-10-16 10:37659456 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-28 02:02 . 2007-03-08 15:36577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-28 02:02 . 2008-06-20 10:45360320 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-28 02:02 . 2004-08-04 07:56108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-28 02:02 . 2004-08-04 06:14182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-28 02:02 . 2007-04-16 15:52984576 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-28 02:02 . 2004-08-04 07:561580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-28 02:02 . 2008-08-14 09:582136064 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-28 02:02 . 2008-08-14 09:222015744 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-28 02:02 . 2007-06-13 10:231033216 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2009-04-21 00:181883672----a-w-c:\program files\Freecorder\tbFre1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="e:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-06-19 393216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-09-19 684032]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-27 148888]
"AAWTray"="c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 88024]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\Stickies\\stickies.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/26/2009 12:45 AM 108289]
S1 Multicam;MultiCam for Picolo;c:\windows\system32\Drivers\multicam.sys --> c:\windows\system32\Drivers\multicam.sys [?]
S1 SASKUTIL;SASKUTIL;\??\e:\program files\SUPERAntiSpyware\SASKUTIL.sys --> e:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 AtomSync;AtomSync;e:\program files\AtomSync\service.exe [9/23/2008 10:34 PM 159744]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [5/20/2008 10:47 PM 13224]
S3 SASENUM;SASENUM;\??\e:\program files\SUPERAntiSpyware\SASENUM.SYS --> e:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-02 01:16]

2009-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4265909289-2111342016-2801439982-1016.job
- c:\documents and settings\Samuel.OAKTREE3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-18 07:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gbcph.org/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\b9k9d87q.default\
FF - prefs.js: browser.startup.homepage - www.gbcph.org
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: e:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-27 20:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files\\Zango\\bin\\10.3.75.0\\CoreSrv.dll"

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files\\Zango\\bin\\10.3.75.0\\Toolbar.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(856)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(1440)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-28 20:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-28 03:08
ComboFix2.txt 2009-06-28 02:04

Pre-Run: 108,959,559,680 bytes free
Post-Run: 108,944,457,728 bytes free

214

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Folder::
c:\Program Files\Zango

RegLockDel::
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0\0\win32]

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0\0\win32]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 09-06-26.02 - Dad 06/27/2009 22:42.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1007.579 [GMT -7:00]
Running from: c:\documents and settings\Dad\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dad\Desktop\cfscript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 )))))))))))))))))))))))))))))))
.

2009-06-28 02:02 . 2009-06-28 02:02--------d-----w-c:\windows\system32\dllcache\cache
2009-06-27 21:03 . 2009-06-27 21:03--------d--h--w-c:\windows\PIF
2009-06-27 06:55 . 2009-06-27 06:55--------d-----w-c:\documents and settings\Dad\Application Data\Malwarebytes
2009-06-27 06:50 . 2009-06-27 06:54--------d-----w-c:\program files\SUPERAntiSpyware
2009-06-27 06:27 . 2009-06-27 18:06117760----a-w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-27 06:27 . 2009-06-27 06:27--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-27 06:20 . 2009-06-27 06:20--------d-----w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com
2009-06-27 05:46 . 2009-06-27 05:46--------d-----w-c:\program files\Trend Micro
2009-06-27 05:40 . 2009-06-27 05:39410984----a-w-c:\windows\system32\deploytk.dll
2009-06-26 07:45 . 2009-03-30 17:3396104----a-w-c:\windows\system32\drivers\avipbb.sys
2009-06-26 07:45 . 2009-03-24 23:0855640----a-w-c:\windows\system32\drivers\avgntflt.sys
2009-06-26 07:45 . 2009-02-13 19:2922360----a-w-c:\windows\system32\drivers\avgntmgr.sys
2009-06-26 07:45 . 2009-02-13 19:1745416----a-w-c:\windows\system32\drivers\avgntdd.sys
2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\program files\Avira
2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\documents and settings\All Users\Application Data\Avira
2009-06-26 07:36 . 2009-06-17 18:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-26 07:36 . 2009-06-26 07:36--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-26 07:36 . 2009-06-17 18:2719096----a-w-c:\windows\system32\drivers\mbam.sys
2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\program files\iPod
2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-22 00:46 . 2009-06-22 00:46--------d-----w-c:\program files\Bonjour
2009-06-22 00:45 . 2009-06-22 00:45--------d-----w-c:\program files\QuickTime
2009-06-22 00:43 . 2009-06-22 00:43--------d-----w-c:\program files\Apple Software Update
2009-06-21 22:50 . 2009-06-21 22:50--------d-----w-c:\documents and settings\Dad\Local Settings\Application Data\AOL
2009-06-05 20:57 . 2009-06-05 20:5775048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 23:55 . 2009-04-10 18:27--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-27 06:49 . 2002-01-04 09:43--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-06-27 05:39 . 2002-01-02 07:20--------d-----w-c:\program files\Java
2009-06-27 04:41 . 2007-07-22 04:02--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 06:04 . 2007-03-25 15:4951936----a-w-c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 06:02 . 2002-01-02 07:21--------d-----w-c:\program files\OpenOffice.org 2.2
2009-06-26 05:56 . 2003-07-31 11:52--------d--h--w-c:\program files\InstallShield Installation Information
2009-06-26 05:52 . 2002-01-02 08:35--------d-----w-c:\documents and settings\Dad\Application Data\OpenOffice.org2
2009-06-26 05:52 . 2008-10-08 06:27--------d-----w-c:\documents and settings\Dad\Application Data\stickies
2009-06-26 05:20 . 2002-01-04 09:37--------d-----w-c:\program files\Common Files\Panda Software
2009-06-26 05:12 . 2008-11-25 19:33--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
2009-06-22 00:48 . 2008-09-15 04:37--------d-----w-c:\program files\Common Files\Apple
2009-06-21 22:51 . 2009-04-10 18:24--------d-----w-c:\program files\Common Files\AOL
2009-06-09 17:09 . 2007-09-17 05:02--------d-----w-c:\documents and settings\Samuel.OAKTREE3\Application Data\OpenOffice.org2
2009-05-11 22:48 . 2009-05-11 22:2034----a-w-c:\documents and settings\Samuel.OAKTREE3\jagex_runescape_preferences.dat
2009-04-10 18:29 . 2009-04-10 18:291144808----a-w-c:\documents and settings\All Users\Application Data\AOL Downloads\aimtunes\AIMTunes.exe
2008-01-15 18:50 . 2007-10-21 07:101004--sha-w-c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( [emailprotected]_01.59.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 05:48 . 2009-06-28 05:4816384 c:\windows\temp\Perflib_Perfdata_244.dat
+ 2009-06-28 02:02 . 2008-10-16 22:0951224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5682944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:5624576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5614336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-28 02:02 . 2005-06-10 23:5357856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-28 02:02 . 2004-08-04 07:5617408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-28 02:02 . 2004-08-04 07:5613312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-28 02:02 . 2004-08-04 05:5824576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-28 02:02 . 2004-08-04 06:0029056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-28 02:02 . 2004-08-04 07:5615360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-06-28 02:02 . 2004-08-04 07:56502272 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-28 02:02 . 2008-10-16 10:37659456 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-28 02:02 . 2007-03-08 15:36577536 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-28 02:02 . 2008-06-20 10:45360320 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-28 02:02 . 2004-08-04 07:56108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-28 02:02 . 2004-08-04 06:14182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-28 02:02 . 2007-04-16 15:52984576 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-28 02:02 . 2004-08-04 07:56167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-28 02:02 . 2004-08-04 07:561580544 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-28 02:02 . 2008-08-14 09:582136064 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-28 02:02 . 2008-08-14 09:222015744 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-28 02:02 . 2007-06-13 10:231033216 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2009-04-21 00:181883672----a-w-c:\program files\Freecorder\tbFre1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="e:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-06-19 393216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-09-19 684032]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-27 148888]
"AAWTray"="c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 88024]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\Stickies\\stickies.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/26/2009 12:45 AM 108289]
S1 Multicam;MultiCam for Picolo;c:\windows\system32\Drivers\multicam.sys --> c:\windows\system32\Drivers\multicam.sys [?]
S1 SASKUTIL;SASKUTIL;\??\e:\program files\SUPERAntiSpyware\SASKUTIL.sys --> e:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 AtomSync;AtomSync;e:\program files\AtomSync\service.exe [9/23/2008 10:34 PM 159744]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [5/20/2008 10:47 PM 13224]
S3 SASENUM;SASENUM;\??\e:\program files\SUPERAntiSpyware\SASENUM.SYS --> e:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-02 01:16]

2009-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4265909289-2111342016-2801439982-1016.job
- c:\documents and settings\Samuel.OAKTREE3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-18 07:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gbcph.org/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\b9k9d87q.default\
FF - prefs.js: browser.startup.homepage - www.gbcph.org
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: e:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-27 22:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(1456)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-28 22:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-28 05:56
ComboFix2.txt 2009-06-28 03:08
ComboFix3.txt 2009-06-28 02:04

Pre-Run: 108,956,647,424 bytes free
Post-Run: 108,939,886,592 bytes free

207
    OK I think we finally got all of that.

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    • The above procedure will:
    • Delete the following:
    • ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

Use the ESET Online Antivirus Scanner

This scanner requires Internet Explorer

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. WAIT for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.[emailprotected] as CAB hook log:
OnlineScanner.ocx - delete file error:The process cannot access the file because it is being used by another process.

OnlineScanner.ocx - copy file error :The process cannot access the file because it is being used by another process.

OnlineScanner.ocx - registred OK
# version=6
# iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
# OnlineScanner.ocx=1.0.0.5863
# api_version=3.0.2
# EOSSerial=f8635a3504fa9c4583e41c03195de3f1
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-06-29 09:53:45
# local_time=2009-06-29 02:53:45 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1797 21 100 100 76642968750
# scanned=46189
# found=0
# cleaned=0
# scan_time=1490
Looks good. Is the computer running OK now?

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, SPYWARE, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky WEBSITE. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Ahhh...much better!

My thanks to all of the CH players who invested time in helping me resolve this problem. This has been a long but rewarding and educational process. Thanks also for the final "tools" recommendations to help safeguard my future computing experiences.

Kudos to the team!

(Now it's time to run off to the XP thread and see how my other machine is doing!)
3838.

Solve : Hijack this log.?

Answer»

Can you please check through this log to see if there is anything bad on ym system? thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:04:09, on 01/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows LIVE\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\BurnAware Free\nmsaccessu.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spotify\spotify.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\IObit\IObit Security 360\IObit Security 360.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [btbb_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] "C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237311651968
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} (F-Secure Health Check 1.1) - http://www.utvinternet.com/Residential/ClicksilverBroadband/PCHC/fscax.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper FLAGS Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe
O23 - Service: GOOGLE Update Service (gupdate1c9d95539169a80) (gupdate1c9d95539169a80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS360service - Unknown owner - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\BurnAware Free\nmsaccessu.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7997 bytes

3839.

Solve : from internet browsers - IE disappearing - scan logs?

Answer»

Ok, I got the laptop and sure enough the application for IE was missing from c:\program files\Internet Explorer. I tried to load IE6 but got a message that a later VERSION was already loaded. I tried to load IE7 but for some strange reason got a Proxy timeout from the DOE. I tried to load IE8, but part of the install process is updating, and with no working IE that failed. Finally installed the latest Firefox and made that default, now the laptop can get online.

Installed the programs and the SCANS are below:

Superantispyware - first scan

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/01/2009 at 09:01 PM

Application Version : 4.26.1006

Core Rules Database Version : 3952
Trace Rules Database Version: 1894

Scan type : Complete Scan
Total Scan Time : 00:42:14

Memory items scanned : 769
Memory threats detected : 0
Registry items scanned : 5963
Registry threats detected : 0
File items scanned : 22124
File threats detected : 67

Adware.Tracking Cookie
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected]roll[1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][2].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected][1].txt
C:\Documents and Settings\admin\Cookies\[emailprotected]live[2].txt

second scan

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/01/2009 at 10:08 PM

Application Version : 4.26.1006

Core Rules Database Version : 3952
Trace Rules Database Version: 1894

Scan type : Complete Scan
Total Scan Time : 00:51:39

Memory items scanned : 753
Memory threats detected : 0
Registry items scanned : 5962
Registry threats detected : 0
File items scanned : 22181
File threats detected : 0

Malwarebytes scan

Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 2

7/1/2009 8:04:23 PM
mbam-log-2009-07-01 (20-04-23).txt

Scan type: Quick Scan
Objects scanned: 61857
Time elapsed: 12 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Hijackthis scan

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:21 PM, on 7/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Microsoft SHARED Computer Toolkit\bin\SRVANY.EXE
C:\Program Files\Microsoft Shared Computer Toolkit\bin\SCTThresholdMonitor.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Cisco Systems\CSAgent\bin\CSAControl.exe
C:\Program Files\Cisco Systems\CSAgent\bin\leventmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\trcboot.exe
C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\rpcnet.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\Drivers\ldlcserv.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Apoint\HidFind.exe
c:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://schools.nyc.gov/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.nycboe.org/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8002
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [DIR] Dir /w
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [KADxMain] c:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [systray] C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Check Windows Disk Protection.lnk = C:\Program Files\Microsoft Shared Computer Toolkit\CheckWDP.hta (User 'SYSTEM')
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Check Windows Disk Protection.lnk = C:\Program Files\Microsoft Shared Computer Toolkit\CheckWDP.hta (User 'Default user')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Cisco Security Agent.lnk = C:\Program Files\Cisco Systems\CSAgent\bin\okclient.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.cybershift.net
O15 - Trusted Zone: http://*.nycboe.net
O15 - Trusted Zone: http://*.nycenet.edu
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189458741687
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189458561375
O20 - AppInit_DLLs: csauser.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Security Agent (CSAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\CSAgent\bin\CSAControl.exe
O23 - Service: DataSvr2 - Unknown owner - C:\Program Files\Wave Systems Corp\Common\DataServer.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ldlcserv - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Remote Procedure Call (RPC) Net (Rpcnet) - Absolute Software Corp. - C:\WINDOWS\system32\rpcnet.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SCTThresholdMonitor (SCTThresholdMon) - Unknown owner - C:\Program Files\Microsoft Shared Computer Toolkit\bin\SRVANY.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: TrcBoot - IBM Corporation - C:\WINDOWS\system32\drivers\trcboot.exe
O23 - Service: WDPOperations - Unknown owner - C:\Program Files\Microsoft Shared Computer Toolkit\bin\SRVANY.EXE
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O24 - Desktop Component 1: (no name) - http://www.childrenfirstintensive.com/laptop

--
End of file - 14473 bytes


In addition I ran ccleaner and removed almost 1gb of junk, ran spybot and FOUND nothing.

What do you think? Thanks

3840.

Solve : system security 2009 - can't run programs and can't start in safe mode?

Answer»

I have RESTARTED and run MBAM and HJT a few more times and seem to have gotten the last of the evidence of the INFECTION... THANKS for your HELP, we're very very busy right now so DEALING with a stubborn computer problem was not high on my list...

Thanks again!

3841.

Solve : Re: Firefox & IE search results go to wrong page. Can't run HijackThis. HELP Please?

Answer»

Hello,

I have read the thread and I seem to have the same problem.

I dont know if the same solution would apply in my case so I start again giving the DDS logs:


DDS (Ver_09-06-26.01) - NTFSx86
Run by Guillaume at 1:05:58.93 on 02-07-2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.91.1033.18.3069.1944 [GMT 2:00]

SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\vfsFPService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\DigitalPersona\Bin\DpHostW.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
C:\Windows\system32\agrsmsvc.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\Guillaume\Desktop\gmer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\conime.exe
C:\Users\Guillaume\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.HP.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [ares] "c:\program files\ares\Ares.exe" -h
mRun: [DpAgent] c:\program files\digitalpersona\bin\dpagent.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ClamWin] "c:\program files\clamwin\bin\ClamTray.exe" --logon
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
TCP: NameServer = 85.255.112.68,85.255.112.66
TCP: {0ECBD136-23E9-41FE-8373-11C4F97608E6} = 85.255.112.68,85.255.112.66
TCP: {9737D2AB-68FA-4999-B25B-0AF3DAF71C2D} = 85.255.112.68,85.255.112.66
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
LSA: Notification Packages = scecli DPPWDFLT

================= FIREFOX ===================

FF - ProfilePath - c:\users\guilla~1\appdata\roaming\mozilla\firefox\profiles\7epg4avp.default\
FF - component: c:\program files\digitalpersona\bin\firefoxext\components\dpffcli.dll
FF - component: c:\program files\mozilla firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\guillaume\appdata\local\google\update\1.2.183.7\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-1 64160]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/01/21 03:06:23];c:\program files\hewlett-packard\media\dvd\000.fcl [2008-11-29 87536]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_805f33de\AEstSrv.exe [2009-1-21 77824]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 921936]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-2-19 365952]
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\hewlett-packard\media\tv\kernel\tv\TVCapSvc.exe [2008-11-27 296320]
R2 TVSched;TV Task Scheduler (TVTS);c:\program files\hewlett-packard\media\tv\kernel\tv\TVSched.exe [2008-11-27 116096]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-11-18 599344]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-9-4 54784]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-1-21 22072]
S2 gupdate1c9e16bff8dc080;Google Update Service (gupdate1c9e16bff8dc080);c:\program files\google\update\GoogleUpdate.exe [2009-5-30 133104]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-2-19 222512]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-18 33176]
S3 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-19 19456]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-10-23 107360]

=============== Created Last 30 ================

2009-07-02 00:30--d-----c:\program files\common files\Wise Installation Wizard
2009-07-02 00:17--d-----c:\program files\Trend Micro
2009-07-02 00:16206,178,511a-------c:\windows\MEMORY.DMP
2009-07-01 23:5815,688a-------c:\windows\system32\lsdelete.exe
2009-07-01 21:1764,160a-------c:\windows\system32\drivers\Lbd.sys
2009-07-01 21:17-cd-h---c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-01 21:17-cd-h---c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-01 21:17--d-----c:\program files\Lavasoft
2009-07-01 13:42--d-----c:\users\guilla~1\appdata\roaming\.clamwin
2009-07-01 13:41--d-----c:\programdata\.clamwin
2009-07-01 13:41--d-----c:\program files\ClamWin
2009-07-01 13:41--d-----c:\progra~2\.clamwin
2009-06-30 14:57107,368a-------c:\windows\system32\GEARAspi.dll
2009-06-30 14:5715,464a-------c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-30 14:57--d-----c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-30 14:57--d-----c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-30 12:57--d-----c:\users\guilla~1\appdata\roaming\Symantec
2009-06-30 12:49--d-----c:\program files\common files\Symantec Shared
2009-06-25 17:15--d-----c:\programdata\AVS4YOU
2009-06-25 17:15--d-----c:\progra~2\AVS4YOU
2009-06-25 17:15--d-----c:\users\guilla~1\appdata\roaming\AVS4YOU
2009-06-25 17:12974,848a-------c:\windows\system32\mfc70.dll
2009-06-25 17:12487,424a-------c:\windows\system32\msvcp70.dll
2009-06-25 17:12344,064a-------c:\windows\system32\msvcr70.dll
2009-06-25 17:12--d-----c:\program files\common files\AVSMedia
2009-06-25 17:121,700,352a-------c:\windows\system32\GdiPlus.dll
2009-06-25 17:1224,576a-------c:\windows\system32\msxml3a.dll
2009-06-25 17:12--d-----c:\program files\AVS4YOU
2009-06-24 10:36--d-----c:\users\guillaume\group
2009-06-21 16:43--d-----C:\mwdumper
2009-06-21 01:382,412,042a-------C:\mwdumper.jar
2009-06-17 22:34--d-----c:\users\guilla~1\appdata\roaming\Mozilla Embedded Browser
2009-06-17 18:12--d-----C:\Downloads
2009-06-14 13:5986,096a-------c:\windows\system32\php_mysqli.dll
2009-06-14 13:5945,135a-------c:\windows\system32\php_mysql.dll
2009-06-09 16:01--d-----C:\php5
2009-06-08 23:00--d-----c:\program files\Microsoft Visual Studio 8
2009-06-07 16:38--d-----c:\programdata\Lavasoft
2009-06-07 13:48--d-----c:\users\guillaume\Grupo
2009-06-06 11:23--d-----c:\users\guilla~1\appdata\roaming\Software
2009-06-06 11:23--d-----c:\program files\Quest Software
2009-06-06 11:23--d-----c:\program files\common files\Quest Shared
2009-06-05 20:43--d-----C:\wamp
2009-06-04 11:52--d-----c:\programdata\muvee Technologies
2009-06-02 15:09--d-----c:\users\guillaume\Divers
2009-06-02 11:54--d-----c:\users\guilla~1\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-06-02 10:46--d-----c:\users\guilla~1\appdata\roaming\SolidDocuments
2009-06-02 10:4513,560a-------c:\windows\system32\solidlocalui.dll
2009-06-02 10:4521,240a-------c:\windows\system32\solidlocalmon.dll
2009-06-02 10:44--d-----c:\programdata\SolidDocuments
2009-06-02 10:44--d-----c:\progra~2\SolidDocuments

==================== Find3M ====================

2009-07-01 12:1786,016a-------c:\windows\inf\infstrng.dat
2009-07-01 12:1786,016a-------c:\windows\inf\infstor.dat
2009-07-01 12:1751,200a-------c:\windows\inf\infpub.dat
2009-05-18 14:182,076,672a-------c:\windows\system32\libmysql.dll
2009-05-16 10:2598,304a-------c:\windows\system32\CmdLineExt.dll
2009-05-14 04:160a--SHR--c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF9143YJF_E517901-371_4A_I3600_SHP_V98.32_F.23_T090105_WV3-1_L409_M3069_J320_
7AMD_8F31_92.20_#090121_N10EC8168;168C001C_(NU324PA#ACJ)_XMOBILE_CN10_Z_2Rev 1.MRK
2009-05-01 20:303,366,912a-------c:\windows\system32\GPhotos.scr
2009-03-25 14:137,100,928a-------c:\program files\PocketDivXEncoder_0.3.96.exe
2009-01-21 13:00665,600a-------c:\windows\inf\drvindex.dat
2008-01-21 04:43174a--sh---c:\program files\desktop.ini
2006-11-02 14:42287,440a-------c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 14:42287,440a-------c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 14:4230,674a-------c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 14:4230,674a-------c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 11:20287,440a-------c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20287,440a-------c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:2030,674a-------c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:2030,674a-------c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 1:06:30.45 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 21-01-2009 11:19:10
System Uptime: 07-02-2009 00:41:30 (3481 hours ago)

Motherboard: HP | | 3600
Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-74 | Socket M2/S1G1 | 2200/1800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 287 GiB total, 86.189 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.857 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP26: 18-05-2009 16:52:24 - Installed MySQL Server 5.1
RP27: 18-05-2009 17:18:17 - Removed MySQL Server 5.1
RP28: 18-05-2009 19:05:39 - Installed MySQL Server 5.1
RP29: 18-05-2009 19:08:52 - Removed MySQL Server 5.1
RP30: 18-05-2009 21:23:52 - Windows Update
RP31: 19-05-2009 21:18:33 - Installed AVG Free 8.5
RP36: 20-05-2009 15:11:18 - Windows Update
RP37: 20-05-2009 22:26:05 - Installed MySQL Server 5.1
RP38: 20-05-2009 22:30:12 - Removed MySQL Server 5.1
RP39: 21-05-2009 08:58:04 - Windows Update
RP40: 24-05-2009 15:41:14 - Scheduled Checkpoint
RP41: 25-05-2009 19:53:23 - Windows Update
RP42: 26-05-2009 11:12:03 - Installed Opera 9.64
RP43: 26-05-2009 12:03:07 - Installed MySQL Server 5.1
RP44: 28-05-2009 16:07:30 - Windows Update
RP45: 28-05-2009 16:23:53 - Windows Update
RP48: 29-05-2009 11:21:15 - Installed Apache HTTP Server 2.0.63
RP49: 30-05-2009 15:04:57 - Scheduled Checkpoint
RP50: 01-06-2009 12:54:18 - Scheduled Checkpoint
RP51: 02-06-2009 09:59:08 - Windows Update
RP52: 02-06-2009 11:57:34 - Removed Solid Converter PDF v4
RP53: 02-06-2009 12:03:56 - Removed Adobe Reader 9.
RP54: 02-06-2009 12:09:10 - Installed Adobe Reader 8.1.0
RP55: 02-06-2009 12:19:45 - Removed Adobe Reader 8.1.0
RP56: 02-06-2009 12:26:42 - Removed Acrobat.com
RP127: 02-07-2009 00:40:23 - Restore Operation

==== Installed Programs ======================

Acrobat.com
ActiveCheck component for HP Active Support Library
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1.1
Adobe Shockwave Player
Agere Systems HDA Modem
AMD USB Audio Driver Filter
Atheros Driver Installation Program
ATI Catalyst Install Manager
Caesar IV
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
ClamWin Free Antivirus 0.95.2
CyberLink DVD Suite
DigitalPersona Personal 4.0
ESU for Microsoft Vista
FileZilla CLIENT 3.2.4.1
GearDrvs
Google Chrome
Google Earth
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Common Access Service Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Help and Support
HP Integrated Module with Bluetooth wireless technology 6.0.1.6204
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart SmartMenu
HP MediaSmart TV
HP MediaSmart Webcam
HP MULTIPLE MODEM INSTALLER for VISTA
HP Quick Launch Buttons 6.40 L1
HP Total Care Advisor
HP Total Care Setup
HP Update
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
IDT Audio
Java(TM) 6 Update 7
JMicron JMB38X Flash Media Controller Driver
LabelPrint
LightScribe System Software 1.14.17.1
Microsoft .NET Framework 3.5 SP1
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Mozilla Firefox (3.0.11)
MSXML 4.0 SP2 (KB954430)
My HP Games
MySQL Server 5.1
Norton Internet Security
Nvu 1.0PR
Opera 9.64
PHP 5.2.9-2
Picasa 3
Power2Go
PowerDirector
ProtectSmart Hard Drive Protection
Quest Software Toad for MySQL Freeware 4.1
Realtek 8169 8168 8101E 8102E Ethernet Driver
Skins
Skype™ 4.0
Synaptics Pointing Device Driver
Validity Sensors software
VLC media player 0.9.9
WampServer 2.0
Windows Driver Package - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)
WinRAR archiver

==== Event Viewer Messages From Past Week ========

30-06-2009 21:16:57, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LiveUpdate Notice service.
30-06-2009 21:16:27, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the CLTNetCnService service.
30-06-2009 21:15:57, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ccSetMgr service.
30-06-2009 21:15:27, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ccEvtMgr service.
30-06-2009 14:33:19, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer hp psc 1300 series with shared resource name hp psc 1300 series. Error 2114. The printer cannot be used by others on the network.
30-06-2009 14:33:07, Error: Service Control Manager [7022] - The IPsec Policy Agent service hung on starting.
30-06-2009 14:30:21, Error: EventLog [6008] - The previous system shutdown at 14:21:55 on 30-06-2009 was unexpected.
29-06-2009 23:05:02, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0.
29-06-2009 10:44:45, Error: Service Control Manager [7000] - The AVG Free On-access Scanner Minifilter Driver x86 service failed to start due to the following error: The system cannot find message text for message number 0xAVG Free On-access Scanner Minifilter Driver x86 in the message file for The system cannot find message text for message number 0x%1 in the message file for %2..
29-06-2009 10:44:43, Error: Service Control Manager [7000] - The AVG Free AVI Loader Driver x86 service failed to start due to the following error: The system cannot find message text for message number 0xAVG Free AVI Loader Driver x86 in the message file for The system cannot find message text for message number 0x%1 in the message file for %2..
27-06-2009 22:17:05, Error: EventLog [6008] - The previous system shutdown at 22:10:26 on 27-06-2009 was unexpected.
26-06-2009 10:38:11, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.34 for the Network Card with network address 00242C2F27B4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
25-06-2009 22:35:15, Error: EventLog [6008] - The previous system shutdown at 22:29:40 on 25-06-2009 was unexpected.
25-06-2009 12:52:30, Error: Microsoft-Windows-ResourcePublication [1002] - Element Provider\Microsoft.Base.Publication/Publication/Computer failed to publish. Ensure that both PKEY_PUBSVCS_METADATA and PKEY_PUBSVCS_TYPE are set properly on the function instance and there were no errors adding the function instance.
25-06-2009 12:52:28, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.33 for the Network Card with network address 00242C2F27B4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
25-06-2009 09:47:17, Error: PlugPlayManager [12] - The device 'JMB38X xD Host Controller' (PCI\VEN_197B&DEV_2384&SUBSYS_3600103C&REV_00\4&2c5d624a&0&0450) disappeared from the system without first being prepared for removal.
25-06-2009 09:47:17, Error: PlugPlayManager [12] - The device 'JMB38X SD/MMC Host Controller' (PCI\VEN_197B&DEV_2382&SUBSYS_3600103C&REV_00\4&2c5d624a&0&0150) disappeared from the system without first being prepared for removal.
25-06-2009 09:47:17, Error: PlugPlayManager [12] - The device 'JMB38X SD Host Controller' (PCI\VEN_197B&DEV_2381&SUBSYS_3600103C&REV_00\4&2c5d624a&0&0250) disappeared from the system without first being prepared for removal.
25-06-2009 09:47:17, Error: PlugPlayManager [12] - The device 'JMB38X MS Host Controller' (PCI\VEN_197B&DEV_2383&SUBSYS_3600103C&REV_00\4&2c5d624a&0&0350) disappeared from the system without first being prepared for removal.
25-06-2009 09:47:05, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
02-07-2009 00:34:16, Error: EventLog [6008] - The previous system shutdown at 00:32:57 on 02-07-2009 was unexpected.
02-07-2009 00:32:30, Error: EventLog [6008] - The previous system shutdown at 00:30:20 on 02-07-2009 was unexpected.
02-07-2009 00:21:29, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
02-07-2009 00:17:50, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
02-07-2009 00:17:49, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
02-07-2009 00:17:15, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
02-07-2009 00:17:15, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
02-07-2009 00:17:14, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
02-07-2009 00:17:13, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
02-07-2009 00:17:05, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
02-07-2009 00:16:48, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
02-07-2009 00:16:48, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
02-07-2009 00:16:42, Error: EventLog [6008] - The previous system shutdown at 00:14:15 on 02-07-2009 was unexpected.
01-07-2009 21:17:31, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
01-07-2009 13:32:19, Error: Service Control Manager [7023] - The Secure Socket Tunneling Protocol Service service terminated with the following error: The RPC server is unavailable.
01-07-2009 13:32:19, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The RPC server is unavailable.
01-07-2009 12:16:04, Error: Service Control Manager [7031] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
01-07-2009 12:16:04, Error: Service Control Manager [7031] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service.

==== End Of File ===========================


Thanks in advance for helping me out here.Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
mURLSearchHooks: H - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TCP: NameServer = 85.255.112.68,85.255.112.66
TCP: {0ECBD136-23E9-41FE-8373-11C4F97608E6} = 85.255.112.68,85.255.112.66
TCP: {9737D2AB-68FA-4999-B25B-0AF3DAF71C2D} = 85.255.112.68,85.255.112.66

Folder::
c:\program files\avg

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.
Sorry, forgot this.

Download Security Check from one of the following links and save it to your Desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.[/list]

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

----------

Also let me know what antivirus you prefer to use. I see ClamWin and Norton but it looks like Norton isn't running.Hi,


Thanks for the quick reply.

I am using ClamWin now.

The log after running ComboFIx is here:


ComboFix 09-07-01.01 - Guillaume 02-07-2009 1:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.91.1033.18.3069.2062 [GMT 2:00]
Running from: c:\users\Guillaume\Desktop\ComboFix1.exe
Command switches used :: c:\users\Guillaume\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\gxvxcoxyqisirdbgrshqltjfqpnppynxitbow.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxckvcnewtfoyxnwodiwnsxjpnofqpdpnuw.dll
c:\windows\system32\gxvxcxtsvyvnqvjtubxrlrdhegupcxbdluvhf.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
D:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GXVXCSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.

2009-07-02 00:18 . 2009-07-02 00:18--------d-----w-c:\users\Guillaume\AppData\Local\temp
2009-07-01 23:41 . 2009-07-01 23:41410984----a-w-c:\windows\system32\deploytk.dll
2009-07-01 22:30 . 2009-07-01 22:30--------d-----w-c:\program files\Common Files\Wise Installation Wizard
2009-07-01 22:17 . 2009-07-01 22:17--------d-----w-c:\program files\Trend Micro
2009-07-01 21:58 . 2009-01-18 21:3515688----a-w-c:\windows\system32\lsdelete.exe
2009-07-01 19:17 . 2009-01-18 21:3064160----a-w-c:\windows\system32\drivers\Lbd.sys
2009-07-01 19:17 . 2009-07-01 19:17--------dc-h--w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-01 19:17 . 2009-01-18 21:432892112-c--a-w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-07-01 19:17 . 2009-07-01 19:17--------d-----w-c:\program files\Lavasoft
2009-07-01 11:42 . 2009-07-01 11:48--------d-----w-c:\users\Guillaume\AppData\Roaming\.clamwin
2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\programdata\.clamwin
2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\program files\ClamWin
2009-06-30 12:57 . 2008-04-17 11:1215464----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-30 12:57 . 2008-04-17 11:12107368----a-w-c:\windows\system32\GEARAspi.dll
2009-06-30 12:57 . 2009-06-30 12:57--------d-----w-c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-06-30 10:57 . 2009-07-01 07:40--------d-----w-c:\users\Guillaume\AppData\Roaming\Symantec
2009-06-30 10:49 . 2009-07-01 11:31--------d-----w-c:\program files\Common Files\Symantec Shared
2009-06-30 09:08 . 2009-06-30 09:08--------d-----w-c:\users\Public\InOut
2009-06-29 21:20 . 2009-06-29 21:20680----a-w-c:\users\Guillaume\AppData\Local\d3d9caps.dat
2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\programdata\AVS4YOU
2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\users\Guillaume\AppData\Roaming\AVS4YOU
2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\Common Files\AVSMedia
2009-06-25 15:12 . 2003-05-21 21:50344064----a-w-c:\windows\system32\msvcr70.dll
2009-06-25 15:12 . 2002-01-05 12:48974848----a-w-c:\windows\system32\mfc70.dll
2009-06-25 15:12 . 2002-01-05 11:40487424----a-w-c:\windows\system32\msvcp70.dll
2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\AVS4YOU
2009-06-25 15:12 . 2008-07-11 09:521700352----a-w-c:\windows\system32\GdiPlus.dll
2009-06-25 15:12 . 2003-05-21 21:5024576----a-w-c:\windows\system32\msxml3a.dll
2009-06-24 08:36 . 2009-06-25 11:14--------d-----w-c:\users\Guillaume\group
2009-06-21 14:43 . 2009-06-21 14:43--------d-----w-C:\mwdumper
2009-06-17 20:34 . 2009-06-22 17:55--------d-----w-c:\users\Guillaume\AppData\Roaming\Mozilla Embedded Browser
2009-06-17 16:12 . 2009-06-24 15:20--------d-----w-C:\Downloads
2009-06-15 12:58 . 2009-06-15 12:58--------d-----w-c:\users\Guillaume\AppData\Local\Quest Software
2009-06-14 11:59 . 2009-04-09 06:2586096----a-w-c:\windows\system32\php_mysqli.dll
2009-06-14 11:59 . 2009-04-09 06:2545135----a-w-c:\windows\system32\php_mysql.dll
2009-06-09 14:01 . 2009-06-09 14:01--------d-----w-C:\php5
2009-06-08 21:03 . 2009-06-08 21:03--------d-----w-c:\program files\Microsoft Works
2009-06-08 21:00 . 2009-06-08 21:00--------d-----w-c:\program files\Microsoft Visual Studio 8
2009-06-08 20:59 . 2009-06-08 20:59--------d-----w-c:\users\Guillaume\AppData\Local\Microsoft Help
2009-06-08 20:58 . 2009-06-08 20:58--------d--h--r-C:\MSOCache
2009-06-08 20:39 . 2009-06-08 20:39--------d-----w-c:\users\Guillaume\AppData\Local\Seven Zip
2009-06-07 14:38 . 2009-07-01 19:17--------d-----w-c:\programdata\Lavasoft
2009-06-07 14:32 . 2009-06-07 14:32--------d-----w-c:\windows\Sun
2009-06-07 11:48 . 2009-06-07 11:53--------d-----w-c:\users\Guillaume\Grupo
2009-06-06 09:23 . 2009-06-06 09:233584----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\IconTmpl7.15B59236_99D3_4DBB_BC63_B5BF7D73F468.exe
2009-06-06 09:23 . 2009-06-06 09:23244224----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\Icon8EEA8E04.exe
2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\users\Guillaume\AppData\Roaming\Software
2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Common Files\Quest Shared
2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Quest Software
2009-06-05 18:43 . 2009-06-09 15:50--------d-----w-C:\wamp
2009-06-04 09:52 . 2009-06-04 09:52--------d-----w-c:\programdata\muvee Technologies
2009-06-04 09:51 . 2009-06-04 09:52--------d-----w-c:\users\Guillaume\AppData\Roaming\muvee Technologies
2009-06-02 13:09 . 2009-06-29 11:41--------d-----w-c:\users\Guillaume\Divers
2009-06-02 11:38 . 2009-06-02 11:38--------d-----w-c:\program files\Common Files\Adobe AIR
2009-06-02 10:09 . 2009-06-02 11:37--------d-----w-c:\program files\Common Files\Adobe
2009-06-02 09:54 . 2009-06-02 09:54--------d-----w-c:\users\Guillaume\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-06-02 08:46 . 2009-06-02 08:50--------d-----w-c:\users\Guillaume\AppData\Roaming\SolidDocuments
2009-06-02 08:45 . 2008-08-01 16:3213560----a-w-c:\windows\system32\solidlocalui.dll
2009-06-02 08:45 . 2008-08-01 16:3221240----a-w-c:\windows\system32\solidlocalmon.dll
2009-06-02 08:44 . 2009-06-02 08:44--------d-----w-c:\programdata\SolidDocuments

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 23:57 . 2009-01-21 10:1812----a-w-c:\windows\bthservsdp.dat
2009-07-01 23:41 . 2009-02-19 11:40--------d-----w-c:\program files\Java
2009-07-01 11:31 . 2009-02-19 09:35--------d-----w-c:\programdata\Symantec
2009-06-29 22:28 . 2009-02-19 10:26--------d-----w-c:\program files\Microsoft SQL Server
2009-06-29 22:24 . 2009-02-19 10:23--------d-----w-c:\program files\Microsoft.NET
2009-06-29 22:12 . 2009-05-26 17:09--------d-----w-c:\users\Guillaume\AppData\Roaming\NuSphere
2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\programdata\WildTangent
2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\program files\HP Games
2009-06-23 16:00 . 2009-05-22 11:29--------d-----w-c:\users\Guillaume\AppData\Roaming\CyberLink
2009-06-20 18:12 . 2009-05-26 11:00--------d-----w-c:\users\Guillaume\AppData\Roaming\DBDesigner4
2009-06-19 13:00 . 2009-05-18 12:02--------d-----w-c:\program files\PHP
2009-06-17 19:54 . 2009-06-01 08:32--------d-----w-c:\users\Guillaume\AppData\Roaming\Skype
2009-06-17 19:40 . 2009-06-01 08:45--------d-----w-c:\users\Guillaume\AppData\Roaming\skypePM
2009-06-08 21:45 . 2009-05-14 02:20104560----a-w-c:\users\Guillaume\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-08 21:06 . 2009-02-19 10:21--------d-----w-c:\programdata\Microsoft Help
2009-06-08 21:03 . 2006-11-02 12:37--------d-----w-c:\program files\MSBuild
2009-06-08 08:26 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Hewlett-Packard
2009-06-08 08:25 . 2009-02-19 09:33--------d-----w-c:\programdata\Hewlett-Packard
2009-06-07 17:07 . 2009-05-31 20:18--------d-----w-c:\users\Guillaume\AppData\Roaming\FileZilla
2009-06-03 13:47 . 2009-02-19 09:32--------d--h--w-c:\program files\InstallShield Installation Information
2009-06-02 10:25 . 2009-05-19 19:41--------d-----w-c:\program files\File Recover
2009-06-01 08:45 . 2009-06-01 08:4556---ha-w-c:\windows\system32\ezsidmv.dat
2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\program files\Common Files\Skype
2009-06-01 08:32 . 2009-06-01 08:32--------d-----r-c:\program files\Skype
2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\programdata\Skype
2009-05-31 20:18 . 2009-05-31 20:18--------d-----w-c:\program files\FileZilla FTP Client
2009-05-30 21:18 . 2009-05-15 03:52--------d-----w-c:\program files\Google
2009-05-28 20:00 . 2009-05-28 20:00--------d-----w-c:\program files\EASEUS
2009-05-28 18:02 . 2009-02-19 12:35--------d-----w-c:\program files\SMINST
2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\Common Files\fabFORCE
2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\fabFORCE
2009-05-26 10:03 . 2009-05-26 10:03--------d-----w-c:\programdata\MySQL
2009-05-26 09:12 . 2009-05-26 09:12--------d-----w-c:\program files\Opera
2009-05-25 23:40 . 2009-05-25 22:13--------d-----w-c:\users\Guillaume\AppData\Roaming\vlc
2009-05-25 22:12 . 2009-05-25 22:12--------d-----w-c:\program files\VideoLAN
2009-05-20 21:09 . 2009-02-19 09:35--------d-----w-c:\programdata\Norton
2009-05-19 19:34 . 2009-05-19 19:34--------d-----w-c:\programdata\ParetoLogic
2009-05-19 19:33 . 2009-05-19 19:33--------d-----w-c:\programdata\Cached Installations
2009-05-19 19:19 . 2009-05-19 19:19--------d-----w-c:\program files\AVG
2009-05-19 09:06 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
2009-05-18 19:26 . 2009-05-18 19:26--------d-----w-c:\program files\MSXML 4.0
2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\programdata\NOS
2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\program files\NOS
2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\users\Guillaume\AppData\Roaming\Nvu
2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\program files\Nvu
2009-05-18 12:18 . 2009-05-29 10:152076672----a-w-c:\windows\system32\libmysql.dll
2009-05-17 06:24 . 2009-05-17 06:24--------d-----w-c:\program files\Western Digital Corporation
2009-05-16 15:39 . 2009-05-16 15:390----a-w-c:\windows\nsreg.dat
2009-05-16 08:25 . 2009-05-16 08:25--------d--h--r-c:\users\Guillaume\AppData\Roaming\SecuROM
2009-05-16 08:25 . 2009-05-16 08:2598304----a-w-c:\windows\system32\CmdLineExt.dll
2009-05-16 08:14 . 2009-05-16 08:14--------d-----w-c:\program files\Sierra
2009-05-16 08:11 . 2009-05-16 08:11--------d-----w-c:\users\Guillaume\AppData\Roaming\InstallShield
2009-05-15 03:53 . 2009-05-15 03:53--------d-----w-c:\program files\Common Files\PX Storage Engine
2009-05-14 02:55 . 2009-05-14 02:55--------d-----w-c:\users\Guillaume\AppData\Roaming\WildTangent
2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Macrovision
2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\ATI
2009-05-14 02:51 . 2009-05-14 02:51--------d-----w-c:\users\Guillaume\AppData\Roaming\DigitalPersona
2009-05-14 02:18 . 2009-05-14 02:18--------d-----w-c:\users\Guillaume\AppData\Roaming\HP TCS
2009-05-14 02:18 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Sidebar
2009-05-14 02:16 . 2009-05-14 02:160--sha-r-c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF9143YJF_E517901-371_4A_I3600_SHP_V98.32_F.23_T090105_WV3-1_L409_M3069_J320_7AMD_8F31_92.20_#090121_N10EC8168;168C001C_(NU324PA#ACJ)_XMOBILE_CN10_Z_2Rev 1.MRK
2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr
2009-03-25 12:13 . 2009-05-15 03:357100928----a-w-c:\program files\PocketDivXEncoder_0.3.96.exe
2009-02-19 10:47 . 2009-02-19 10:338192--sha-w-c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-12-11 842816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-01 148888]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification PackagesREG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E6DB3961-07E4-45A0-AA3C-F3B3B7F4F9F7}"= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{353CF60D-E2AD-4F09-B76F-C1CDD3478789}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe:HP TouchSmart Music
"{4AA41B04-FF93-4B2D-A7A8-6DA731383642}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe:HP TouchSmart Photo
"{3A5169F5-3859-4E6E-BB92-5B35B8C6911B}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe:HP TouchSmart Video
"{BC92971A-983D-4974-88A3-576F943534BC}"= c:\program files\Hewlett-Packard\Media\DVD\TSMAgent.exe:HP TouchSmart Media Resident Program
"{A7467990-D655-4E94-80E7-FA9E8BA1E3FA}"= c:\program files\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
"{A00F1E0E-FBE5-4BB6-97FB-380E719F92E5}"= c:\program files\Hewlett-Packard\Media\DVD\HPDVDSmart.exe:HP MediaSmart DVD
"{6F13DC25-28CE-42DB-ABD0-5682B2024A79}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe:HP TouchSmart Music
"{67D587A5-DEB8-4A93-B3B1-3226CAB96983}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe:HP TouchSmart Photo
"{94801C04-866B-4BF4-A902-F4195C37EA9B}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe:HP TouchSmart Video
"{8B4BBE2F-DFEB-4EA4-BCC8-2734E5E8A9FB}"= c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe:HP TouchSmart Media Resident Program
"{92E60A91-51C1-4153-914B-020EE33F6C60}"= c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
"{535552D7-2F2E-457A-A653-B94E417C029B}"= c:\program files\Hewlett-Packard\Media\TV\QP.exe:Quick Play
"{445E2C51-CF0E-4F90-83EB-C1903B572927}"= c:\program files\Hewlett-Packard\Media\TV\QPService.exe:Quick Play Resident Program
"TCP Query User{6B46CD09-8566-434F-A3FF-CBDA4B0B7331}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{C11FEE4C-5B54-453A-83D4-25941667E24E}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{844E49C1-FDE0-4617-8D07-9CE36D1BF429}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{EB116974-69E3-4B3F-8A6A-A7CCDB2A6FCA}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{8F9629FE-2EC6-4DB4-B73F-DE5398BD5FA1}"= UDP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server
"{809437AF-EDE8-42B0-AB49-89B0183A1352}"= TCP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server
"{9D1960D7-5A1C-451F-9530-A2A63A482EE7}"= UDP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener
"{125EECFC-463C-41F6-99FD-F26D456CF288}"= TCP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener
"{C420771C-6514-4124-9253-5143600D9699}"= UDP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser
"{4C5C4A73-C523-4639-AA30-079FF741791B}"= TCP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser
"{0858C917-6AE0-47FD-9220-529AC026C79A}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{2ABB040C-C949-4C0A-99A1-698D45CF9014}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{0F855C04-E7EE-4B44-AE86-C5E8541D7566}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{640C01A5-F4AC-47DF-8372-C676D3CE567E}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= UDP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG
"UDP Query User{29EC753F-84F2-48F1-8170-B813D5537431}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= TCP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG
"TCP Query User{79D3A5C4-4E33-4AF6-BF9E-375EC79BEB93}c:\\program files\\nusphere\\phped\\srv.exe"= UDP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server
"UDP Query User{08869455-D764-4AAD-823E-A744B1FDA516}c:\\program files\\nusphere\\phped\\srv.exe"= TCP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server
"{1B779A5F-1F93-4A92-8729-18090A1ECBA2}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{C16D5914-BA67-4BE6-B6E9-E7790E83F72C}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{6797A88C-F4AD-4568-A9B5-5B435E0C06E8}"= c:\program files\Skype\Phone\Skype.exe:Skype

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [01-07-2009 21:17 64160]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/01/21 03:06];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [29-11-2008 04:04 87536]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe [21-01-2009 12:29 77824]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18-01-2009 23:34 921936]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [19-02-2009 14:35 365952]
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [27-11-2008 03:13 296320]
R2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [27-11-2008 03:13 116096]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [18-11-2008 16:09 599344]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [04-09-2008 19:47 54784]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [21-01-2009 12:33 22072]
S2 gupdate1c9e16bff8dc080;Google Update Service (gupdate1c9e16bff8dc080);c:\program files\Google\Update\GoogleUpdate.exe [30-05-2009 23:17 133104]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [19-02-2009 11:49 222512]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [18-05-2009 19:49 33176]
S3 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19-03-2008 02:24 19456]
S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [23-10-2008 11:42 107360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcsREG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-07-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:34]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16]

2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003Core.job
- c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16]

2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003UA.job
- c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-ares - c:\program files\Ares\Ares.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Guillaume\AppData\Roaming\Mozilla\Firefox\Profiles\7epg4avp.default\
FF - component: c:\program files\DigitalPersona\Bin\firefoxext\components\dpffcli.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\Guillaume\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 02:18
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\mysql\bin\mysqld\" --defaults-file=\"c:\mysql\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3809033370-1981303550-699846253-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a5,c6,03,b0,fe,da,19,0e,13,6f,1d,be,81,54,7e,02,98,7a,e5,db,eb,9e,6e,
b8,0d,f4,3e,c1,a9,b2,25,b3,df,5f,35,0d,bb,d1,a9,20,18,46,31,f0,11,60,81,fe,\
"??"=hex:03,ed,aa,f5,c2,c1,45,25,6f,40,71,e2,b3,45,2f,79

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\DPPWDFLT.dll
.
Completion time: 2009-07-02 2:20
ComboFix-quarantined-files.txt 2009-07-02 00:20

Pre-Run: 92,222,681,088 bytes free
Post-Run: 92,724,477,952 bytes free

298--- E O F ---2009-06-02 07:59


and the checkup.txt :


Results of screen317's Security Check version 0.98.4
Windows Vista Service Pack 1
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:
``````````````````````````````

Windows Firewall Enabled!
ClamWinFreeAntivirus0.95.2
NortonInternetSecurity
ECHO is off.
``````````````````````````````
Anti-malware/Other Utilities Check:
``````````````````````````````

Ad-Aware
Java(TM) 6 Update 14
Java(TM) 6 Update 7
Out of date Java installed!
Adobe Flash Player 10
``````````````````````````````
Process Check:
objlist.exe by Laurent
``````````````````````````````

Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
``````````````````````````````
DNS Vulnerability Check:
``````````````````````````````


Scan took 3517 seconds.
`````````End of Log```````````




ClamWin is a good antivirus scanner but it offers no real-time blocking so you need to install an actual real-time antivirus ASAP.

Please do this while I am looking over the ComboFix log.

Go to Add or Remove Programs and uninstall: NortonInternetSecurity

Also make sure Java(TM) 6 Update 7 is NOT still there. If so please uninstall it also.

---

Next:

Download the Norton Removal Tool (SymNRT) to your desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the 'Norton_Removal_Tool' and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC.
  • Delete the 'Norton_Removal_Tool' from your desktop.
.
----------

Looking at the ComboFix log now....
Sorry, I keep forgetting to finish what I start. I sometimes know what I'm doing.

Before we continue download and install a free antivirus.

Remember to only install one antivirus!

1) Avast! Home Free Edition
2) AVG Free Edition
3) Avira AntiVir Personal

Be back with more instructions after finishing the ComboFix log.
OK. Here we go.

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

----------

If you already have Malwarebytes be sure to update it before running the scan!

Download Malwarebytes' Anti-Malware (MBAM)

Alternate MBAM download link

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Also let me know how the computer is running now.

    .Hi

    Here is the new ComboFix log.


    ComboFix 09-07-01.01 - Guillaume 02-07-2009 10:37.2 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.91.1033.18.3069.2003 [GMT 2:00]
    Running from: c:\users\Guillaume\Desktop\ComboFix1.exe
    Command switches used :: c:\users\Guillaume\Desktop\CFScript.txt
    SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
    .

    2009-07-02 08:41 . 2009-07-02 08:43--------d-----w-c:\users\Guillaume\AppData\Local\temp
    2009-07-01 22:30 . 2009-07-01 22:30--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-07-01 22:17 . 2009-07-01 22:17--------d-----w-c:\program files\Trend Micro
    2009-07-01 21:58 . 2009-01-18 21:3515688----a-w-c:\windows\system32\lsdelete.exe
    2009-07-01 19:17 . 2009-01-18 21:3064160----a-w-c:\windows\system32\drivers\Lbd.sys
    2009-07-01 19:17 . 2009-07-01 19:17--------dc-h--w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
    2009-07-01 19:17 . 2009-01-18 21:432892112-c--a-w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
    2009-07-01 19:17 . 2009-07-01 19:17--------d-----w-c:\program files\Lavasoft
    2009-07-01 11:42 . 2009-07-01 11:48--------d-----w-c:\users\Guillaume\AppData\Roaming\.clamwin
    2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\programdata\.clamwin
    2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\program files\ClamWin
    2009-06-30 12:57 . 2008-04-17 11:1215464----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
    2009-06-30 12:57 . 2008-04-17 11:12107368----a-w-c:\windows\system32\GEARAspi.dll
    2009-06-30 12:57 . 2009-06-30 12:57--------d-----w-c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2009-06-30 10:57 . 2009-07-02 08:23--------d-----w-c:\users\Guillaume\AppData\Roaming\Symantec
    2009-06-30 10:49 . 2009-07-02 08:23--------d-----w-c:\program files\Common Files\Symantec Shared
    2009-06-30 09:08 . 2009-06-30 09:08--------d-----w-c:\users\Public\InOut
    2009-06-29 21:20 . 2009-06-29 21:20680----a-w-c:\users\Guillaume\AppData\Local\d3d9caps.dat
    2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\programdata\AVS4YOU
    2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\users\Guillaume\AppData\Roaming\AVS4YOU
    2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\Common Files\AVSMedia
    2009-06-25 15:12 . 2003-05-21 21:50344064----a-w-c:\windows\system32\msvcr70.dll
    2009-06-25 15:12 . 2002-01-05 12:48974848----a-w-c:\windows\system32\mfc70.dll
    2009-06-25 15:12 . 2002-01-05 11:40487424----a-w-c:\windows\system32\msvcp70.dll
    2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\AVS4YOU
    2009-06-25 15:12 . 2008-07-11 09:521700352----a-w-c:\windows\system32\GdiPlus.dll
    2009-06-25 15:12 . 2003-05-21 21:5024576----a-w-c:\windows\system32\msxml3a.dll
    2009-06-24 08:36 . 2009-06-25 11:14--------d-----w-c:\users\Guillaume\group
    2009-06-21 14:43 . 2009-06-21 14:43--------d-----w-C:\mwdumper
    2009-06-17 20:34 . 2009-06-22 17:55--------d-----w-c:\users\Guillaume\AppData\Roaming\Mozilla Embedded Browser
    2009-06-17 16:12 . 2009-06-24 15:20--------d-----w-C:\Downloads
    2009-06-15 12:58 . 2009-06-15 12:58--------d-----w-c:\users\Guillaume\AppData\Local\Quest Software
    2009-06-14 11:59 . 2009-04-09 06:2586096----a-w-c:\windows\system32\php_mysqli.dll
    2009-06-14 11:59 . 2009-04-09 06:2545135----a-w-c:\windows\system32\php_mysql.dll
    2009-06-09 14:01 . 2009-06-09 14:01--------d-----w-C:\php5
    2009-06-08 21:03 . 2009-06-08 21:03--------d-----w-c:\program files\Microsoft Works
    2009-06-08 21:00 . 2009-06-08 21:00--------d-----w-c:\program files\Microsoft Visual Studio 8
    2009-06-08 20:59 . 2009-06-08 20:59--------d-----w-c:\users\Guillaume\AppData\Local\Microsoft Help
    2009-06-08 20:58 . 2009-06-08 20:58--------d--h--r-C:\MSOCache
    2009-06-08 20:39 . 2009-06-08 20:39--------d-----w-c:\users\Guillaume\AppData\Local\Seven Zip
    2009-06-07 14:38 . 2009-07-01 19:17--------d-----w-c:\programdata\Lavasoft
    2009-06-07 14:32 . 2009-06-07 14:32--------d-----w-c:\windows\Sun
    2009-06-07 11:48 . 2009-06-07 11:53--------d-----w-c:\users\Guillaume\Grupo
    2009-06-06 09:23 . 2009-06-06 09:233584----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\IconTmpl7.15B59236_99D3_4DBB_BC63_B5BF7D73F468.exe
    2009-06-06 09:23 . 2009-06-06 09:23244224----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\Icon8EEA8E04.exe
    2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\users\Guillaume\AppData\Roaming\Software
    2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Common Files\Quest Shared
    2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Quest Software
    2009-06-05 18:43 . 2009-06-09 15:50--------d-----w-C:\wamp
    2009-06-04 09:52 . 2009-06-04 09:52--------d-----w-c:\programdata\muvee Technologies
    2009-06-04 09:51 . 2009-06-04 09:52--------d-----w-c:\users\Guillaume\AppData\Roaming\muvee Technologies
    2009-06-02 13:09 . 2009-06-29 11:41--------d-----w-c:\users\Guillaume\Divers
    2009-06-02 11:38 . 2009-06-02 11:38--------d-----w-c:\program files\Common Files\Adobe AIR
    2009-06-02 10:09 . 2009-06-02 11:37--------d-----w-c:\program files\Common Files\Adobe
    2009-06-02 09:54 . 2009-06-02 09:54--------d-----w-c:\users\Guillaume\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2009-06-02 08:46 . 2009-06-02 08:50--------d-----w-c:\users\Guillaume\AppData\Roaming\SolidDocuments
    2009-06-02 08:45 . 2008-08-01 16:3213560----a-w-c:\windows\system32\solidlocalui.dll
    2009-06-02 08:45 . 2008-08-01 16:3221240----a-w-c:\windows\system32\solidlocalmon.dll
    2009-06-02 08:44 . 2009-06-02 08:44--------d-----w-c:\programdata\SolidDocuments

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-07-02 08:41 . 2009-01-21 10:1812----a-w-c:\windows\bthservsdp.dat
    2009-07-02 08:23 . 2009-02-19 09:35--------d-----w-c:\programdata\Symantec
    2009-07-02 08:21 . 2009-02-19 09:34--------d-----w-c:\programdata\NortonInstaller
    2009-07-02 08:18 . 2009-02-19 11:40--------d-----w-c:\program files\Java
    2009-07-02 08:15 . 2009-02-19 10:21--------d-----w-c:\programdata\Microsoft Help
    2009-07-02 00:29 . 2009-07-01 23:41410984----a-w-c:\windows\system32\deploytk.dll
    2009-06-29 22:28 . 2009-02-19 10:26--------d-----w-c:\program files\Microsoft SQL Server
    2009-06-29 22:24 . 2009-02-19 10:23--------d-----w-c:\program files\Microsoft.NET
    2009-06-29 22:12 . 2009-05-26 17:09--------d-----w-c:\users\Guillaume\AppData\Roaming\NuSphere
    2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\programdata\WildTangent
    2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\program files\HP Games
    2009-06-23 16:00 . 2009-05-22 11:29--------d-----w-c:\users\Guillaume\AppData\Roaming\CyberLink
    2009-06-20 18:12 . 2009-05-26 11:00--------d-----w-c:\users\Guillaume\AppData\Roaming\DBDesigner4
    2009-06-19 13:00 . 2009-05-18 12:02--------d-----w-c:\program files\PHP
    2009-06-17 19:54 . 2009-06-01 08:32--------d-----w-c:\users\Guillaume\AppData\Roaming\Skype
    2009-06-17 19:40 . 2009-06-01 08:45--------d-----w-c:\users\Guillaume\AppData\Roaming\skypePM
    2009-06-08 21:45 . 2009-05-14 02:20104560----a-w-c:\users\Guillaume\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-06-08 21:03 . 2006-11-02 12:37--------d-----w-c:\program files\MSBuild
    2009-06-08 08:26 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Hewlett-Packard
    2009-06-08 08:25 . 2009-02-19 09:33--------d-----w-c:\programdata\Hewlett-Packard
    2009-06-07 17:07 . 2009-05-31 20:18--------d-----w-c:\users\Guillaume\AppData\Roaming\FileZilla
    2009-06-03 13:47 . 2009-02-19 09:32--------d--h--w-c:\program files\InstallShield Installation Information
    2009-06-02 10:25 . 2009-05-19 19:41--------d-----w-c:\program files\File Recover
    2009-06-01 08:45 . 2009-06-01 08:4556---ha-w-c:\windows\system32\ezsidmv.dat
    2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\program files\Common Files\Skype
    2009-06-01 08:32 . 2009-06-01 08:32--------d-----r-c:\program files\Skype
    2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\programdata\Skype
    2009-05-31 20:18 . 2009-05-31 20:18--------d-----w-c:\program files\FileZilla FTP Client
    2009-05-30 21:18 . 2009-05-15 03:52--------d-----w-c:\program files\Google
    2009-05-28 20:00 . 2009-05-28 20:00--------d-----w-c:\program files\EASEUS
    2009-05-28 18:02 . 2009-02-19 12:35--------d-----w-c:\program files\SMINST
    2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\Common Files\fabFORCE
    2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\fabFORCE
    2009-05-26 10:03 . 2009-05-26 10:03--------d-----w-c:\programdata\MySQL
    2009-05-26 09:12 . 2009-05-26 09:12--------d-----w-c:\program files\Opera
    2009-05-25 23:40 . 2009-05-25 22:13--------d-----w-c:\users\Guillaume\AppData\Roaming\vlc
    2009-05-25 22:12 . 2009-05-25 22:12--------d-----w-c:\program files\VideoLAN
    2009-05-20 21:09 . 2009-02-19 09:35--------d-----w-c:\programdata\Norton
    2009-05-19 19:34 . 2009-05-19 19:34--------d-----w-c:\programdata\ParetoLogic
    2009-05-19 19:33 . 2009-05-19 19:33--------d-----w-c:\programdata\Cached Installations
    2009-05-19 19:19 . 2009-05-19 19:19--------d-----w-c:\program files\AVG
    2009-05-19 09:06 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail
    2009-05-18 19:26 . 2009-05-18 19:26--------d-----w-c:\program files\MSXML 4.0
    2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\programdata\NOS
    2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\program files\NOS
    2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\users\Guillaume\AppData\Roaming\Nvu
    2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\program files\Nvu
    2009-05-18 12:18 . 2009-05-29 10:152076672----a-w-c:\windows\system32\libmysql.dll
    2009-05-17 06:24 . 2009-05-17 06:24--------d-----w-c:\program files\Western Digital Corporation
    2009-05-16 15:39 . 2009-05-16 15:390----a-w-c:\windows\nsreg.dat
    2009-05-16 08:25 . 2009-05-16 08:25--------d--h--r-c:\users\Guillaume\AppData\Roaming\SecuROM
    2009-05-16 08:25 . 2009-05-16 08:2598304----a-w-c:\windows\system32\CmdLineExt.dll
    2009-05-16 08:14 . 2009-05-16 08:14--------d-----w-c:\program files\Sierra
    2009-05-16 08:11 . 2009-05-16 08:11--------d-----w-c:\users\Guillaume\AppData\Roaming\InstallShield
    2009-05-15 03:53 . 2009-05-15 03:53--------d-----w-c:\program files\Common Files\PX Storage Engine
    2009-05-14 02:55 . 2009-05-14 02:55--------d-----w-c:\users\Guillaume\AppData\Roaming\WildTangent
    2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Macrovision
    2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\ATI
    2009-05-14 02:51 . 2009-05-14 02:51--------d-----w-c:\users\Guillaume\AppData\Roaming\DigitalPersona
    2009-05-14 02:18 . 2009-05-14 02:18--------d-----w-c:\users\Guillaume\AppData\Roaming\HP TCS
    2009-05-14 02:18 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Sidebar
    2009-05-14 02:16 . 2009-05-14 02:160--sha-r-c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF9143YJF_E517901-371_4A_I3600_SHP_V98.32_F.23_T090105_WV3-1_L409_M3069_J320_7AMD_8F31_92.20_#090121_N10EC8168;168C001C_(NU324PA#ACJ)_XMOBILE_CN10_Z_2Rev 1.MRK
    2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr
    2009-03-25 12:13 . 2009-05-15 03:357100928----a-w-c:\program files\PocketDivXEncoder_0.3.96.exe
    2009-02-19 10:47 . 2009-02-19 10:338192--sha-w-c:\windows\Users\Default\NTUSER.DAT
    .

    ((((((((((((((((((((((((((((( [emailprotected]_00.18.35 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-11-02 07:33 . 2006-11-02 07:3348128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18248_none_f34a4cecba3fd10b\mshtmler.dll
    + 2008-01-21 02:23 . 2008-01-21 02:2372704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18248_none_ae0ee83906df1e56\admparse.dll
    + 2009-02-19 10:37 . 2009-02-19 10:3764512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18248_none_01c5b9e9a1ec46b0\WininetPlugin.dll
    + 2008-01-21 01:58 . 2009-07-02 08:3251680 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-05-14 02:18 . 2009-07-02 08:4316384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-05-14 02:18 . 2009-07-01 23:5816384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-05-14 02:18 . 2009-07-01 23:5832768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-05-14 02:18 . 2009-07-02 08:4332768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-05-14 02:18 . 2009-07-02 08:4316384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-05-14 02:18 . 2009-07-01 23:5816384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-01-21 02:25 . 2008-01-21 02:256656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18254_none_33f7ddc1da1f1d8a\McrMgr.dll
    + 2009-05-17 07:56 . 2009-07-02 00:307588 c:\windows\System32\WDI\ERCQueuedResolutions.dat
    + 2009-05-14 02:17 . 2009-07-02 08:329578 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3809033370-1981303550-699846253-1003_UserData.bin
    - 2009-07-01 23:57 . 2009-07-01 23:572048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-07-02 08:42 . 2009-07-02 08:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2008-01-21 02:24 . 2008-01-21 02:24180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18248_none_647f330bae383e13\ieui.dll
    + 2008-01-21 02:24 . 2008-01-21 02:24129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18248_none_478070c58c9d650d\sqmapi.dll
    + 2006-11-02 07:27 . 2006-11-02 09:39161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18248_none_ae0ee83906df1e56\ieakui.dll
    + 2006-11-02 13:05 . 2009-07-02 08:32110090 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 10:33 . 2009-07-02 08:15663196 c:\windows\System32\perfh009.dat
    - 2006-11-02 10:33 . 2009-07-02 00:05663196 c:\windows\System32\perfh009.dat
    + 2006-11-02 10:33 . 2009-07-02 08:15127404 c:\windows\System32\perfc009.dat
    - 2006-11-02 10:33 . 2009-07-02 00:05127404 c:\windows\System32\perfc009.dat
    - 2009-02-19 11:41 . 2009-07-01 23:41148888 c:\windows\System32\javaws.exe
    + 2009-07-02 00:29 . 2009-07-02 00:29148888 c:\windows\System32\javaws.exe
    - 2009-02-19 11:41 . 2009-07-01 23:41144792 c:\windows\System32\javaw.exe
    + 2009-07-02 00:29 . 2009-07-02 00:29144792 c:\windows\System32\javaw.exe
    - 2009-02-19 11:41 . 2009-07-01 23:41144792 c:\windows\System32\java.exe
    + 2009-07-02 00:29 . 2009-07-02 00:29144792 c:\windows\System32\java.exe
    + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22435_none_f2f64e4f84abbcec\OESpamFilter.dat
    + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18259_none_f25b10ee6b9abd39\OESpamFilter.dat
    + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21056_none_f0fb46578794b34f\OESpamFilter.dat
    + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16860_none_f060ffc26e84642a\OESpamFilter.dat
    + 2008-01-21 02:24 . 2008-01-21 02:242455488 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21046_none_fa10127687d0d070\ieapfltr.dat
    + 2008-01-21 02:24 . 2008-01-21 02:242455488 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16851_none_f976cc2b6ebf9aa2\ieapfltr.dat
    + 2006-11-02 10:22 . 2009-07-02 08:296553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
    - 2006-11-02 10:22 . 2009-07-01 11:106553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
    + 2008-06-06 17:27 . 2009-07-02 08:28131780406 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-12-11 842816]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136]
    "ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-06-11 86016]
    "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification PackagesREG_MULTI_SZ scecli DPPWDFLT

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
    backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
    backup=c:\windows\pss\Monitor Apache Servers.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{E6DB3961-07E4-45A0-AA3C-F3B3B7F4F9F7}"= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{353CF60D-E2AD-4F09-B76F-C1CDD3478789}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe:HP TouchSmart Music
    "{4AA41B04-FF93-4B2D-A7A8-6DA731383642}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe:HP TouchSmart Photo
    "{3A5169F5-3859-4E6E-BB92-5B35B8C6911B}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe:HP TouchSmart Video
    "{BC92971A-983D-4974-88A3-576F943534BC}"= c:\program files\Hewlett-Packard\Media\DVD\TSMAgent.exe:HP TouchSmart Media Resident Program
    "{A7467990-D655-4E94-80E7-FA9E8BA1E3FA}"= c:\program files\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
    "{A00F1E0E-FBE5-4BB6-97FB-380E719F92E5}"= c:\program files\Hewlett-Packard\Media\DVD\HPDVDSmart.exe:HP MediaSmart DVD
    "{6F13DC25-28CE-42DB-ABD0-5682B2024A79}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe:HP TouchSmart Music
    "{67D587A5-DEB8-4A93-B3B1-3226CAB96983}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe:HP TouchSmart Photo
    "{94801C04-866B-4BF4-A902-F4195C37EA9B}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe:HP TouchSmart Video
    "{8B4BBE2F-DFEB-4EA4-BCC8-2734E5E8A9FB}"= c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe:HP TouchSmart Media Resident Program
    "{92E60A91-51C1-4153-914B-020EE33F6C60}"= c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
    "{535552D7-2F2E-457A-A653-B94E417C029B}"= c:\program files\Hewlett-Packard\Media\TV\QP.exe:Quick Play
    "{445E2C51-CF0E-4F90-83EB-C1903B572927}"= c:\program files\Hewlett-Packard\Media\TV\QPService.exe:Quick Play Resident Program
    "TCP Query User{6B46CD09-8566-434F-A3FF-CBDA4B0B7331}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
    "UDP Query User{C11FEE4C-5B54-453A-83D4-25941667E24E}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
    "TCP Query User{844E49C1-FDE0-4617-8D07-9CE36D1BF429}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
    "UDP Query User{EB116974-69E3-4B3F-8A6A-A7CCDB2A6FCA}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
    "{8F9629FE-2EC6-4DB4-B73F-DE5398BD5FA1}"= UDP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server
    "{809437AF-EDE8-42B0-AB49-89B0183A1352}"= TCP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server
    "{9D1960D7-5A1C-451F-9530-A2A63A482EE7}"= UDP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener
    "{125EECFC-463C-41F6-99FD-F26D456CF288}"= TCP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener
    "{C420771C-6514-4124-9253-5143600D9699}"= UDP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser
    "{4C5C4A73-C523-4639-AA30-079FF741791B}"= TCP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser
    "{0858C917-6AE0-47FD-9220-529AC026C79A}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "{2ABB040C-C949-4C0A-99A1-698D45CF9014}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "{0F855C04-E7EE-4B44-AE86-C5E8541D7566}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "TCP Query User{640C01A5-F4AC-47DF-8372-C676D3CE567E}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= UDP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG
    "UDP Query User{29EC753F-84F2-48F1-8170-B813D5537431}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= TCP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG
    "TCP Query User{79D3A5C4-4E33-4AF6-BF9E-375EC79BEB93}c:\\program files\\nusphere\\phped\\srv.exe"= UDP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server
    "UDP Query User{08869455-D764-4AAD-823E-A744B1FDA516}c:\\program files\\nusphere\\phped\\srv.exe"= TCP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server
    "{1B779A5F-1F93-4A92-8729-18090A1ECBA2}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "{C16D5914-BA67-4BE6-B6E9-E7790E83F72C}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "{6797A88C-F4AD-4568-A9B5-5B435E0C06E8}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "{E278D605-6FAC-43B7-A46F-9FDD26CCD134}"= UDP:c:\users\Guillaume\AppData\Local\temp\7zSEB67.tmp\SymNRT.exe:Norton Removal Tool
    "{879ABAC5-CD45-490F-BB81-F33B9AD48DA6}"= TCP:c:\users\Guillaume\AppData\Local\temp\7zSEB67.tmp\SymNRT.exe:Norton Removal Tool

    R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [01-07-2009 21:17 64160]
    R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/01/21 03:06];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [29-11-2008 04:04 87536]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe [21-01-2009 12:29 77824]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18-01-2009 23:34 921936]
    R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [19-02-2009 14:35 365952]
    R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [27-11-2008 03:13 296320]
    R2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [27-11-2008 03:13 116096]
    R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [18-11-2008 16:09 599344]
    R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [04-09-2008 19:47 54784]
    R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [21-01-2009 12:33 22072]
    S2 gupdate1c9e16bff8dc080;Google Update Service (gupdate1c9e16bff8dc080);c:\program files\Google\Update\GoogleUpdate.exe [30-05-2009 23:17 133104]
    S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [19-02-2009 11:49 222512]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [18-05-2009 19:49 33176]
    S3 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19-03-2008 02:24 19456]
    S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [23-10-2008 11:42 107360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcsREG_MULTI_SZ BthServ

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2009-07-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:34]

    2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16]

    2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16]

    2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003Core.job
    - c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16]

    2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003UA.job
    - c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    FF - ProfilePath - c:\users\Guillaume\AppData\Roaming\Mozilla\Firefox\Profiles\7epg4avp.default\
    FF - component: c:\program files\DigitalPersona\Bin\firefoxext\components\dpffcli.dll
    FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    FF - plugin: c:\users\Guillaume\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-02 10:43
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQL]
    "ImagePath"="\"c:\mysql\bin\mysqld\" --defaults-file=\"c:\mysql\my.ini\" MySQL"

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
    "ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-3809033370-1981303550-699846253-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    "??"=hex:a5,c6,03,b0,fe,da,19,0e,13,6f,1d,be,81,54,7e,02,98,7a,e5,db,eb,9e,6e,
    b8,0d,f4,3e,c1,a9,b2,25,b3,df,5f,35,0d,bb,d1,a9,20,18,46,31,f0,11,60,81,fe,\
    "??"=hex:03,ed,aa,f5,c2,c1,45,25,6f,40,71,e2,b3,45,2f,79
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'lsass.exe'(712)
    c:\windows\system32\DPPWDFLT.dll

    - - - - - - - > 'Explorer.exe'(3040)
    c:\program files\DigitalPersona\Bin\DpoFeedb.dll
    c:\program files\DigitalPersona\Bin\DpoSet.dll
    c:\windows\system32\btncopy.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\System32\Ati2evxx.exe
    c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe
    c:\windows\System32\audiodg.exe
    c:\windows\System32\Ati2evxx.exe
    c:\windows\System32\wlanext.exe
    c:\program files\DigitalPersona\Bin\DpHostW.exe
    c:\windows\System32\agrsmsvc.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    c:\program files\CyberLink\Shared files\RichVideo.exe
    c:\windows\System32\wbem\unsecapp.exe
    c:\windows\System32\conime.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    c:\windows\System32\wbem\unsecapp.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\Synaptics\SynTP\SynTPHelper.exe
    c:\windows\System32\wbem\WMIADAP.exe
    .
    **************************************************************************
    .
    Completion time: 2009-07-02 10:47 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-07-02 08:47
    ComboFix2.txt 2009-07-02 00:20

    Pre-Run: 95,925,760,000 bytes free
    Post-Run: 95,698,595,840 bytes free

    350--- E O F ---2009-07-02 08:28


    .... and the Malwarebytes log:

    Malwarebytes' Anti-Malware 1.38
    Database version: 2362
    Windows 6.0.6001 Service Pack 1

    02-07-2009 10:54:54
    mbam-log-2009-07-02 (10-54-54).txt

    Scan type: Quick Scan
    Objects scanned: 82864
    Time elapsed: 3 minute(s), 25 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Thanks for helping me out.

    I'm going to see how it is running now.

    Cheers
    What is the status of the new antivirus?I am using Avira now.

    It has updated the last version.

    I ran a scan and it found and healed 3 threats.

    So far it's doing ok.

    * Click START then RUN
    * Now type Combofix /u in the runbox
    * Make sure there's a space between Combofix and /u
    * Then hit Enter

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a new, clean Restore Point.

    ----------

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    ----------

    How is the computer running now?

    .The computer seems to be running ok.

    I'll keep you informed in the next few days. Thank you anyway for the great help you gave me. Sounds good.

    Here are a few more suggestions.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks for the suggestions.

    I'll have a look at this too.

    Cheers
    3842.

    Solve : DEP Error preventing access to computer.?

    Answer»

    Hello, not to sure of the reason for the error but having read some previous posts it seems like the right forum to post. Yesterday evening after turning on my computer I got a "DEP userinit login app" message on my computer, blank screen but for message and background image. I managed to get my browser up, searched the web for the message, and came to this site. Read some more and came to the sticky on malware removal help. I've downloaded all programs listed, my java is upto date, and I'm running AVG Free with an upto date database by 1 day.

    However I have no desktop, location of saved files, and cannot bypass this by using the task managers RUN feature. Both task manager and explorer (win start button + E) come up as DEP Errors. So in short I cannot install or run anything other than the browser.

    Went to bed grumpy, woke up this morning, ISSUE is still there, (faint hope this was a BAD dream).

    Any help will be APPRECIATED.

    (edit #1)
    Managed to get desktop, INSTALLED and ran software in order EvilFantasy suggested. Log files are attached.

    [attachment deleted by admin]

    3843.

    Solve : Microsoft Updates will not scan my computer for updates?

    Answer»

    When I go to Windows Updates and click for the express scan for updates I get an error message. The number of the error message is 0x80248011. I have tried a couple of the solutions that Microsoft recommends on its Update site, but have not been successful in completing them. For one it asks me to rename a file, but it won't let me change the name.

    I have used the Protection Scan/Disc Cleanup Scan on the Microsoft site and they REPORT there are no virus problems, and I have used my Norton scan with the same results.

    I have also been having a problem with shutting down my computer and have to do it by turning the power off, so I have not been receiving automatic updates.

    How can I solve this problem? THANKS for remembering that I am not very computer literate, so please use the most simplistic explanation as to how to remedy this situation. Could the problem I have getting updates be connected to the shutdown problem?

    I appreciate any help you can give me on these problem. Thank you. Have you tried renaming the file under safe mode?When I try Microsoft Updates suggestion for resolving this problem it tell me to do start/run/services.mcs/ right click automatic updates/ click stop/ rename folder/ but there is no folder to rename. If I left click automatic updates I get a box NAMED Automatic Updates with a name in a box marked path to executables which contains C:/WINDOWS/SYSTEM32/SVCHOST.exe -k netsvcs and this is the point where I get lost. Is this the file I'm being directed to rename? When I try to rename it, nothing happens. Thanks for your suggestion about renaming it in safe mode, but how do I go about doing that? Still have this problem. Anybody out there have any ideas?http://www.microsoft.com/communities/default.mspx


    go to above theres lots of help there, forums , blogs etc , harryI was having a number of problems with Windows update and found a solution that seemed to work.

    1. Boot into safe mode with networking
    2. run windows update
    3. if it asks to install ActiveX do it
    4. when the update fails click on Administrator options in the left pane
    5. click on the CATALOG link at the end of the first sentence
    6. another window will open and you will be given another chance to install ActiveX, do it
    7. once the window changes from the box telling you about ActiveX to the glowing white search box, reboot
    8. when you have booted normally run windows update again
    9. you may get a page that wants you to reregister components, do it
    10. you will get the update page for the genuine advantage and the windows package installer, install them
    11. once they are installed continue with the updates, express or custom

    This worked for me, your mileage may differ, but it could not hurt to try it.
    yes kando as you said you do need this i found as well , you will get the update page for the genuine advantage and the windows package installer, install themKando, thanks for your suggestion. I tried it, but it didn't work. Got the same error message as usual. Any other suggestions?go to , tools , internet options, advanced , reset internet explorer settings , click reset , read the page that

    comes up , what it takes out and resets BACK to when your pc was new , i have done it twice over the years

    and it did no harm , its worth a go , harryhi harry, thanks for the suggestion. I haven't tried it yet because when I go to Internet Options/Advanced does not have a reset button for internet explorer. There is a tab that says Programs which has a button called Reset Web Settings with the description You can reset Internet Explorer to the default home and search pages. Is this the same thing? that is the very thing Hi Harry, just tried your suggestion. Sorry, but it didn't work. Any other ideas?i will PM you in 10 minutes

    3844.

    Solve : Malware removal procedures completed?

    Answer»

    Hello

    I have completed the required procedures for malware removal as your post described and am now going to post the logs here for your analysis. Thanks for the help. I am using a HP Pavilion Entertaimnet PC with windows VISTA. I have been having problems with opening window files. If I open too many of them in a row, the computer responds very slowly, so that the window opens slow as a tutle, or it does not even open at all, leaving me with a white window with no data shown.

    Here are the logs:
    Malwarebytes' Anti-Malware 1.38
    Database version: 2297
    Windows 6.0.6001 Service Pack 1

    05/07/2009 11:39:30 AM
    mbam-log-2009-07-05 (11-39-30).txt

    Scan type: Quick Scan
    Objects scanned: 77745
    Time elapsed: 6 minute(s), 35 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\SSDPSRV (Backdoor.Bot) -> QUARANTINED and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Windows\System32\ssdpsrv.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\Windows\System32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Windows\System32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:53:02 AM, on 05/07/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files\Kaspersky Lab Tool\is-226OJ\is-226OJ.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\BitTorrent\bittorrent.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [ICSDCLT] C:\Windows\rundll32.exe C:\Windows\system32\icsdclt.dll,ICSClient
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [is-226OJ] "C:\Program Files\Kaspersky Lab Tool\is-226OJ\is-226OJ.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
    O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office XP\Office10\OSA.EXE
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Programador de LiveUpdate automático (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: is-226OJ - Kaspersky Lab - C:\Program Files\Kaspersky Lab Tool\is-226OJ\is-226OJ.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

    --
    End of file - 10400 bytes

    Thanks again for the help, CaroleScan Suspicious File(s)

    Please go to VirusTotal.com
    (If more than one file needs scanned they must be done separately and logs posted for each one)

    1. Copy the file path in the below Code box:

    Code: [Select]C:\Program Files\Kaspersky Lab Tool\is-226OJ\is-226OJ.exe
    2. At the upload site, click once inside the window next to Browse.
    3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    4. Next click Send File
    Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    This will perform a scan across multiple different virus scanning ENGINES.
    Important: Wait for all of the scanning engines to complete.
    5. Copy and then Paste the link to the results in the next reply

    ----------

    Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to BLOCK DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the ENTIRE contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.

    3845.

    Solve : Good decoration of free security softwares?

    Answer»

    I bought a new computer few days ago.I have installed the following softwares for protection:
    1. AVG anti-virus free edition.
    2. SuperAntiSpyware free edition.
    3. spybot search & destroy.
    4. Zone Alarm firewall.
    5. CCleaner.

    Are they conflict with each other?If they conflict what softwares are necessary to uninstall among them?And what softwares are necessary to install for better protection against virus,spyware,rootkit,hack etc.? I need a good decoration of free security softwares for allround protection. Pls help me.Those will all work fine with each other.

    I would also suggest installing the following, which will not interfere with anything.

    WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based BROWSERS like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see hereThank you for your advice.But I have known from difference source that more than one anti-spyware software could damage the computer.In my computer I have installed both "SuperAntiSpyware" and "Spybot search & destroy" anti-spyware software.Besides, there is a component as anti-spyware in "AVG anti-virus" which is installed in my computer.So is it harmful for my computer? What is your thinking?You can install and use as many antispyware programs as you like. This is as long as they are scan only, no real-time protection.

    Spybot search & Destroy does not have real-time protection other than Tea-Timer which I always suggest turning off anyway.

    SuperAntiSpyware does have a paid version with real-time protection but if you didn't buy the license the real-time protection won't run.

    SpywareBlaster only adds restrictions to your browser to block known bad web sites. It doesn't actually run.Thank you.How can I turn off tea timer?Disable Spybot's TeaTimer

    1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
    2. Run Spybot S&D
    3. Go to the Mode MENU, and make sure ADVANCED Mode is selected.
    4. On the left HAND side, choose Tools > Resident
    uncheck Resident TeaTimer and OK any prompt and Restart your computer.

    Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.In your post (sub: read this before requesting malware removal help) in this board, you advice:
    "You should only have one antivirus and one firewall active at any time".But in my computer there are two firewall active."Zone alarm firewall" and "windows firewall".Can I turn off "windows firewall"?Yes you should turn off the Windows Firewall.which firewall is more effective?"Zone alarm" / "windows firewall" or other?Zone Alarm is a good firewall.Thank you. My last question:
    I have changed the superantispyware's setting. In "scanning control tab" only three following "scanner options" are checked:
    1. Close browsers before scanning.
    2. Scan for tracking cookies.
    3. Terminate memory threats before quarantining.
    Other options are unchecked. Is it the correct selection? If you are using the free version.

    Click the Preferences button.

    * Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts

    3846.

    Solve : Virus is not letting execute any program?

    Answer»

    My system is ATTACKED by some malware. its automatically opening all porn websites and not letting me to run any virus program. i have followed the thread on the cool website and run as you guys said. i am pasting the logs below. please advise me what should i do next.

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/03/2009 at 03:07 PM

    Application Version : 4.26.1006

    Core Rules Database Version : 3969
    Trace Rules Database Version: 1909

    Scan type : Complete Scan
    Total Scan Time : 03:47:20

    Memory items scanned : 609
    Memory threats detected : 3
    Registry items scanned : 6318
    Registry threats detected : 97
    File items scanned : 119848
    File threats detected : 75

    Trojan.Agent/Gen-6TO4
    C:\WINDOWS\SYSTEM32\6TO4V32.DLL
    C:\WINDOWS\SYSTEM32\6TO4V32.DLL

    Trojan.Agent/Gen-RogueDropper
    C:\WINDOWS\SYSTEM32\IEHELPER.DLL
    C:\WINDOWS\SYSTEM32\IEHELPER.DLL
    HKU\s-1-5-21-796845957-515967899-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8567edfa-408c-43e9-b929-4c25c04f5003}

    Adware.SysGuard/FakeAlert
    C:\WINDOWS\SYSGUARD.EXE
    C:\WINDOWS\SYSGUARD.EXE
    HKU\s-1-5-21-796845957-515967899-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run#system tool [ C:\WINDOWS\sysguard.exe ]
    C:\WINDOWS\Prefetch\SYSGUARD.EXE-39D8A190.pf

    Adware.Vundo Variant
    HKLM\Software\Classes\CLSID\{BBD4551A-9B23-41cd-9BCD-818AA2DA7B63}
    HKCR\CLSID\{BBD4551A-9B23-41CD-9BCD-818AA2DA7B63}
    HKCR\CLSID\{BBD4551A-9B23-41CD-9BCD-818AA2DA7B63}
    HKCR\CLSID\{BBD4551A-9B23-41CD-9BCD-818AA2DA7B63}\InProcServer32
    HKCR\CLSID\{BBD4551A-9B23-41CD-9BCD-818AA2DA7B63}\InProcServer32#ThreadingModel
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBD4551A-9B23-41cd-9BCD-818AA2DA7B63}
    HKU\s-1-5-21-796845957-515967899-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BBD4551A-9B23-41CD-9BCD-818AA2DA7B63}

    Trojan.Vundo-Variant/NextGen
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8567edfa-408c-43e9-b929-4c25c04f5003}
    HKCR\CLSID\{8567EDFA-408C-43E9-B929-4C25C04F5003}
    HKCR\CLSID\{8567EDFA-408C-43E9-B929-4C25C04F5003}
    HKCR\CLSID\{8567EDFA-408C-43E9-B929-4C25C04F5003}\inprocserver32
    HKCR\CLSID\{8567EDFA-408C-43E9-B929-4C25C04F5003}\inprocserver32#ThreadingModel

    Adware.Tracking Cookie
    C:\Documents and Settings\OM\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\OM\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\OM\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\OM\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\OM\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\OM\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Guest\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\NetworkService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\NetworkService\Cookies\[emailprotected][2].txt

    Trojan.Unknown Origin
    HKLM\Software\xpre
    HKLM\Software\xpre#execount

    Rootkit.Unclassified/KR_Done
    C:\WINDOWS\system32\kr_done1

    Rogue.SysCleaner
    HKU\s-1-5-21-796845957-515967899-839522115-1003\Software\xInsiDERexe

    Trojan.Unclassified/NVCOI
    C:\Program Files\Temporary

    Trojan.Hugipon
    HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters
    HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters#ServiceDll

    Rogue.Agent/Gen
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#aazalirt
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#skaaanret
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#jungertab
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#zibaglertz
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#iddqdops
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#ronitfst
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#tobmygers
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#jikglond
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#tobykke
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#klopnidret
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#jiklagka
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#salrtybek
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#seeukluba
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#jrjakdsd
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#krkdkdkee
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#dkewiizkjdks
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#dkekkrkska
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#rkaskssd
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#kuruhccdsdd
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#krujmmwlrra
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#kkwknrbsggeg
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#ktknamwerr
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#iqmcnoeqz
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#ienotas
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#krkmahejdk
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#otpeppggq
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#krtawefg
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#oranerkka
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#kitiiwhaas
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#otowjdseww
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#otnnbektre
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#oropbbsee
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#irprokwks
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#ooorjaas
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#id
    HKU\s-1-5-21-796845957-515967899-839522115-1003\SOFTWARE\AVSCAN#ready

    Trojan.Agent/Gen
    C:\WINDOWS\system32\lowsec\local.ds
    C:\WINDOWS\system32\lowsec\user.ds
    C:\WINDOWS\system32\lowsec
    C:\Program Files\DRV

    Trojan.Backdoor[DRV]
    HKLM\System\CONTROLSET001\SERVICES\DRV
    HKLM\System\CONTROLSET001\SERVICES\DRV#Type
    HKLM\System\CONTROLSET001\SERVICES\DRV#Start
    HKLM\System\CONTROLSET001\SERVICES\DRV#ErrorControl
    HKLM\System\CONTROLSET001\SERVICES\DRV#ImagePath
    HKLM\System\CONTROLSET001\SERVICES\DRV#ObjectName
    HKLM\System\CONTROLSET001\SERVICES\DRV#FailureActions
    HKLM\System\CONTROLSET001\SERVICES\DRV\parameters
    HKLM\System\CONTROLSET001\SERVICES\DRV\parameters#ServiceDll
    HKLM\System\CONTROLSET001\SERVICES\DRV\security
    HKLM\System\CONTROLSET001\SERVICES\DRV\security#Security
    HKLM\System\CONTROLSET001\SERVICES\DRV\Enum
    HKLM\System\CONTROLSET001\SERVICES\DRV\Enum#0
    HKLM\System\CONTROLSET001\SERVICES\DRV\Enum#Count
    HKLM\System\CONTROLSET001\SERVICES\DRV\Enum#NextInstance
    HKLM\System\CONTROLSET003\SERVICES\DRV
    HKLM\System\CONTROLSET003\SERVICES\DRV#Type
    HKLM\System\CONTROLSET003\SERVICES\DRV#Start
    HKLM\System\CONTROLSET003\SERVICES\DRV#ErrorControl
    HKLM\System\CONTROLSET003\SERVICES\DRV#ImagePath
    HKLM\System\CONTROLSET003\SERVICES\DRV#ObjectName
    HKLM\System\CONTROLSET003\SERVICES\DRV#FailureActions
    HKLM\System\CONTROLSET003\SERVICES\DRV\parameters
    HKLM\System\CONTROLSET003\SERVICES\DRV\parameters#ServiceDll
    HKLM\System\CONTROLSET003\SERVICES\DRV\security
    HKLM\System\CONTROLSET003\SERVICES\DRV\security#Security
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#Type
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#Start
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#ErrorControl
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#ImagePath
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#ObjectName
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV#FailureActions
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\parameters
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\parameters#ServiceDll
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\security
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\security#Security
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\Enum
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\Enum#0
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\Enum#Count
    HKLM\System\CURRENTCONTROLSET\SERVICES\DRV\Enum#NextInstance

    Trojan.Agent/Gen-Backdoor[WinRes]
    C:\WINDOWS\FONTS\COOECP.TLB
    C:\WINDOWS\FONTS\LOGCDE.DLL
    C:\WINDOWS\FONTS\WINDEF.DLL
    C:\WINDOWS\FONTS\WINDEF.LOG
    C:\WINDOWS\FONTS\WINPAGED.OCX
    C:\WINDOWS\SYSTEM32\MSBKTI.EXE
    C:\WINDOWS\SYSTEM32\MSEQDW.EXE
    C:\WINDOWS\SYSTEM32\MSHHISS.EXE
    C:\WINDOWS\SYSTEM32\MSJXG.EXE
    C:\WINDOWS\SYSTEM32\MSMAMJ.EXE
    C:\WINDOWS\SYSTEM32\MSSBXGJ.EXE
    C:\WINDOWS\SYSTEM32\MSUIV.EXE
    C:\WINDOWS\SYSTEM32\MSVDAZP.EXE
    C:\WINDOWS\SYSTEM32\MSWHC.EXE
    C:\WINDOWS\SYSTEM32\MSXXGSVF.EXE
    C:\WINDOWS\SYSTEM32\MSYJV.EXE
    C:\WINDOWS\SYSTEM32\MSYNKM.EXE

    Trojan.Agent/Gen-UPX
    C:\WINDOWS\FONTS\SERVICES.EXE

    Trojan.Dropper/Win-NV
    C:\WINDOWS\LD12.EXE

    Adware.Vundo/Variant-MSFake
    C:\WINDOWS\SYSTEM32\MSWINSCK.OCX

    Rootkit.Agent/Gen-FraudLoad-F
    C:\WINDOWS\SYSTEM32\TPSAXYD.EXE

    Trojan.Agent/Gen-Dropper[Temp]
    C:\WINDOWS\TWAIN_32\HPQGNDS2.TMP




    Malwarebytes' Anti-Malware 1.38
    Database version: 2369
    Windows 5.1.2600 Service Pack 3

    7/3/2009 3:45:02 PM
    mbam-log-2009-07-03 (15-45-02).txt

    Scan type: Quick Scan
    Objects scanned: 100383
    Time elapsed: 7 minute(s), 16 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 4
    Registry Values Infected: 4
    Registry Data Items Infected: 0
    Folders Infected: 2
    Files Infected: 9

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcmstub (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\drvdrv (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_DRVDRV (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_DRV (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hsf7husjnfg98gi498aejhiugjkdg4 (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LowRiskFileTypes (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\WINDOWS\system32\iDlo01 (Trojan.Downloader) -> Quarantined and deleted successfully.
    c:\documents and settings\OM\Start Menu\Programs\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.

    Files Infected:
    c:\WINDOWS\system32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.
    c:\fdvjfx.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
    c:\documents and settings\OM\start menu\Programs\system security\System Security (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
    C:\WINDOWS\9129837.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\documents and settings\OM\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\documents and settings\OM\Application Data\wiaservg.log (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\010112010146118114.dat (Worm.KoobFace) -> Quarantined and deleted successfully.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:22:58 PM, on 7/3/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18372)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\MediaMelon\bin\wrapper.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\WINDOWS\system32\java.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
    C:\Program Files\SmartVoip.com\SmartVoip\SmartVoip.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Documents and Settings\OM\Desktop\JavaRa\JavaRa.exe
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    O1 - Hosts: ::1 localhost
    O1 - Hosts: 209.44.111.62 antispy.microsoft.com
    O1 - Hosts: 209.44.111.62 antiaware-pro.com
    O1 - Hosts: 209.44.111.62 www.antiaware-pro.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
    O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
    O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
    O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SmartVoip] "C:\Program Files\SmartVoip.com\SmartVoip\SmartVoip.exe" -nosplash -minimized
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: ImageMixer 3 SE Camera Monitor.lnk = ?
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [java_sun] Java (Sun)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/45.11/uploader2.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Google Update Service (gupdate1c98fbdcfb083d4) (gupdate1c98fbdcfb083d4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LICH - Unknown owner - C:\WINDOWS\system32\lich.exe (file missing)
    O23 - Service: MediaMelon Client 1.0 (MediaMelon Client) - Unknown owner - C:\Program Files\MediaMelon\bin\wrapper.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

    --
    End of file - 11611 bytes

    Edit to remove malicious link in HJT log.
    Welcome to CH.

    There are multiple entries that lead me to believe this is a Virut infection but we will have a closer look to make sure.

    Open HijackThis and select Do a system scan only

    Vista users right click on HijackThis and select Run as Administrator. (you will RECEIVE a UAC prompt, please allow it)

    Place a check mark next to the following entries: (if there)

    • O1 - Hosts: ::1 localhost
    • O1 - Hosts: 209.44.111.62 antispy.microsoft.com
    • O1 - Hosts: 209.44.111.62 antiaware-pro.com
    • O1 - Hosts: 209.44.111.62 www.antiaware- pro.com
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    .
    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ----------

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    Driver::
    lich

    File::
    C:\WINDOWS\system32\lich.exe

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI have runned the combofix. here is the log. THanks a bunch.

    ComboFix 09-07-04.04 - OM 07/04/2009 23:48.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1169 [GMT -5:00]
    Running from: c:\documents and settings\OM\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\OM\Desktop\CFScript.txt
    AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    * Created a new restore point

    FILE ::
    "c:\windows\system32\lich.exe"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\-1124205267
    c:\windows\Installer\105b0428.msp
    c:\windows\Installer\105b0496.msp
    c:\windows\Installer\3f1184.msi
    c:\windows\Installer\55e09e.msp
    c:\windows\Installer\acc93ef.msi
    c:\windows\system32\drivers\4289843a.sys
    c:\windows\system32\prsgrc.dll
    c:\windows\system32\ssprs.dll
    c:\windows\system32\wbem\proquota.exe
    F:\AUTORUN.INF

    c:\windows\system32\proquota.exe was missing
    Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_6to4
    -------\Legacy_lich
    -------\Legacy_pcmstub
    -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
    -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
    -------\Service_4289843a
    -------\Service_6to4
    -------\Service_lich


    ((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 )))))))))))))))))))))))))))))))
    .

    2010-07-15 02:42 . 2009-06-04 22:31--------d-----w-c:\documents and settings\OM\Application Data\dvdcss
    2010-07-15 02:42 . 2010-07-15 02:42--------d-----w-c:\documents and settings\OM\Application Data\vlc
    2010-07-15 02:41 . 2010-07-15 02:41--------d-----w-c:\program files\VideoLAN
    2010-07-13 21:48 . 2009-04-05 00:3373784----a-w-c:\documents and settings\OM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-07-03 21:19 . 2009-07-03 21:19--------d-----w-c:\program files\Trend Micro
    2009-07-03 20:59 . 2009-07-03 20:59152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\OM\Application Data\Malwarebytes
    2009-07-03 20:34 . 2009-06-17 16:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-07-03 20:34 . 2009-06-17 16:2719096----a-w-c:\windows\system32\drivers\mbam.sys
    2009-07-03 16:14 . 2009-07-03 21:39117760----a-w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-07-03 16:14 . 2009-07-03 16:14--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\SUPERAntiSpyware
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-C:\MSId8962.tmp
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-07-03 16:02 . 2009-07-03 16:02--------d-----w-c:\program files\CCleaner
    2009-07-03 04:12 . 2009-07-03 23:39--------d-----w-c:\documents and settings\OM\Application Data\Lavasoft
    2009-07-02 19:15 . 2009-07-02 19:154656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP7.sys
    2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP6.sys
    2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP5.sys
    2009-07-02 19:11 . 2009-07-02 19:114656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP4.sys
    2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP3.sys
    2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP2.sys
    2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP1.sys
    2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP0.sys
    2009-07-02 18:26 . 2009-07-03 03:12--------d-----w-c:\documents and settings\All Users\Application Data\12080624
    2009-07-02 18:26 . 2009-07-02 18:26--------d-sh--w-c:\windows\System Volume Information
    2009-06-29 03:13 . 2009-06-29 03:13--------d-----w-c:\program files\MediaMelon
    2009-06-22 02:45 . 2009-06-22 02:45--------d-----w-c:\program files\Common Files\xing shared
    2009-06-09 03:53 . 2009-06-09 03:53--------d-----w-c:\documents and settings\All Users\Application Data\McAfee
    2009-06-05 13:30 . 2009-05-21 16:33410984----a-w-c:\windows\system32\deploytk.dll
    2009-06-05 13:29 . 2009-06-05 13:29152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_13\lzma.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-15 03:11 . 2007-07-13 04:5086327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-07-05 04:32 . 2008-06-17 01:01--------d-----w-c:\documents and settings\OM\Application Data\HPAppData
    2009-07-04 04:40 . 2009-04-03 14:36--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
    2009-07-03 21:03 . 2008-04-23 00:50--------d-----w-c:\program files\Java
    2009-07-03 16:07 . 2009-03-31 00:50--------d-----w-c:\documents and settings\OM\Application Data\Azureus
    2009-07-03 13:05 . 2008-06-19 03:4511952----a-w-c:\windows\system32\avgrsstx.dll
    2009-07-03 13:05 . 2008-06-19 03:45327688----a-w-c:\windows\system32\drivers\avgldx86.sys
    2009-07-03 13:05 . 2007-03-03 08:0127784----a-w-c:\windows\system32\drivers\avgmfx86.sys
    2009-07-03 13:05 . 2008-06-19 03:45108552----a-w-c:\windows\system32\drivers\avgtdix.sys
    2009-07-03 02:52 . 2008-06-19 03:45--------d-----w-c:\documents and settings\All Users\Application Data\avg8
    2009-07-02 18:55 . 2009-04-11 11:22--------d-----w-c:\documents and settings\OM\Application Data\Amazon
    2009-07-02 18:55 . 2009-04-11 11:21--------d-----w-c:\program files\Amazon
    2009-07-02 18:27 . 2009-07-02 18:27327---h--w-c:\windows\Fonts\mlog
    2009-07-02 18:25 . 2007-01-16 18:01--------d-----w-c:\documents and settings\OM\Application Data\AdobeUM
    2009-06-30 00:58 . 2009-04-17 16:59--------d-----w-c:\documents and settings\OM\Application Data\U3
    2009-06-22 02:45 . 2008-07-17 01:21--------d-----w-c:\program files\Common Files\Real
    2009-06-20 01:19 . 2009-02-03 04:21--------d-----w-c:\program files\Google
    2009-06-03 04:41 . 2009-06-03 04:41--------d-----w-c:\documents and settings\OM\Application Data\ATI
    2009-06-03 03:14 . 2009-06-03 03:14708608----a-w-c:\windows\system32\Resecure60.dll
    2009-06-03 03:14 . 2009-06-03 03:146536----a-w-c:\windows\system32\WinGPDrv.dat
    2009-06-03 03:14 . 2009-06-03 03:146533----a-w-c:\windows\system32\NGWinDrv.dat
    2009-06-03 03:14 . 2009-06-03 03:14458752----a-w-c:\windows\system32\LiveUpdate.dll
    2009-06-03 03:14 . 2009-06-03 03:141290240----a-w-c:\windows\system32\NGWinSys.dll
    2009-06-03 03:14 . 2004-08-04 12:001025----a-w-c:\windows\system32\y1vz87p.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth2.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth1.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth2.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth1.dll
    2009-06-03 03:12 . 2009-06-03 03:12--------d-----w-c:\program files\Common Files\RAM Common
    2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\VectorDraw
    2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\Common Files\Bentley
    2009-06-03 03:09 . 2009-06-03 03:0910134----a-r-c:\documents and settings\OM\Application Data\Microsoft\Installer\{D4A33E08-4FE7-40C4-BF5E-5853C56ADD7C}\ARPPRODUCTICON.exe
    2009-06-03 03:09 . 2009-03-31 01:57--------d-----w-c:\program files\Common Files\Bentley Shared
    2009-06-01 15:56 . 2008-07-20 03:46--------d-----w-c:\documents and settings\Guest\Application Data\HPAppData
    2009-05-31 12:26 . 2009-05-31 12:2673784----a-w-c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-05-10 03:04 . 2009-02-06 01:22--------d-----w-c:\documents and settings\OM\Application Data\ZoomBrowser EX
    2009-05-10 03:03 . 2009-02-06 01:14--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-05-07 15:32 . 2004-08-04 12:00345600----a-w-c:\windows\system32\localspl.dll
    2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr
    2009-04-17 12:26 . 2004-08-04 12:001847168----a-w-c:\windows\system32\win32k.sys
    2009-04-15 14:51 . 2004-08-04 12:00585216----a-w-c:\windows\system32\rpcrt4.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848]
    "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-02-24 3558136]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-03 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-03 1948440]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
    "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
    ImageMixer 3 SE Camera Monitor.lnk - c:\program files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe [2009-2-14 253952]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
    2008-12-22 17:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-07-03 13:0511952----a-w-c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
    backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Themes"=2 (0x2)
    "TapiSrv"=3 (0x3)
    "Symantec AntiVirus"=2 (0x2)
    "SNDSrvc"=3 (0x3)
    "SavRoam"=3 (0x3)
    "HPSLPSVC"=2 (0x2)
    "hpqddsvc"=2 (0x2)
    "helpsvc"=2 (0x2)
    "FastUserSwitchingCompatibility"=3 (0x3)
    "ERSvc"=2 (0x2)
    "DefWatch"=2 (0x2)
    "ccSetMgr"=2 (0x2)
    "ccPwdSvc"=3 (0x3)
    "ccEvtMgr"=2 (0x2)
    "BITS"=2 (0x2)
    "avg8emc"=2 (0x2)
    "Ati HotKey Poller"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
    "c:\\Program Files\\Vuze\\Azureus.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    "c:\\Program Files\\MediaMelon\\bin\\wrapper.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "11:TCP"= 11:TCP:INTERNET
    "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:45 PM 327688]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:45 PM 108552]
    R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
    R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2009 8:05 AM 906520]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 9:06 AM 298776]
    R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\MediaMelon\bin\wrapper.exe [4/16/2009 3:30 PM 217088]
    S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2009 5:36 PM 133104]
    S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [7/2/2009 2:09 PM 1252474]
    S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
    S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/12/2004 4:48 AM 169192]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPServiceREG_MULTI_SZ HPSLPSVC
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34]

    2009-07-05 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 14:36]

    2009-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35]

    2009-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-SpeedItUpEX - c:\program files\Speeditup Free\SpeedItUp.exe
    HKCU-Run-SmartVoip - c:\program files\SmartVoip.com\SmartVoip\SmartVoip.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-04 23:55
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(888)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(2836)
    c:\windows\system32\webcheck.dll
    c:\windows\system32\IEFRAME.dll
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
    c:\windows\system32\msls31.dll
    c:\windows\system32\OneX.DLL
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\BCMWLTRY.EXE
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\drivers\CDAC11BA.EXE
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    c:\windows\system32\java.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\HP\Digital Imaging\bin\hpqste08.exe
    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
    c:\windows\system32\msiexec.exe
    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
    .
    **************************************************************************
    .
    Completion time: 2009-07-05 23:59 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-07-05 04:59

    Pre-Run: 3,585,925,120 bytes free
    Post-Run: 4,511,961,088 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [OPERATING systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows Server 2003, Enterprise" /noexecute=optout /fastdetect
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    306--- E O F ---2009-06-11 08:03
    Download OTM by OldTimer to your desktop.

    Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

    * Save it to your Desktop.
    * Double-click OTM.exe to run it.
    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

    Code: [Select]:Processes
    explorer.exe

    :services

    :reg

    :files
    c:\documents and settings\All Users\Application Data\Symantec

    :Commands
    [purity]
    [emptytemp]
    [start explorer]

    * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    * Click the red Moveit! button.
    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    Close OTM

    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes.

    ----------

    Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.

    ----------

    Also let me know how the computer is running now.

    .hI evilfantasy,
    THANK FOR YOUR HELP. I ran programs as you told me. when i ran OTM by Oldtimer, after clicking on "Move It" there is a message in the green box "it killed all" and screen went blank. I can see only desktop background. then I waited for 30 mins and restarted the system forcefully. It ran fine. then I ran DDS program. the logs are as follows.
    DDS.txt


    DDS (Ver_09-06-26.01) - NTFSx86
    Run by OM at 8:54:36.78 on Sun 07/05/2009
    Internet Explorer: 8.0.6001.18372
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1324 [GMT -5:00]

    AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
    C:\WINDOWS\system32\svchost.exe -k HPService
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    C:\Program Files\MediaMelon\bin\wrapper.exe
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\java.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Documents and Settings\OM\Desktop\dds.com

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
    TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
    TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
    TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
    EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
    uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide
    uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
    uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
    mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se\CameraMonitor.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
    DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/45.11/uploader2.cab
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
    DPF: {8ad9c840-044e-11d1-b3e9-00805f499d93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {cafeefac-0016-0000-0014-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {cafeefac-ffff-ffff-ffff-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: !saswinlogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: NavLogon - c:\windows\system32\NavLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 327688]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-3-3 27784]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-18 108552]
    R1 sasdifsv;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
    R1 saskutil;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
    R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-3 906520]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298776]
    R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\mediamelon\bin\wrapper.exe [2009-4-16 217088]
    R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008]
    R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080613.003\naveng.sys [2008-6-14 89936]
    R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080613.003\navex15.sys [2008-6-14 856336]
    S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\google\update\GoogleUpdate.exe [2009-2-15 133104]
    S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2009-7-2 1252474]
    S3 sasenum;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
    S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096]
    S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160]
    S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808]
    S4 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192]
    S4 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864]

    =============== Created Last 30 ================

    2009-07-05 08:10--d-----C:\_OTM
    2009-07-04 23:58-cd-----c:\windows\system32\dllcache\cache
    2009-07-04 23:5050,176ac------c:\windows\system32\dllcache\proquota.exe
    2009-07-04 23:5050,176a-------c:\windows\system32\proquota.exe
    2009-07-04 23:46a-dshr--C:\cmdcons
    2009-07-04 23:44161,792a-------c:\windows\SWREG.exe
    2009-07-04 23:44155,136a-------c:\windows\PEV.exe
    2009-07-04 23:4498,816a-------c:\windows\sed.exe
    2009-07-04 23:44--ds----C:\ComboFix
    2009-07-03 16:19--d-----c:\program files\Trend Micro
    2009-07-03 15:34--d-----c:\docume~1\om\applic~1\Malwarebytes
    2009-07-03 15:3438,160a-------c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-03 15:3419,096a-------c:\windows\system32\drivers\mbam.sys
    2009-07-03 15:34--d-----c:\program files\Malwarebytes' Anti-Malware
    2009-07-03 15:34--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-07-03 11:14--d-----c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
    2009-07-03 11:13--d-----c:\program files\SUPERAntiSpyware
    2009-07-03 11:13--d-----c:\docume~1\om\applic~1\SUPERAntiSpyware.com
    2009-07-03 11:13--d-----C:\MSId8962.tmp
    2009-07-03 11:13--d-----c:\program files\common files\Wise Installation Wizard
    2009-07-03 11:02--d-----c:\program files\CCleaner
    2009-07-02 13:26--d-----c:\docume~1\alluse~1\applic~1\12080624
    2009-07-02 13:26--dsh---c:\windows\System Volume Information
    2009-06-28 22:13--d-----c:\program files\MediaMelon
    2009-06-21 21:45--d-----c:\program files\common files\xing shared
    2009-06-14 20:120a-------c:\windows\mtstack16.INI

    ==================== Find3M ====================

    2009-07-03 08:05327,688a-------c:\windows\system32\drivers\avgldx86.sys
    2009-07-03 08:0511,952a-------c:\windows\system32\avgrsstx.dll
    2009-07-03 08:05108,552a-------c:\windows\system32\drivers\avgtdix.sys
    2009-07-02 13:27327----h---c:\windows\fonts\mlog
    2009-06-02 22:141,290,240a-------c:\windows\system32\NGWinSys.dll
    2009-06-02 22:14708,608a-------c:\windows\system32\Resecure60.dll
    2009-06-02 22:14458,752a-------c:\windows\system32\LiveUpdate.dll
    2009-06-02 22:146,536a-------c:\windows\system32\WinGPDrv.dat
    2009-06-02 22:146,533a-------c:\windows\system32\NGWinDrv.dat
    2009-05-21 11:33410,984a-------c:\windows\system32\deploytk.dll
    2009-05-07 10:32345,600a-------c:\windows\system32\localspl.dll
    2009-05-01 13:303,366,912a-------c:\windows\system32\GPhotos.scr
    2009-04-17 07:261,847,168a-------c:\windows\system32\win32k.sys
    2009-04-15 09:51585,216a-------c:\windows\system32\rpcrt4.dll
    2009-03-14 19:0860,744a-------c:\documents and settings\om\g2mdlhlpx.exe
    2008-02-22 20:0032a----r--c:\documents and settings\all users\hash.dat

    ============= FINISH: 8:54:54.70 ===============


    Attach.txt


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-06-26.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/12/2007 11:53:14 PM
    System Uptime: 7/5/2009 8:41:08 AM (0 hours ago)

    Motherboard: Dell Inc. | | 0XD720
    Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/166mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 24 GiB total, 4.19 GiB free.
    D: is CDROM ()
    E: is FIXED (NTFS) - 10 GiB total, 5.547 GiB free.
    F: is FIXED (NTFS) - 78 GiB total, 11.013 GiB free.

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description: BCM2045
    Device ID: USB\VID_413C&PID_8126\5&2CD8A58F&0&2
    Manufacturer:
    Name: BCM2045
    PNP Device ID: USB\VID_413C&PID_8126\5&2CD8A58F&0&2
    Service:

    Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
    Description: Officejet J6400 series
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet J6400 series
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:

    Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
    Description: Officejet J6400 series
    Device ID: ROOT\PRINTER\0000
    Manufacturer: HP
    Name: Officejet J6400 series
    PNP Device ID: ROOT\PRINTER\0000
    Service:

    Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
    Description: Nokia N75
    Device ID: ROOT\WPD\0000
    Manufacturer: Nokia
    Name: Nokia N75
    PNP Device ID: ROOT\WPD\0000
    Service: WUDFRd

    ==== System Restore Points ===================

    RP451: 7/4/2009 11:50:21 PM - ComboFix created restore point
    RP452: 7/5/2009 8:29:04 AM - System Checkpoint

    ==== Installed Programs ======================

    32 Bit HP CIO Components Installer
    4Media HD Video Converter
    6400_Help
    Adobe Acrobat 6.0 Professional
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player Plugin
    Aide PDF to DXF Converter 9.5
    AirXonix version 1.41
    Any Video Converter 2.7.1
    Ap PDF to IMAGE
    Apple Mobile Device Support
    Apple Software Update
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    AutoCAD 2004
    Autodesk Express Viewer
    AVG 8.5
    Bentley IEG License Service
    Bentley MicroStation (V 08.05.01.25) - 1
    Bonjour
    bpd_scan
    BPDSoftware
    BPDSoftware_Ini
    Broadcom 440x 10/100 Integrated Controller
    BufferChm
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon RAW Image Task for ZoomBrowser EX
    Canon Utilities CameraWindow
    Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
    Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    Canon Utilities EOS Utility
    Canon Utilities MyCamera
    Canon Utilities RemoteCapture Task for ZoomBrowser EX
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    Cards_Calendar_OrderGift_DoMorePlugout
    CCleaner (remove only)
    Conexant HDA D110 MDC V.92 Modem
    Creative WebCam NX Ultra Driver (1.01.03.0112)
    Critical Update for Windows Media Player 11 (KB959772)
    CustomerResearchQFolder
    Dell Wireless WLAN Card
    Destination Component
    DeviceDiscovery
    DeviceManagementQFolder
    DivX Web Player
    DocProc
    DocProcQFolder
    eSupportQFolder
    Fax
    Free DWG Viewer 6.2
    Google Earth
    Google Gears
    Google Update Helper
    Google Updater
    GoToMeeting 4.0.0.320
    GPBaseService
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Customer Participation Program 10.0
    HP Imaging Device Functions 10.0
    HP Officejet J6400 Series
    HP Photosmart Essential 2.5
    HP Photosmart Essential 3.0
    HP Smart Web Printing
    HP Solution Center 10.0
    HP Update
    HPPhotoSmartPhotobookWebPack1
    HPProductAssistant
    HPSSupply
    ImageMixer 3 SE
    iTunes
    J6400
    Java(TM) 6 Update 14
    LiveUpdate 2.0 (Symantec Corporation)
    Malwarebytes' Anti-Malware
    MarketResearch
    MediaMelon Client
    MetaFrame Presentation Server Web Client for Win32
    Microsoft .NET Framework 2.0
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office Professional Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.5
    Microsoft Visual C++ 2005 Redistributable
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    NetDeviceManager
    Nokia Connectivity Cable Driver
    OCR Software by I.R.I.S. 10.0
    PC Connectivity Solution
    Picasa 3
    ProductContext
    PSSWCORE
    QuickSet
    QuickTime
    RealPlayer
    RedistSysFiles
    SafeCast Shared Components
    Scan
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Shop for HP Supplies
    SigmaTel Audio
    SmartWebPrintingOC
    SolutionCenter
    Sound Blaster ADVANCED MB Drivers
    STAAD.Pro V8i
    Status
    SUPERAntiSpyware Free Edition
    Symantec AntiVirus
    Synaptics Pointing Device Driver
    Toolbox
    TrayApp
    UnloadSupport
    Update for Windows Internet Explorer 8 (KB961813)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VBA (2627.01)
    Veoh Web Player Beta
    VeohTV BETA
    VideoLAN VLC media player 0.8.6b
    VideoToolkit01
    Vuze
    WebFldrs XP
    WebReg
    Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
    Windows Driver Package - Nokia Modem (02/15/2007 3.1)
    Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 8 Release Candidate 1
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    WinStorm30
    Yahoo! Messenger
    Yahoo! Search Protection

    ==== End Of File ===========================
    Thanks,
    SreeGo to Add or Remove Programs and uninstall:

    • LiveUpdate 2.0 (Symantec Corporation)
    • MarketResearch
    • Symantec AntiVirus
    .
    Download the Norton Removal Tool (SymNRT) to your desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.
    • Go to your desktop and double click on the 'Norton_Removal_Tool' and then click Setup.
    • Once open Click Next
    • Accept the license agreement and click Next
    • Type in the letters/numbers that you see into the text box then click Next.
    • Then click Next and the tool will start running.
    • Once finished restart the PC.
    • Delete the 'Norton_Removal_Tool' from your desktop.
    .
    ----------

    Delete these files/folders, as follows:

    1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
    It must be Notepad, not Wordpad.
    2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

    Code: [Select]KillAll::

    DDS::
    TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

    3. Go to the Notepad window and click Edit > Paste
    4. Then click File > Save
    5. Name the file CFScript.txt - Save the file to your Desktop
    6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



    ComboFix will begin to execute, just follow the prompts.
    After reboot (in case it asks to reboot), it will produce a log for you.
    Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeHI,
    I ran the combofix. Here is the log. Thanks.

    ComboFix 09-07-05.01 - OM 07/05/2009 19:38.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1467 [GMT -5:00]
    Running from: c:\documents and settings\OM\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\OM\Desktop\CFScript.txt
    AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\messenger\msmsgs.exe

    .
    ((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
    .

    2010-07-15 02:42 . 2009-06-04 22:31--------d-----w-c:\documents and settings\OM\Application Data\dvdcss
    2010-07-15 02:42 . 2010-07-15 02:42--------d-----w-c:\documents and settings\OM\Application Data\vlc
    2010-07-15 02:41 . 2010-07-15 02:41--------d-----w-c:\program files\VideoLAN
    2010-07-13 21:48 . 2009-04-05 00:3373784----a-w-c:\documents and settings\OM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-07-05 13:10 . 2009-07-05 13:10--------d-----w-C:\_OTM
    2009-07-05 04:50 . 2008-04-14 00:1250176-c--a-w-c:\windows\system32\dllcache\proquota.exe
    2009-07-05 04:50 . 2008-04-14 00:1250176----a-w-c:\windows\system32\proquota.exe
    2009-07-03 21:19 . 2009-07-03 21:19--------d-----w-c:\program files\Trend Micro
    2009-07-03 20:59 . 2009-07-03 20:59152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\OM\Application Data\Malwarebytes
    2009-07-03 20:34 . 2009-06-17 16:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-07-03 20:34 . 2009-06-17 16:2719096----a-w-c:\windows\system32\drivers\mbam.sys
    2009-07-03 16:14 . 2009-07-03 21:39117760----a-w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-07-03 16:14 . 2009-07-03 16:14--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\SUPERAntiSpyware
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-C:\MSId8962.tmp
    2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\Common Files\Wise Installation Wizard
    2009-07-03 16:02 . 2009-07-03 16:02--------d-----w-c:\program files\CCleaner
    2009-07-03 04:12 . 2009-07-03 23:39--------d-----w-c:\documents and settings\OM\Application Data\Lavasoft
    2009-07-02 19:15 . 2009-07-02 19:154656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP7.sys
    2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP6.sys
    2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP5.sys
    2009-07-02 19:11 . 2009-07-02 19:114656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP4.sys
    2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP3.sys
    2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP2.sys
    2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP1.sys
    2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP0.sys
    2009-07-02 18:26 . 2009-07-03 03:12--------d-----w-c:\documents and settings\All Users\Application Data\12080624
    2009-07-02 18:26 . 2009-07-02 18:26--------d-sh--w-c:\windows\System Volume Information
    2009-06-29 03:13 . 2009-06-29 03:13--------d-----w-c:\program files\MediaMelon
    2009-06-22 02:45 . 2009-06-22 02:45--------d-----w-c:\program files\Common Files\xing shared
    2009-06-09 03:53 . 2009-06-09 03:53--------d-----w-c:\documents and settings\All Users\Application Data\McAfee

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-15 03:11 . 2007-07-13 04:5086327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-07-06 00:35 . 2008-06-17 01:01--------d-----w-c:\documents and settings\OM\Application Data\HPAppData
    2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\program files\Common Files\Symantec Shared
    2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\program files\Symantec
    2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
    2009-07-05 13:02 . 2009-04-03 14:36--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater
    2009-07-03 21:03 . 2008-04-23 00:50--------d-----w-c:\program files\Java
    2009-07-03 16:07 . 2009-03-31 00:50--------d-----w-c:\documents and settings\OM\Application Data\Azureus
    2009-07-03 13:05 . 2008-06-19 03:4511952----a-w-c:\windows\system32\avgrsstx.dll
    2009-07-03 13:05 . 2008-06-19 03:45327688----a-w-c:\windows\system32\drivers\avgldx86.sys
    2009-07-03 13:05 . 2007-03-03 08:0127784----a-w-c:\windows\system32\drivers\avgmfx86.sys
    2009-07-03 13:05 . 2008-06-19 03:45108552----a-w-c:\windows\system32\drivers\avgtdix.sys
    2009-07-03 02:52 . 2008-06-19 03:45--------d-----w-c:\documents and settings\All Users\Application Data\avg8
    2009-07-02 18:55 . 2009-04-11 11:22--------d-----w-c:\documents and settings\OM\Application Data\Amazon
    2009-07-02 18:55 . 2009-04-11 11:21--------d-----w-c:\program files\Amazon
    2009-07-02 18:27 . 2009-07-02 18:27327---h--w-c:\windows\Fonts\mlog
    2009-07-02 18:25 . 2007-01-16 18:01--------d-----w-c:\documents and settings\OM\Application Data\AdobeUM
    2009-06-30 00:58 . 2009-04-17 16:59--------d-----w-c:\documents and settings\OM\Application Data\U3
    2009-06-22 02:45 . 2008-07-17 01:21--------d-----w-c:\program files\Common Files\Real
    2009-06-20 01:19 . 2009-02-03 04:21--------d-----w-c:\program files\Google
    2009-06-05 13:29 . 2009-06-05 13:29152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-06-03 04:41 . 2009-06-03 04:41--------d-----w-c:\documents and settings\OM\Application Data\ATI
    2009-06-03 03:14 . 2009-06-03 03:14708608----a-w-c:\windows\system32\Resecure60.dll
    2009-06-03 03:14 . 2009-06-03 03:146536----a-w-c:\windows\system32\WinGPDrv.dat
    2009-06-03 03:14 . 2009-06-03 03:146533----a-w-c:\windows\system32\NGWinDrv.dat
    2009-06-03 03:14 . 2009-06-03 03:14458752----a-w-c:\windows\system32\LiveUpdate.dll
    2009-06-03 03:14 . 2009-06-03 03:141290240----a-w-c:\windows\system32\NGWinSys.dll
    2009-06-03 03:14 . 2004-08-04 12:001025----a-w-c:\windows\system32\y1vz87p.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth2.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth1.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth2.dll
    2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth1.dll
    2009-06-03 03:12 . 2009-06-03 03:12--------d-----w-c:\program files\Common Files\RAM Common
    2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\VectorDraw
    2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\Common Files\Bentley
    2009-06-03 03:09 . 2009-06-03 03:0910134----a-r-c:\documents and settings\OM\Application Data\Microsoft\Installer\{D4A33E08-4FE7-40C4-BF5E-5853C56ADD7C}\ARPPRODUCTICON.exe
    2009-06-03 03:09 . 2009-03-31 01:57--------d-----w-c:\program files\Common Files\Bentley Shared
    2009-06-01 15:56 . 2008-07-20 03:46--------d-----w-c:\documents and settings\Guest\Application Data\HPAppData
    2009-05-31 12:26 . 2009-05-31 12:2673784----a-w-c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-05-21 16:33 . 2009-06-05 13:30410984----a-w-c:\windows\system32\deploytk.dll
    2009-05-10 03:04 . 2009-02-06 01:22--------d-----w-c:\documents and settings\OM\Application Data\ZoomBrowser EX
    2009-05-10 03:03 . 2009-02-06 01:14--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-05-07 15:32 . 2004-08-04 12:00345600----a-w-c:\windows\system32\localspl.dll
    2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr
    2009-04-17 12:26 . 2004-08-04 12:001847168----a-w-c:\windows\system32\win32k.sys
    2009-04-15 14:51 . 2004-08-04 12:00585216----a-w-c:\windows\system32\rpcrt4.dll
    .

    ((((((((((((((((((((((((((((( [emailprotected]_04.55.54 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-07-06 00:43 . 2009-07-06 00:4316384 c:\windows\Temp\Perflib_Perfdata_fc.dat
    - 2004-08-04 12:00 . 2009-07-03 03:4258998 c:\windows\system32\perfc009.dat
    + 2004-08-04 12:00 . 2009-07-05 04:5858998 c:\windows\system32\perfc009.dat
    + 2004-08-04 12:00 . 2009-07-05 04:58392864 c:\windows\system32\perfh009.dat
    - 2004-08-04 12:00 . 2009-07-03 03:42392864 c:\windows\system32\perfh009.dat
    + 2007-01-16 16:51 . 2009-07-05 18:133817984 c:\windows\Installer\1073be.msi
    - 2007-01-16 16:51 . 2009-07-03 23:383817984 c:\windows\Installer\1073be.msi
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
    "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848]
    "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-02-24 3558136]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-03 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
    "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-03 1948440]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
    "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
    ImageMixer 3 SE Camera Monitor.lnk - c:\program files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe [2009-2-14 253952]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
    2008-12-22 17:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-07-03 13:0511952----a-w-c:\windows\system32\avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
    backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Themes"=2 (0x2)
    "TapiSrv"=3 (0x3)
    "Symantec AntiVirus"=2 (0x2)
    "SNDSrvc"=3 (0x3)
    "SavRoam"=3 (0x3)
    "HPSLPSVC"=2 (0x2)
    "hpqddsvc"=2 (0x2)
    "helpsvc"=2 (0x2)
    "FastUserSwitchingCompatibility"=3 (0x3)
    "ERSvc"=2 (0x2)
    "DefWatch"=2 (0x2)
    "ccSetMgr"=2 (0x2)
    "ccPwdSvc"=3 (0x3)
    "ccEvtMgr"=2 (0x2)
    "BITS"=2 (0x2)
    "avg8emc"=2 (0x2)
    "Ati HotKey Poller"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
    "c:\\Program Files\\Vuze\\Azureus.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    "c:\\Program Files\\MediaMelon\\bin\\wrapper.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "11:TCP"= 11:TCP:INTERNET
    "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:45 PM 327688]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:45 PM 108552]
    R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
    R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2009 8:05 AM 906520]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 9:06 AM 298776]
    R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\MediaMelon\bin\wrapper.exe [4/16/2009 3:30 PM 217088]
    S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2009 5:36 PM 133104]
    S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [7/2/2009 2:09 PM 1252474]
    S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPServiceREG_MULTI_SZ HPSLPSVC
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34]

    2009-07-06 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 14:36]

    2009-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35]

    2009-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-05 19:45
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(892)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(3104)
    c:\windows\system32\webcheck.dll
    c:\windows\system32\IEFRAME.dll
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
    c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
    c:\windows\system32\msls31.dll
    c:\windows\system32\OneX.DLL
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\BCMWLTRY.EXE
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\drivers\CDAC11BA.EXE
    c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\java.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\HP\Digital Imaging\bin\hpqste08.exe
    c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
    c:\windows\system32\msiexec.exe
    c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
    .
    **************************************************************************
    .
    Completion time: 2009-07-06 19:47 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-07-06 00:47
    ComboFix2.txt 2009-07-05 04:59

    Pre-Run: 4,735,184,896 bytes free
    Post-Run: 4,738,347,008 bytes free

    284--- E O F ---2009-06-11 08:03
    How is the computer running now?

    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete: ComboFix and its associated files and folders.
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    1. Double click OTM to launch it.
    Vista users right click and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
    5. Once complete exit out of OTM.

    HI,
    My computer is running Normal now. Thank you very much. Do I need to do anything else?

    Thanks a million,
    SreeFinal suggestions.

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    3847.

    Solve : Cant install Micr. office xp installer patch??

    Answer»

    I have 1GB of RAM and 9.76g on my C drive and 269 on my e drive. Is that normal. My motherboard is ASUS p4s333 and for some reason my bios says it incorrect. OK i installed microsoft OFFICE xp professional with frontpage on my comp and for some reason its not showing or coming up and when i put the disk in to set it up it says SOMETHING about the installer PATCH. I have xp home edition sp 3. When I go to add and remove and try to uninstall it and it says the source does not exist. Very confusing. it cant FIND the installer patch. even with the cd. Thank you in advance whomever replies. if you need any other info please don't hesitate to ask.

    Nicole

    3848.

    Solve : HJT Log for perusal before l submit another post?

    Answer»

    I'm having terrible problems with my pc at the MOMENT but before l send a POST to the right forum, could someone take a look at my HJT log to see if anything is dodgy.
    I've already downloaded the latest versions of SAS, MBAM, and Avast Antivirus, and they have all run successfully without any errors.
    Copy of HJT log follows.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:46:25, on 06/07/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    BOOT mode: Normal

    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\windows\Explorer.EXE
    C:\windows\system32\spoolsv.exe
    C:\windows\system32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\windows\System32\svchost.exe
    C:\windows\system32\nvsvc32.exe
    C:\windows\System32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Malwarebytes\mbamservice.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\PROGRA~1\Wanadoo\CnxMon.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\windows\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
    C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\PROGRA~1\Wanadoo\Watch.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Trend Micro\HijackThis\Sniper.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wanadoo.fr/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R3 - URLSearchHook: Search CLASS - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9CADDFDF-8C2B-436C-8E42-F0AB5C2FD79E}: NameServer = 80.10.246.130 80.10.246.3
    O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes\mbamservice.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe

    --
    End of file - 5768 bytesThere is NOTHING related to malware in the log.Thanks very much for that Evil.
    I'll now go and post my problem in the appropriate forum.
    Regards

    3849.

    Solve : loading issues?

    Answer»

    Logfile of TREND Micro HijackThis v2.0.2
    Scan saved at 8:43:09 PM, on 7/5/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\JAVA\jre6\bin\jqs.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\skeys.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\QUICKTIME\QTTask.exe
    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
    C:\WINDOWS\V0400Mon.exe
    C:\WINDOWS\Imgtask.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\COMMON~1\AOL\113512~1\EE\AOLHOS~1.EXE
    C:\PROGRA~1\COMMON~1\AOL\113512~1\EE\AOLServiceHost.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Xfire\Xfire.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\AVG\AVG8\avgscanx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\trend micro\HijackThis\HijackThis.exe
    C:\Program Files\trend micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gaiaonline.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50239
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;;localhost
    R3 - URLSearchHook: (no name) - - (no file)
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: (no name) - *{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,SKEYS /I
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
    O2 - BHO: Gamevance - {0ED403E8-470A-4a8a-85A4-D7688CFE39A3} - C:\Program Files\Gamevance\gamevancelib32.dll (file missing)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: 890166 helper - {A48FE9AC-DD02-4FF7-9211-B7BA9A2C8BF2} - (no file)
    O2 - BHO: FCTBPos00Pos - {B1BE275B-78BF-4A33-81AB-380699CFF329} - C:\Program Files\Gaia Online Toolbar\Toolbar.dll (file missing)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135120535\EE\AOLHostManager.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL,UPF
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0400Cvw.dll] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0400Cvw.dll
    O4 - HKLM\..\Run: [V0400Mon.exe] C:\WINDOWS\V0400Mon.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
    O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (USER 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] OSK.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCfox000
    O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
    O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O22 - SharedTaskScheduler: garcea - {eb9f614b-ea44-40d0-8829-542e4f254739} - (no file)
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 11345 bytes
    broni i downloaded avg security and found 13 threats to my computer tell me if i'm still infected plzMy Web Search Toolbar. Although a valid application it's marked as shovelware because it's often installed when installing another FREE program that's completely unrelated to this toolbar.
    mwsbar.dll My Web Search Toolbar Internet Browser Helper Object (BHO).dll. Although a valid application it's marked as shovelware because it's often installed when installing another free program that's completely unrelated to this toolbar.


    it looks like you have this but wait for an expert to tell you to delete it


    and i think the ask tool bar has to be deleted

    3850.

    Solve : Virus Combo?

    Answer»

    I was cruising some unscrupulous sites (my fault, so I partially deserve his) and clearly picked up something that was quite strong.

    Managed to partially stop it (I think) before it fully got working but it has blocked me from opening any programs (other than Hijack this for some reason) and I can't boot into safe mode.

    Typing this on my laptop since I can't open Firefox/IE/etc on the desktop.

    Hijack This pops up a bunch of stuff that I'm fairly certain shouldn't be there, but obviously a little leery of just removing some files that MAY be needed w/o further input.

    RUNNING Windows XP. Have disabled my internet also on the desktop in case it's trying to download stuff to expand/continue.

    Got an alert that at least in part it was Virus.Win32.Gpcode.ak trying to come in, along with a couple of others. Any suggestions as to how I can best get info to you guys? Managed to get a clean HJ Report off via mobile drive. Happy to provide more as possible/requested. Thanks for any help you can provide.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:24:44 AM, on 7/6/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16850)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\DOCUME~1\Ryan\LOCALS~1\Temp\kn2jp7hf9.exe
    C:\DOCUME~1\Ryan\LOCALS~1\Temp\kn2jp7hf9.exe
    C:\DOCUME~1\Ryan\LOCALS~1\Temp\f.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
    C:\DOCUME~1\Ryan\LOCALS~1\Temp\kn2jp7hf9.exe
    C:\Program Files\MagicDisc\MagicDisc.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\fonts\services.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\DOCUME~1\Ryan\LOCALS~1\Temp\b.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    F3 - REG:win.ini: load=C:\WINDOWS\system32\msohqxlm.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\msqta.exe
    O2 - BHO: &AMP;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: C:\WINDOWS\system32\gsf83iujid.dll - {d76ab2a1-00f3-42bd-f434-00bbc39c8953} - C:\WINDOWS\system32\gsf83iujid.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
    O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
    O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,[emailprotected]
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [] C:\DOCUME~1\Ryan\LOCALS~1\Temp\kn2jp7hf9.exe
    O4 - HKCU\..\Run: [LowRiskFileTypes] C:\WINDOWS\sysguard.exe
    O4 - HKCU\..\Run: [hsf7husjnfg98gi498aejhiugjkdg4] C:\DOCUME~1\Ryan\LOCALS~1\Temp\kn2jp7hf9.exe
    O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\Ryan\LOCALS~1\Temp\smss.exe
    O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\Ryan\protect.dll,[emailprotected]
    O4 - HKCU\..\Run: [ColdWare] C:\DOCUME~1\Ryan\LOCALS~1\Temp\f.exe
    O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\Ryan\LOCALS~1\Temp\b.exe
    O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\msmsbm.exe
    O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\kiuft40lou.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [hsf7husjnfg98gi498aejhiugjkdg4] C:\WINDOWS\TEMP\kiuft40lou.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Windows System Recover!] C:\WINDOWS\TEMP\debug.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,[emailprotected] (User 'Default user')
    O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Wireless PCI Card Configuration Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - EXTRA context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
    O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet.exe
    O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PokerSites\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PokerSites\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: ,C:\DOCUME~1\Ryan\LOCALS~1\Temp\38314765517mxx.dll
    O20 - Winlogon Notify: __c0087625 - C:\WINDOWS\system32\__c0087625.dat
    O22 - SharedTaskScheduler: rtasgvfu76ew8ndkfno94 - {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - C:\WINDOWS\system32\gsf83iujid.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
    O23 - Service: B-Service - Unknown owner - C:\Documents and Settings\Ryan\Application Data\Mikogo\B-Service.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

    --
    End of file - 10474 bytesThe logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

    There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. Trying to fix this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information.

    Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

    Backing up files before formatting

    If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

    Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

    I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.

    -) Dr.Web CureIt!
    -) AVG Win32/Virut Removal Tool
    -) Symantwc W32.Virut Removal Tool
    -) McAfee Avert Stinger
    -) Microsoft Windows MALICIOUS Software Removal Tool

    If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

    Very important, do the following immediately or as soon as possible!

    If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.

    From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

    DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.
    Thanks Evil

    Looks like only one solution, so I'll carefully try and salvage what I can before wiping clean and starting over.